External data protection officer in Hamburg, Berlin and Munich: Order in two working days
Anyone who needs an external data protection officer in Hamburg, Berlin and Munich at the same time rarely changes provider per location. This guide shows obligations, costs and an order path with two working days lead time instead of six weeks.
According to Art. 37 GDPR and § 38 BDSG, companies in Germany must appoint a data protection officer as soon as at least 20 people constantly process personal data automatically or a core activity requires extensive, regular monitoring. Anyone who operates locations in Hamburg, Berlin and Munich at the same time is faced with the question of whether three local representatives should be appointed or a uniform external solution should be chosen. The answer determines the costs, reporting line and audit robustness of the entire documentation and at the same time determines how quickly supervisory inquiries, data breaches and the rights of those affected can be processed.
This guide specifically addresses the location question. You will learn what obligations arise from being present in three city states and federal states at the same time, which supervisory authority is responsible for which location and how to organise an external appointment that covers all three seats. You can read about the fines involved, how the three authorities HmbBfDI, BlnBDI and BayLDA work in practice and what special procedural requirements apply at each location. You can see what cost structure a multi-location mandate realistically has and what components are included in a platform solution. The end result is a concrete procedure with an appointment certificate, reporting line and 490 audit templates that is ready for use within two working days and not after several weeks of contract negotiations in the lawyer's office. The you form is maintained throughout, all obligations are documented with paragraphs and standards.
Key Takeaways
- Three locations in Hamburg, Berlin and Munich do not require a DPO per city, but rather an appointment certificate with a clearly documented reporting line to the management.
- Three supervisory authorities are responsible at the same time: HmbBfDI, BlnBDI and BayLDA, with sometimes different interpretation practices for employee data protection and order processing.
- An external data protection officer via Officer-as-a-Service is usually able to act two working days after being appointed; classic mandates take two to six weeks.
When the obligation to order applies if you work at three locations
The obligation to order results from Art. 37 Para. 1 GDPR in conjunction with Section 38 Para. 1 BDSG. As soon as at least 20 people are constantly processing personal data automatically, a data protection officer must be appointed. This threshold applies company-wide and not per location. Anyone who employs 8 people in Hamburg, 9 in Berlin and 7 in Munich exceeds the 24-person threshold and must be named, even if no individual location alone reaches the 20-person mark. The threshold is an indicator, not a protective shield, and also applies if employees work part-time or in the home office.
In addition, there is the core activity clause from Article 37 Paragraph 1 Letters b and c GDPR. Anyone who regularly and systematically processes observations or special categories of data in accordance with Art. 9 GDPR is required to order, regardless of the number of employees. Typical cases include HR tech platforms, healthcare services, marketing analytics with tracking, fintechs with credit checks or insurance intermediaries with claims data. In these constellations, the obligation applies from the first employee onwards and is regularly checked by the supervisory authorities during occasional audits. Violations of the ordering obligation are subject to a fine of up to 10 million euros or 2 percent of the previous year's worldwide turnover according to Art. 83 Para. 4 GDPR.
In practical terms, this means: A single DPO for all three locations is not only possible, but from the perspective of the supervisory authorities it is usually desirable because it offers a consistent point of contact. The company remains responsible as a legal entity; the appointment certificate is created centrally and referenced in the list of procedures in accordance with Art. 30 GDPR. Anyone who appoints an external data protection officer avoids conflicts of loyalty with the line, gaps in representation during vacation and the professional risk that an internal officer without previous experience has to resolve supervisory inquiries. In addition, there is special protection against dismissal for internal representatives in accordance with Section 6 Paragraph 4 BDSG, which does not play a role in external mandates. The appointment certificate, signed, filed, verifiable.
Three supervisory authorities, one reporting line: HmbBfDI, BlnBDI and BayLDA
Hamburg, Berlin and Munich are monitored by three different state supervisory authorities. Responsible in Hamburg is the Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI), in Berlin the Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI) and in Munich the Bavarian State Office for Data Protection Supervision (BayLDA) is responsible for the private sector. Which authority is responsible in an individual case is determined by the location of the head office, usually the location of the main branch in accordance with Art. 4 No. 16 GDPR. In cross-border cases, the one-stop shop procedure in accordance with Art. 56 GDPR also applies and brings the lead authority into a coordinated decision with the relevant supervisory authorities.
The three authorities differ noticeably in their supervisory practices. In recent years, the HmbBfDI has published noticeably early on tracking, telemetry and international data transfer and works closely with consumer protection associations. The BlnBDI is known for a consistent approach to employee data and HR tools and has issued six- and seven-figure fines in several cases, including in the areas of applicant management and employee monitoring. The BayLDA has an operational focus on direct marketing, B2B addresses, cookies and image processing in industrial companies and publishes detailed activity reports with indications of fines. Anyone who works in all three areas must know the respective interpretations and take them into account in statements.
Operationally, this means a central reporting line. The external DPO reports to the management as the responsible body in accordance with Art. 38 Para. 3 GDPR, coordinates inquiries from the respective supervisory authority and keeps the list of procedures per processing activity, not per location. As a compliance platform and officer-as-a-service, CIVAC works exactly in this logic: one reporting line, one documentation, three addressable supervisory authorities with location-specific correspondence history and cleanly separated file statuses. Correspondence, written submissions, deadline calendars and internal statements are available in versions and can be reproduced within minutes in the event of an audit. The appointment certificate, signed, filed, verifiable. Anyone who has previously coordinated this construct in three separate law firms knows the difference.
How much does an external data protection officer cost at multiple locations?
Costs for an external data protection officer depend on three factors: number of employees, complexity of processing activities and type of data categories. For companies with 30 to 80 employees and standard processing, classic mandates in Germany range from around 600 to 1,800 euros per month. When processing special categories of data in accordance with Art. 9 GDPR or profiling, the fees increase from 2,000 euros upwards. Travel and inspection appointments are billed separately, often with hourly rates between 180 and 280 euros net. In addition, there are one-off expenses for the initial audit, risk assessment and setting up the procedure list, which can be between 3,000 and 8,000 euros depending on the law firm.
Several locations rarely increase the effort linearly. Those who operate in Hamburg, Berlin and Munich generally have centralized HR, marketing and sales structures. Most processing activities run through central systems such as CRM, HRIS and ticketing. What actually varies per location are local inspections, works council issues, employee data protection, local marketing campaigns and occasional inquiries from local supervisory authorities. The core content remains the same, the correspondence is conducted in a differentiated manner. Anyone who clearly maps this differentiation saves measurable time in every supervisory correspondence.
With a platform model, the costs are typically flatter and more transparent. The appointment certificate is created once, the workspace documents all three locations in a client structure, audit templates and data protection impact assessments are reusable. Anyone who hires three separate local law firms pays three basic flat rates plus travel time and has three different writing styles, three different case managers and three different escalation paths. Anyone who mandates the external data protection officer via a platform has a contract, an invoice and an escalation address. This not only reduces direct costs by typically 25 to 45 percent, but also the coordination effort in day-to-day business and the risk of contradictory assessments of identical procedures. In internal reporting to management, this means a single status report instead of three individual lawyer memos.
Draw up the appointment certificate, catalogue of tasks and reporting line correctly
The order according to Art. 37 GDPR is made by the management in writing. The content includes the identification of the person appointed, the scope, the start of the order and the reporting line to the highest management level in accordance with Art. 38 Para. 3 GDPR. If there are multiple locations, the scope must specifically include all three locations. A mere reference to the main branch is not sufficient if other locations are themselves responsible within the meaning of the GDPR or act as their own data processors towards employees and those affected.
The catalogue of tasks results from Art. 39 GDPR and includes advice, monitoring, training, cooperation with the supervisory authority and the contact point function for those affected. In practice, there are additional tasks that are not necessarily required by law: maintenance of the directory in accordance with Art. 30 GDPR, support of data protection impact assessments in accordance with Art. 35 GDPR, review of order processing contracts with service providers, statements on new tools and the reporting of data breaches within 72 hours in accordance with Art. 33 GDPR to the responsible supervisory authority. The deadline expires as soon as it is known.
In the CIVAC workspace, the appointment certificate is kept as a versioned document, the tasks are stored as a checklist, and the reporting line is linked to management appointments. Supervisory requests are recorded in the workspace, given a deadline and included in the reporting line with a draft answer. Training courses are documented with participant lists, data breaches are processed in the 72-hour reporting path, and inquiries from those affected in accordance with Art. 15 GDPR are answered in standard templates. The auditor calls, the evidence is ready. Anyone who maintains classic Excel lists and PDF folders cannot achieve this level of transparency without considerable manual effort. This is the practical difference between compliance as a filing cabinet and compliance as software.
Location specifics Hamburg: tracking, media, international data transfers
Hamburg is home to many media, advertising and e-commerce companies. The HmbBfDI addressed relevant topics early and consistently. Cookie banners, pixel tracking, server-side tagging, CRM profiling and third-country transfers are regular topics in audit procedures and in the authority's activity report. Anyone who is based in Hamburg and works with US providers should take the standard contractual clauses in accordance with Implementing Decision (EU) 2021/914 and the Transfer Impact Assessment seriously and document them for each relevant service. Random inspections by the HmbBfDI usually start with a request for a directory and TIA, not with an on-site inspection.
In practice, three areas are relevant. Firstly, the selection of tracking tools with a focus on server-side and first-party architectures, including the question of which identifiers must be consented to before being set. Secondly, the documentation of the legal basis for profiling and direct advertising in accordance with Art. 6 Para. 1 GDPR as well as the rights of objection in accordance with Art. 21 GDPR. Thirdly, the handling of international data transfers to the USA, Great Britain and other third countries, supplemented by the EU-US Data Privacy Framework. Violations can result in fines of up to 20 million euros or 4 percent of global group sales in accordance with Article 83 of the GDPR, whichever is higher. In addition, there are risks of warnings under UWG from competitors and associations.
The external data protection officer at the Hamburg location usually consolidates marketing and sales processing. He checks cookie banner configurations, writes data protection declarations, accompanies campaign setups and carries out data protection impact assessments as soon as systematic profiling takes place. A central workspace in which Hamburg processing operations are documented with their legal bases, contracts and transfer risks is the prerequisite for orderly communication with the HmbBfDI. Audit-proof, documented, Art. 30-proof. CIVAC provides a template library in which the cookie audit, TIA template and third country transfer checklist are prepared and only need to be filled out for each location.
Location specifics Berlin: HR tech, start-ups and employee data
Berlin is home to a high density of tech companies, HR tech providers and start-ups. In recent years, the BlnBDI has repeatedly taken a position on employee data protection, people analytics and HR tools. Topics included background checks, applicant scoring, performance tracking, the use of collaboration tools with telemetry functions and the question of when artificial intelligence in the HR context requires a data protection impact assessment. In the case of automated decisions, Art. 22 GDPR also applies with mandatory information and intervention rights for employees.
Section 26 BDSG is legally relevant for the employee context, supplemented by co-determination obligations according to Section 87 Paragraph 1 No. 6 BetrVG as soon as technical devices are used to monitor behaviour or performance. Anyone who uses HR tools such as Personio, Workday, BambooHR, Lattice or similar platforms in Berlin should keep company agreements, data protection impact assessments and order processing contracts in a closed file. Gaps in this chain are regularly criticized in supervisory procedures and have led to noticeable fines in the past, for example when applicant data was stored longer than necessary without a legal basis or performance data was evaluated without co-determination.
The external DPO at the Berlin location typically works closely with HR and the works council. He checks new tools before introduction, formulates data protection information for applicants and employees, accompanies negotiations on company agreements from a data protection perspective and ensures consistent documentation. In the CIVAC workspace, HR processing is linked as a separate procedural group with the legal basis, company agreement, order processing contract and transfer documentation. Inquiries from those affected in accordance with Art. 15 GDPR are recorded in ticketing, the response text is built from templates and answered within the one-month deadline in accordance with Art. 12 Para. 3 GDPR. Those who work with the standard processes gain, on average, several working days per inquiry compared to independent processing and reduce the risk of follow-up inquiries or complaints to the BlnBDI.
Location specifics Munich: Industry, B2B marketing and cookie practice
Munich and the BayLDA represent a distinctive line in direct marketing, cookies and B2B address trading. The authority has carried out audits on cookie banners and telephone advertising and publishes detailed activity reports with specific expectations of companies. In addition, classic industrial companies are relevant in the Bavarian economic area, where the focus is on procedures with supplier and customer data, image processing in production halls, access control systems and plant security issues. In addition, there are growing procedures relating to networked machines, predictive maintenance and IoT telemetry, which can also generate personal data.
Two aspects in particular need to be taken into account for supervisory practice. Firstly, the BayLDA requires stringent consent documentation for marketing activities in accordance with Section 7 UWG in conjunction with Article 6 Paragraph 1 Letter a GDPR. Secondly, the authority examines video and image processing in production and on factory premises very closely, including the question of whether Section 4 BDSG, Article 6 Paragraph 1 Letter f GDPR or a specific works agreement is the legal basis. Anyone who produces in Munich and is active in B2B marketing at the same time has to manage two very different risk areas at the same time and should reflect both in a uniform process documentation. In the event of violations, orders are regularly issued which must be implemented within 14 days.
The external data protection officer coordinates marketing, sales and production. In practice, this means: a processing directory that keeps marketing campaigns, sales leads, service data and factory data separately, clearly documented consent and objection management, and a risk assessment for every form of image processing. Anyone who proceeds in a structured manner and maps standard processes in a platform will answer supervisory inquiries from Munich with the same logic as from Hamburg or Berlin and avoid identical procedures being described differently in two written documents. Others run compliance like a filing cabinet. We run it like software.
Order in two working days: action instead of delay
Classic mandates for an external data protection officer usually take two to six weeks from the initial contact to the signed appointment certificate. Reasons include contract coordination, legal clarifications, onboarding workshops, data room setup and individually formulated task catalogues. For companies that are already active in Hamburg, Berlin and Munich and may have an open supervisory request there, this period is operationally critical. Supervisory inquiries do not wait for internal contract negotiations, and inquiries from those affected in accordance with Art. 15 GDPR also continue with their monthly deadline.
CIVAC works with a standardised order path that is completed within two working days. Day one: Kick-off call, handover of existing documentation, identification of locations, processing activities and open topics. Day two: The appointment certificate, contract and first risk assessment are signed, the workspace is set up, the reporting line is in place, the 25 representative roles with their interfaces are stored. From this point on, the external data protection officer is able to act immediately with all 490 audit templates and all standard processes. The 72-hour reporting path for data breaches in accordance with Art. 33 GDPR is also active from day two, including the reporting texts for the three supervisory authorities.
The central question is not how quickly a contract can be signed, but how quickly the representative can actually process processes. This requires that the workspace, the task catalogue and the reporting line exist from day one. Anyone who appoints three local lawyers for Hamburg, Berlin and Munich has three onboarding phases in parallel, three law firm systems and three secretariats. Anyone who uses Officer-as-a-Service has one platform, one reporting line and a common directory of procedures. The EU data residency and an ISMS managed in accordance with ISO/IEC 27001:2022 form the technical foundation. Licence the workspace for your internal representatives or have our representatives order it.
How CIVAC organises multi-location mandates
CIVAC is a compliance platform and officer-as-a-service. For multi-location mandates, this means a client structure in the workspace with a central appointment certificate, location-specific procedural directories and a uniform reporting line to management. The 490 audit templates, the 72-hour reporting path according to Art. 33 GDPR and the interfaces to the three responsible supervisory authorities are preconfigured. The data is stored with EU data residency, an information security organisation managed according to ISO/IEC 27001:2022 with its 93 controls accompanies the platform and ensures the confidentiality of the mandates.
You have two options. Variant one: You already have one or more internal data protection officers and licence the workspace so that your internal officers in Hamburg, Berlin and Munich work consistently. You retain personnel sovereignty, but gain audit templates, documentation standards, EU data residency and a standard process for supervisory requests. Variant two: You hand over the mandate. An external data protection officer is appointed for all three locations, the work takes place in the workspace, the management receives monthly reports with concrete status and deadline overviews and an assessment of open risks. Licence the workspace for your internal representatives or have our representatives order it.
If you want to check today whether a multi-location mandate can be set up in two working days, then write to us. Turn reading into a mandate.: info@civac.de or the contact form on civac.de. Within one working day you will receive an initial assessment, a rough indication of effort and a suggestion for the order path for Hamburg, Berlin and Munich. In the initial consultation, we clarify whether a uniform mandate or a hybrid model of internal and external representatives fits your structure, which procedures need to be documented first in an audit-proof manner and how the ongoing reporting line to your management is embedded. The appointment certificate, signed, filed, verifiable.
FAQ
Do we need our own data protection officer in Hamburg, Berlin and Munich?
No. According to Art. 37 GDPR, a data protection officer must be appointed per responsible body, not per location. If Hamburg, Berlin and Munich belong to one legal entity, a central appointment certificate with an express scope for all three branches is sufficient. In the case of separate companies, orders must be made per company; one personal identity is permitted in accordance with Section 38 BDSG.
Which supervisory authority is responsible for three locations?
The supervisory authority at the head office is usually in charge in accordance with Art. 4 No. 16 GDPR. In Hamburg this is the HmbBfDI, in Berlin it is the BlnBDI, in Munich it is the BayLDA for the private sector. Supervisory procedures with cross-border implications are coordinated via the one-stop shop procedure in accordance with Art. 56 GDPR, but the other authorities remain accessible at all times.
How quickly can an external data protection officer be appointed?
Classic mandates take two to six weeks from the initial meeting to signing because contract negotiation, onboarding and data room setup run in parallel. With standardised Officer-as-a-Service, the order is completed within two working days, including the appointment certificate, contract and set-up workspace with all 37 audit templates as well as an active 72-hour reporting path for data breaches in accordance with Art. 33 GDPR. The technical depth is completely retained.
How much does an external DPO for three locations cost compared to three local mandates?
Three local mandates usually add up to three basic flat rates, multiple travel times and parallel onboarding phases. A central mandate summarizes these costs because central processing such as HR, CRM and marketing are documented once. The savings are typically between 25 and 45 percent; the greater effect is usually the reduced coordination effort in day-to-day business.
What happens if there is a supervisory request from one of the three authorities?
Inquiries are recorded in the workspace, given a deadline and communicated to management via the reporting line. The external DPO drafts the answer, compares it with the list of procedures and submits it after approval. The auditor calls, the evidence is ready. The process then remains documented in version form in the workspace.
Can we combine internal and external data protection officers?
Yes. Licence the workspace for your internal representatives in Hamburg, Berlin and Munich, or have an external DPO appointed to coordinate. Dual staffing with clear responsibilities is generally permitted under Article 37 (6) GDPR and is common in larger structures, especially for complex processing with a high risk.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.