77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
External data protection officer: Order, costs and liability in plain language
Data Protection & Privacy

External data protection officer: Order, costs and liability in plain language

20 August 202612 min readBy Lena Vogt
CIVAC

External data protection officers bear responsibility in accordance with Articles 37 to 39 GDPR. This guide organises the ordering obligation, cost framework, catalogue of tasks and liability and shows when the external variant is operationally superior.

According to Article 37 Para. 1 GDPR, there is an obligation to appoint a data protection officer as soon as a company in Germany, in accordance with Section 38 BDSG, constantly employs at least 20 people with the automated processing of personal data or carries out extensive regular monitoring of data subjects. The role can be filled internally or outsourced. Both paths meet the formal requirements of the supervisory authorities, but differ significantly in terms of liability, ongoing costs, independence from management and operational resilience in the event of audits, data breaches and inquiries from those affected. With each additional system that processes personal data, the complexity grows noticeably, from marketing automation to applicant management to AI-supported support.

This article explains in detail which tasks Art. 39 GDPR assigns to an external data protection officer, how the appointment certificate is drawn up cleanly in accordance with Section 38 BDSG, what market prices can be expected in 2026, exactly where the liability limits for management and agents are and what typical errors occur The supervisory authorities regularly complain about selection and onboarding in their 2024 and 2025 activity reports. You will also receive a decision matrix for choosing internally or externally and a compact checklist for the provider discussion. CIVAC is a compliance platform and officer-as-a-service. Licence the workspace for your internal representatives or have our representatives order it. The appointment certificate, signed, filed, verifiable.

Key Takeaways

  • The obligation to order in accordance with Section 38 BDSG applies to 20 or more employees in automated processing or with extensive monitoring in accordance with Art. 37 GDPR.
  • External data protection officers are on average 30 to 50 percent cheaper than internal full-time positions and avoid structural conflicts of interest in accordance with Article 38 (6) GDPR.
  • The appointment certificate, the list of processing activities and the proof of training must be available for inspection and not just exist formally.

Obligation to order: When you absolutely need a data protection officer

The obligation to order arises primarily from Art. 37 Para. 1 GDPR and is specified in Germany by Section 38 BDSG. It takes effect in three constellations. Firstly, if the core activity of a company requires extensive, regular and systematic monitoring of data subjects, for example by tracking providers, telematics insurers, security services or platform operators with behavioral analysis. Secondly, in the case of extensive processing of special categories of personal data in accordance with Art. 9 GDPR, i.e. health, religious or biometric data, or data on criminal convictions in accordance with Art. 10 GDPR. Thirdly, in Germany there are additionally 20 or more employees who constantly process personal data automatically.

The 20-person threshold is set lower than many management assume in practice. Every employee with access to a CRM, applicant management, human resources system, ticketing tool, learning management system or marketing automation counts. Part-time employees and working students also fall below the threshold. An agency with 22 people, 21 of whom work in HubSpot or Salesforce, requires an appointment. Failure to do so could result in fines of up to 10 million euros or two percent of the previous year's global group sales, depending on which amount is higher, in accordance with Article 83 (4) GDPR. In addition, there are orders and prohibitions from the supervisory authority.

An external data protection officer offers a pragmatic path to fulfilling the ordering obligation. The order is placed in writing in accordance with the requirements of the Federal Data Protection Act, and the notification is made to the responsible supervisory authority in accordance with Art. 37 Para. 7 GDPR within a few working days via the online portal of the respective state data protection supervisory authority. CIVAC delivers the appointment certificate with all mandatory information, stores it in the workspace with versioning and audit log and reports it to the respective state data protection supervisory authority. The appointment certificate, signed, filed, verifiable.

Catalog of tasks according to Art. 39 GDPR: What the function does operationally

Art. 39 Paragraph 1 GDPR defines five core tasks of the data protection officer. Firstly, informing and advising the controller, processors and employees about their obligations under the General Data Protection Regulation and other Union and Member State data protection regulations. Secondly, monitoring compliance with the GDPR and other data protection regulations, including the controller's internal strategies, allocation of responsibilities, awareness raising and related reviews. Thirdly, advice in connection with data protection impact assessments in accordance with Art. 35 GDPR and the monitoring of their implementation. Fourth, cooperation with the supervisory authority. Fifth, acting as a contact point for the supervisory authority during consultations in accordance with Art. 36 GDPR.

In operational practice, this means a specific monthly work package. Maintenance and quarterly review of the list of processing activities in accordance with Art. 30 GDPR, ongoing support of all order processing contracts in accordance with Art. 28 GDPR including subcontractor review, processing of requests from those affected in accordance with Art. 15 to 22 GDPR within the monthly period with documented progress, maintenance of data protection information in accordance with Art. Control of data breach reports in accordance with Art. 33 GDPR within 72 hours of becoming aware of them, training of the workforce at least once a year with proof of participation, creation of an annual activity report to the management with action planning and risk matrix.

An external data protection officer with a platform connection brings these tasks into a reproducible cycle. CIVAC provides 490 ready-to-use audit templates, including directory, AVV check, impact assessment, proof of training, deletion concept and data breach log with timestamp and 72-hour escalation. Deadline begins as soon as we become aware of it. The auditor calls, the evidence is ready. Others run compliance like a filing cabinet. We run it like software.

Internal or external: The decision matrix with four criteria

The choice between internal and external ordering follows four main criteria. Firstly, the risk of structural conflicts of interest according to Art. 38 Para. 6 GDPR. An internal data protection officer may not perform any function that leads to conflicts with the supervisory task. In its brief paper No. 12, the Data Protection Conference specified that IT management, HR management, marketing responsibility, IT security and management are regularly incompatible. In SMEs with flat structures, there is often a lack of a suitable internal person without management noticing this. In group structures with dual mandates, role clarity must be documented separately.

Secondly, proof of specialist knowledge in accordance with Art. 37 Para. 5 GDPR. In practice, the supervisory authorities expect certified training, for example according to TÜV, ISACA CIPP/E or an equivalent curriculum, plus ongoing further training of at least 16 hours per year. Third, continuity. Illness, dismissal, maternity protection or parental leave mean that internal solutions are not possible, with an immediate gap in relation to the supervisory authority, which, in accordance with Article 37 (7) GDPR, always expects an approachable representative. An external mandate via a platform with documented substitution rules keeps the function constantly staffed and accessible with reporting requirements.

Fourth, the total costs calculated over three years. An internal full-time position including additional wage costs, training, professional liability and tool licences will be between 95,000 and 130,000 euros per year in 2026. An external mandate via CIVAC starts with a low four-digit monthly amount and scales transparently with employees, locations and processing activities. Licence the workspace for your internal representatives or have our representatives order it. Both models lead to the same appointment certificate in the same workspace, with an identical reporting line to your management and an identical audit log. Changing from internal to external is possible at any time.

Cost models 2026: What external data protection officers really cost

The German market will work with three main pricing models in 2026. First, monthly flat packages. A defined hourly quota including response time in the event of data breaches, a fixed number of on-site appointments per year and audit support is sold here. Secondly, pure daily rates for ad hoc mandates, usually between 1,200 and 2,400 euros net per person-day, often in conjunction with a guaranteed response window. Thirdly, hybrid models with a low basic fee plus consumption billing against proof of time. The median for a company with 50 to 150 employees and a medium risk profile is 1,200 to 2,800 euros net per month, excluding special projects such as an impact assessment for a new AI application.

Three structural cost drivers are relevant. Firstly, the number of processing activities according to Art. 30 GDPR. An online shop with a newsletter, web tracking, credit check, A/B testing and international shipping generates many times the effort that a mechanical engineer creates with classic personnel management. Second, the industry. Healthcare providers, banks, HR tech and adtech have special categories according to Art. 9 GDPR and structurally require more impact assessments per quarter as well as consultations according to Art. 36. Third, the international dimension. Third country transfers in accordance with Art. 44 ff. GDPR with standard contractual clauses, transfer impact assessment and Schrems II conformity significantly increase the hourly requirement.

If you want to compare costs realistically, do not ask for the monthly price, but rather the exact catalogue of services. Does the offer contain the appointment certificate, the report to the supervisory authority, the list according to Art. 30, a data breach log with 72-hour escalation, an annual activity report, a training plan and a documented representation rule? Is EU data residency for the workspace guaranteed contractually, including sub-processors? These seven questions separate reputable providers from fee models without substance.

Liability: Who bears the risk in the event of a data protection breach

The civil law responsibility for compliance with the GDPR clearly lies with the person responsible, i.e. the company, according to Art. 5 Para. 2 and Art. 24 GDPR. The data protection officer advises and monitors, but does not make his own decisions about processing purposes and means. Fines according to Art. 83 GDPR are directed against the person responsible, not against the representative personally. This separation is crucial and is often misunderstood in management circles, especially when a provider advertises with the inaccurate promise of assuming the risk of fines. Contractual clauses that suggest this are ineffective from a supervisory perspective.

The data protection officer's own liability comes into consideration in two constellations. Firstly, contractual poor performance towards the client company, for example in the case of demonstrably incorrect advice resulting in causal damage, for example a fine as a direct result of an incorrect recommendation. Secondly, personal liability under general civil law for intentional or grossly negligent behaviour, such as knowingly concealed incidents or falsified training certificates. External providers cover these risks through professional liability insurance, with coverage amounts starting at two million euros per insured event and a maximum of four million euros per year.

The core message is crucial for management. Appointing a qualified external data protection officer significantly reduces your own liability risk according to Section 130 OWiG, violation of the duty of supervision. Anyone who appoints an expert, follows up their recommendations in a documented manner and keeps the appointment certificate and the report to the supervisory authorities without any gaps has minimised the organisational negligence and fulfilled the duty of care in accordance with Section 43 GmbHG. Audit-proof, documented, Section 130-proof. The auditor calls, the evidence is ready. The recommendation of the representative is documented as well as the decision of the management, the status of implementation and the effectiveness test after three months.

Selection criteria: How you can recognise a reputable external data protection officer

Seven checkpoints separate reliable providers of business card data protection. Firstly, the proof of expertise must be certified and current. Ask about TÜV certificate, ISACA CIPP/E or CIPM, Udo Voigt Academy or equivalent evidence and about the annual continuing education requirement with documented training hours. Secondly, professional liability insurance with a minimum cover of two million euros per insured event, ideally with a current insurance confirmation as an attachment to the mandate contract and a clause on continued liability after the end of the mandate.

Thirdly, depth of industry experience. A healthcare provider needs someone who knows Section 22 BDSG, the Patient Data Protection Act and the facility-specific requirements according to Section 75c SGB V. A SaaS provider needs someone with third country transfer practice, Schrems II and standard contractual clauses. An industrial company needs experience with employee data protection and plant security in accordance with Section 26 BDSG. Fourth, defined accessibility. Response times in the event of data breaches, such as a response within four hours during business hours, plus an emergency number for the 72-hour period in accordance with Art. 33 GDPR, belong in the contract with a clear escalation path.

Fifth, a comprehensible toolset. A platform-based provider with workspace, pre-built templates, automatic versioning and audit log is structurally superior to a Word template provider. Sixth, EU data residency. The directory according to Art. 30, the AVV documentation and the training certificates may not be in a US cloud setup without an adequacy decision. Seventh, a clear representation rule with name, contact details and handover process. In the CIVAC FAQ you will find the detailed checklist with all seven criteria and concrete example questions for the provider interview. Supplement these points with a reference request from two comparable existing customers of the provider, ideally from your industry and size class, as well as a live demo of the workspace with real templates instead of a pure sales presentation. Additionally, have a sample audit report and an anonymized quarterly report shown to you.

Ordering process: From selection to reporting to the supervisory authority

The formal order takes place in four clearly documented steps. First, the written appointment certificate. It names the representative by name and contact details, describes the area of ​​responsibility according to Art. 39 GDPR, refers to the independence according to Art. 38 Paragraph 3 GDPR and to the ban on termination according to Section 6 Paragraph 4 BDSG for internal representatives. External representatives are mandated via a service contract that contains the same content anchors. In addition, the order date, substitution rule, termination process and handover rules are included in the document, as well as a confidentiality clause in accordance with Art. 38 Para. 5 GDPR.

Secondly, the internal announcement. The workforce must be informed, usually via the intranet, newsletter and bulletin board notices. The contact details of the data protection officer must be easily accessible, in practice by publication on the company website in the data protection notice in accordance with Article 13 (1) (b) GDPR. Thirdly, reporting to the responsible supervisory authority in accordance with Article 37 (7) GDPR. It takes place via the online portal of the respective state data protection officer and contains name, contact details and order date, and in the event of a change, the date the predecessor's role ended.

Fourth, operational onboarding. Handover of the existing list in accordance with Article 30, complete inventory of all AVVs, review of the data breaches reported to date, training status of the workforce, open requests from those affected with a deadline, status overview of ongoing impact assessments. CIVAC structures this transition via a 30-day onboarding with a fixed checklist, appointment certificate in the workspace, automatic reporting to the supervisory authorities and a reporting line directly to management. At the end of the onboarding, there is a prioritised action plan that clearly separates quick wins (e.g. AVV gaps, cookie banners), medium-term topics (impact assessment, training wave) and long-term building blocks (deletion concept, emergency plan). The appointment certificate, signed, filed, verifiable.

Typical errors that supervisory authorities complain about in external mandates

The latest activity reports from the state data protection officers for 2024 and 2025 name four recurring deficiencies in external mandates. First, the formal order is missing or outdated. A consultant is often only mandated verbally or by letter of offer, without an appointment certificate within the meaning of Art. 37 GDPR existing. In the event of an audit, this is considered a failure to order with a direct consequence of a fine in accordance with Art. 83 Para. 4 GDPR. The same applies to an appointment certificate without a date, without a task description or without a clear independence clause according to Art. 38 Para. 3 GDPR.

Secondly, the report to the supervisory authority according to Art. 37 Para. 7 GDPR was never made or contains outdated contact details, for example because a consultant was changed without the authority being subsequently reported. Thirdly, the external representative is not integrated into the organisation. There is no direct reporting line to management in accordance with Art. 38 Para. 3 GDPR, no participation in relevant project and product meetings, no early warning about new processing, no fixed quarterly appointment in the board. This means that the substance is missing what the form provides.

Fourth, the documentation is incomplete. Directory according to Art. 30 incomplete, data breach logs without a time stamp and without a 72-hour escalation track, training certificates without participant lists, AVV lists without subcontractor checks according to Art. 28 Para. 4 GDPR. During an audit, these gaps are regularly documented findings with an order for action. CIVAC addresses the four deficiencies via the workspace with versioned appointment certificate, automatic reporting to supervisory authorities, direct reporting line to management and 490 auditor-proof templates with timestamp and complete audit log. The annual activity report is created automatically from the activities documented in the workspace and contains the status of measures, training quota and risk matrix.

This is how you turn reading into an assignment

If your company has reached the 20-person threshold according to Section 38 BDSG, carries out extensive processing of special categories according to Art. 9 GDPR or the existing internal solution has run into a structural conflict of interest according to Art. 38 Paragraph 6 GDPR, it is worth switching to external ordering or connecting your internal representative to the platform. An upcoming corporate audit, a new major customer with a vendor audit or the introduction of an AI application with personal input are also classic reasons for a realignment. The CIVAC compliance platform combines both paths. Licence the workspace for your internal representatives or have our representatives order it. Both models lead to the same appointment certificate in the same system, with the same 490 templates, 93 controls according to ISO/IEC 27001:2022 and contractually guaranteed EU data residency.

A typical start looks like this. In the first conversation we clarify the appointment requirement, the risk profile and the appropriate officer profile. In the second step, you will receive the appointment certificate, the report to the supervisory authority and access to the workspace with all templates, a documented reporting line and the written representation rule within two working days. In the third step, the CIVAC data protection officer takes over day-to-day business with a fixed response time, quarterly report, annual planning and proof of training. You can find the start via the Overview of all representative roles. Turn reading into an assignment. Write to info@civac.de or use the contact form on civac.de. Ideally, you should bring the number of employees, a rough picture of your system landscape and any outstanding findings from the last supervisory or customer audit with you to the initial meeting so that we can specifically tailor the order requirement, package depth and response time.

FAQ

When do I have to appoint an external data protection officer?

The obligation to order applies as soon as your company meets the requirements of Article 37 GDPR or Section 38 BDSG, for example with 20 or more employees in automated processing or with extensive monitoring of data subjects. The choice of external or internal is free. External mandates avoid structural conflicts of interest in accordance with Art. 38 Para. 6 GDPR, ensure a consistent representation rule and are generally significantly cheaper than internal full-time positions with additional wage costs and tools.

How much does an external data protection officer cost per month?

The median for SMEs with 50 to 150 employees will be 1,200 to 2,800 euros net per month in 2026. Cost drivers are the number of processing activities in accordance with Art. 30 GDPR, industry, international data flows and the risk profile with regard to special categories in accordance with Art. 9. Flat-rate packages with a defined hourly quota, response time and fixed on-site appointments are more transparent and more reliable in terms of planning than pure daily rates without a quantity framework.

Am I liable as a managing director despite an external appointment?

Responsibility according to Art. 24 GDPR remains with the company; fines do not affect the representative. However, appointing a qualified external data protection officer reduces the risk according to Section 130 OWiG, provided you implement his recommendations in a documented manner, the appointment is formally correct and the report to the supervisory authority in accordance with Art. 37 Para. 7 GDPR is fully verifiable.

How quickly is an external data protection officer ready for action?

CIVAC delivers the appointment certificate within the SLA of two working days, instead of the industry standard two to six weeks. The report to the supervisory authority takes place in the same step via the respective state portal. The operational onboarding into daily business begins in parallel with a 30-day checklist, workspace access, templates, substitution rules and a documented reporting line to management.

Can an external data protection officer also cover ISMS and ISO 27001 topics?

Data protection and information security overlap in terms of content, but are separate in terms of roles. For a certified ISMS according to ISO/IEC 27001:2022, you also need an information security officer with his or her own appointment. CIVAC provides both roles from one workspace, including 93 controls according to Annex A, a coordinated reporting line to your management, a common data breach and incident template and combined quarterly reporting.

What documents does my external data protection officer have to hand over to me after ordering?

Appointment certificate according to Art. 37 GDPR with description of tasks, proof of notification to the supervisory authority according to Art. 37 Paragraph 7, representation rule with contact details, current proof of professional liability with coverage, access to the list of processing activities and the AVV register. Plus training plan, audit plan, data breach log and quarterly reports for the next twelve months, ideally in a versioned workspace with an audit log and a defined escalation path.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles