Hygiene service providers or hygiene representatives: What companies really need
Anyone who researches hygiene service providers such as Gemex Hygiene Liefersschutz GmbH is usually looking for operational pest control. The legal obligation to be a hygiene officer according to IfSG, HACCP and ISO 22000 remains unaffected. Clearly separate the two functions.
The search for service providers like Gemex Hygiene Storage Protection GmbH regularly leads to a misunderstanding: operational pest control, storage protection and cleaning services are mixed with the hygiene law representative function. Both functions are necessary, but must be strictly separated legally. An external service provider provides inspection, bait stations, monitoring and control in accordance with the Biocides Regulation (EU) No. 528/2012. The appointment of a hygiene representative, on the other hand, results from Section 36 IfSG, from the requirements of EU Regulation 852/2004 on food hygiene, from ISO 22000:2018 as well as from professional association, trade law and pharmaceutical law requirements depending on the industry.
This article explains where the boundaries of duties between external pest monitoring and internal representative role are, like a contract with a service provider such as Gemex Hygiene Liefersschutz GmbH is sensibly designed, which appointment certificate and which reporting line are required for the hygiene officer, what sanctions are threatened in the event of failure to do so and how both functions can be combined in an audit-proof workspace. CIVAC is a compliance platform and officer-as-a-service that maps this dual structure across all locations, from HACCP documentation according to Codex Alimentarius to pest monitoring to annual hygiene training for employees according to Section 43 IfSG and the reporting line to management.
Key Takeaways
- Hygiene service providers such as Gemex Hygiene Liefersschutz GmbH provide operational services, but do not replace the appointment of a hygiene officer in accordance with IfSG, HACCP or ISO 22000.
- The appointment of the hygiene officer is made in writing with a description of the tasks, reporting line to management and a commitment to resources.
- A uniform workspace connects service provider protocols, HACCP points and training certificates into an audit-proof trace.
What a hygiene service provider does and doesn't do
Providers such as Gemex Hygiene Storage Protection GmbH typically provide services in the areas of operational pest control, storage protection and hygiene inspection. This includes the installation and maintenance of monitoring stations, the identification of harmful organisms, the documentation of the course of the infestation, the recommendation of structural and organisational measures as well as the control with approved biocides in accordance with the Biocide Regulation (EU) No. 528/2012. These services are provided via a service or work contract and regularly documented, often in accordance with DIN EN 16636 for pest control with proof of qualifications of the technicians and defined service standards.
What a service provider of this type does not provide, however, is the legal responsibility of the person responsible for the hygiene obligations within the meaning of EU Regulation 852/2004, the IfSG, the Food Hygiene Ordinance, the Drinking Water Ordinance or industry-specific regulations such as the pharmacy operating regulations. The obligation to keep written HACCP documentation, the obligation to provide annual instructions according to Section 43 IfSG for food-related employees, the obligation to assess risks and the obligation to appoint an internal or external hygiene officer remain entirely with the person responsible within the meaning of Art. 4 No. 7 GDPR and Section 3 LFGB.
In practice, gaps arise because management equates the service provider contract with the fulfilment of hygiene obligations. However, a supervisory inspection, for example by the local health authority or the food control authority, does not check the status of the contract, but rather the measures carried out, the documentation and the appointment of a person responsible for hygiene law with a clearly regulated reporting obligation. Others run compliance like a filing cabinet. We run it like software. The CIVAC workspace links service provider reports with the company's mandatory documentation and makes both shifts visible in one track, with the date, person responsible, follow-up action and effectiveness check in a traceable audit trail.
Legal framework: Section 36 IfSG, EU 852/2004 and ISO 22000:2018
The central German framework for the appointment of a hygiene officer results from the Infection Protection Act, in particular Section 23 IfSG for medical facilities with the obligation to have a hygiene commission and staff qualified in hospital hygiene, Section 36 IfSG for community facilities with a requirement to have a hygiene plan, as well as from the hygiene regulations of the federal states, which in some federal states formulate additional obligations for nursing homes, daycare centres and schools. For food establishments, the EU Regulation 852/2004 on food hygiene also applies, which requires a binding HACCP system with seven principles in Annex II. The Drinking Water Ordinance with DIN 2000 applies to water suppliers.
ISO 22000:2018 represents a voluntary, but increasingly mandatory, management system standard for food safety in the supply chain. The standard requires documented responsibility, a risk analysis according to HACCP principles, a food safety prerequisite program according to ISO/TS 22002 and a continuous improvement process with an internal audit routine. The function of the hygiene and food safety officer is explicitly named here and provided with clear duties, including the obligation to report to top management, the obligation to escalate in the event of deviations and the control of internal audits.
Anyone who appoints a hygiene officer documents the assumption of legal and normative responsibility in a named person. The order does not exclude the operational activities of a service provider, but rather integrates their services into the company's own hygiene plan and the HACCP risk analysis. The appointment certificate, signed, filed, verifiable. The workspace stores both the order and the contract documents with the service provider and, in the event of an audit, displays both sides as a coherent trace, with versioning and effective date.
Division of tasks: external storage protection, internal hygiene officer
A proper division of tasks begins with the risk assessment of the company. Which harmful organisms can realistically be expected, which critical control points result from the HACCP system, which areas fall under the Drinking Water Ordinance or under special regulations for community facilities, which storage areas are particularly sensitive? On this basis, external services are tendered and responsibility is taken internally. The external service provider, such as Gemex Hygiene Liefersschutz GmbH, takes over the regular inspection, monitoring, identification of harmful organisms and, if necessary, control with approved means.
The internal hygiene officer is responsible for the overall documentation, training of employees, maintaining the HACCP plan, responding to deviations, controlling audits and reporting to management. He is the contact person for the supervisory authority, coordinates service providers, checks reports for completeness, initiates corrective measures and is the first escalation level for recurring findings. This internal function can be performed by your own employee or by an external officer-as-a-service solution, depending on the size and risk profile of the company. Licence the workspace for your internal representatives or have our representatives appoint them.
The interface between both worlds is the regular inspection with minutes, the clarification of responsibility for measures and the escalation in the event of recurring findings. Anyone who manages both functions in separate systems runs the risk that the service provider's findings will not be incorporated into the HACCP system, that corrective measures will remain without effectiveness control and that the supervisory authority will find a break in the documentation in the event of an audit, which will be viewed as a systemic failure. The workspace merges both tracks and creates a task for each finding with a deadline, person responsible and escalation rule, which automatically informs the next level after expiry.
HACCP, pest monitoring and training certificates in a triad
HACCP according to Codex Alimentarius CAC/RCP 1-1969 Rev. 4 and according to Annex II of EU Regulation 852/2004 requires seven principles: hazard analysis, determination of critical control points, establishment of limit values, monitoring procedures, corrective measures, verification procedures and documentation. Pest monitoring is a typical prerequisite in the sense of the prerequisite programs according to ISO/TS 22002, which reduces the HACCP risks but does not replace the HACCP system itself. Anyone who mixes the two shifts loses track of the critical control points and cannot clearly document effectiveness controls.
The training of employees in accordance with Section 43 IfSG and Annex II Chapter XII of EU 852/2004 is another independent obligation. It includes initial instruction from the health department before starting work and an annual operational refresher with verifiable content control. Evidence of training must be kept and presented in the event of an examination, often in tabular form with date, content, trainer and signature. A service provider that maintains bait stations does not cover this obligation. The hygiene officer organises the training, documents participation and checks understanding through a standardised learning test with a minimum score.
In the CIVAC workspace, the 490 audit templates are interlinked with the three tracks HACCP, monitoring and training. A deviation in the monitoring of a service provider automatically creates a task for the hygiene officer, a note in the HACCP system and a note about possible training needs. The auditor calls, the evidence is ready. Management receives a monthly reporting line with open points, closed points, trends and escalations, in a standardised format with effective date and person responsible.
Drafting a contract with the external hygiene service provider
A reliable contract with a service provider such as Gemex Hygiene Liefersschutz GmbH defines the scope of services, response times, reporting format, escalation channels and the interface to the internal hygiene organisation. Key points are: frequency of inspection with minimum intervals per risk area, type and number of bait stations used with a site plan, documentation standard according to DIN EN 16636 or comparable standard, proof of the technicians' expertise in accordance with the Biocide Ordinance, insurance coverage with minimum amounts and a clearly regulated escalation procedure in the event of an infestation with immediate measures and reporting period.
In terms of data protection law, order processing can arise in accordance with Art. 28 GDPR if the service provider personal data is processed, for example during access controls with ID readers, personal training with participant lists or customer contacts in canteens with allergy profiles. A corresponding order processing contract must be concluded, supplemented by the technical and organisational measures. The hygiene officer checks the contractual situation together with the data protection officer and ensures that the report data is processed in the EU, provided that the data residency is part of the requirement and there is no transfer to third countries without protective measures.
The contract with the term, notice periods, scope of services and report format is stored in the workspace. Each report from the service provider is checked against the agreed format; deviating findings automatically generate tasks with a deadline and person responsible. Anyone who operates multiple locations with different service providers benefits from a uniform basis for comparison because the system aggregates the findings across locations and flags any anomalies. Audit-proof, documented, HACCP-proof. The reporting line to the management is carried out automatically in a standardised format with a comparison to the previous period and a colour heatmap of the locations.
Supervisory practices and sanctions
The supervisory practice in the hygiene sector is organised federally in Germany. Food monitoring is carried out by the district offices and independent cities, infection protection tasks by the health authorities, occupational safety issues by the state offices for occupational safety and, in some sectors, by the district governments. If defects are identified, orders, penalty payments and, in serious cases, the closure of the business in accordance with Section 39 LFGB or Section 39 IfSG apply with immediate enforcement. Depending on the regulations, the fine range is in the five to six-figure range, and is significantly higher in cases of intent or repeat offenses.
A common finding in control reports is the missing or incomplete appointment of a hygiene officer, even though an external service provider has been commissioned. Supervisory authorities interpret this as an organisational failure on the part of those responsible and use the finding as an indicator of further deficiencies, which leads to a tighter level of control. In addition, there are publication obligations under food law in accordance with Section 40 of the LFGB in conjunction with the clarifications under state law, which can lead to names being mentioned on the platforms of the federal states in the event of repeated or serious violations. The reach of such publications is considerable and threatens the existence of the B2B business.
Those who manage the dual structure of external service providers and internal representatives properly not only benefit from a lower probability of sanctions, but also from a better negotiating position with insurance companies, banks and major customers. Food establishments that deliver to retail or catering often have to pass audits according to IFS Food, BRCGS or FSSC 22000. These audits closely examine the interface between service provider and internal responsibility with random samples and document checks. Without a properly appointed hygiene officer, the audit regularly fails and the listing with a major customer is up for grabs.
Order in seven steps
The appointment of a hygiene representative can be structured in seven steps. First: inventory of the relevant legal bases and standards, from Section 36 IfSG to EU 852/2004 to ISO 22000:2018, depending on the industry, type of operation and product portfolio. Second: assessment of the risk profile based on the HACCP risk analysis, the existing service providers and the specific product risks, such as allergens, mycotoxins or microbiological risks. Third: Decision about internal or external appointment, documented with justification, resource calculation and qualification requirements.
Fourth: Creation of the appointment certificate with task description, reporting line, representation regulations, confidentiality agreement and resource commitment including training budget. Fifth: Communicate the order to the workforce, post it on the bulletin board, include it in the employee handbook and inform all relevant service providers. Sixth: Interlinking with the service provider contract, setting joint inspection dates, reporting formats, escalation channels and response times in the event of an acute infestation. Seventh: Initial audit after three months to check the effectiveness of the order and make adjustments, ideally with external audit support.
In the CIVAC workspace, each of these steps is stored with a template, a deadline and a person responsible. Anyone who orders the external hygiene officer via CIVAC receives the process as a managed service with an SLA of two working days instead of the classic two to six weeks. Anyone who licences the workspace runs the process with their own representatives and the same template base, with identical versioning of the documents. In both models, the handovers between service providers and agents are technically stored and verifiable, with a stamp, date and electronic signature.
Common mistakes in practice
Three error patterns dominate supervisory procedures in the hygiene sector. Firstly, the equation of service provider contract and agent function. A pest controller is not a hygiene officer, a cleaning company is not a hygiene officer, a catering consultant is not a hygiene officer, and ISO 22000 certification of the supply chain does not replace the order. The responsibility remains with the person responsible, and the order must be made in writing, dated and with a task description and reporting line, supplemented by a resource commitment.
Secondly, the lack of interlinking of service provider findings with the HACCP system. If a monitoring report reports an infestation, but this finding is not included in the HACCP system, there is no effectiveness control. Supervisory authorities assess this gap as a systemic failure and classify the operation in a higher risk class according to the AVV framework monitoring. Higher risk classes mean narrower control intervals and higher fees, in some federal states up to four times the standard rate, as well as an increased probability of publication according to Section 40 LFGB for every further finding.
Thirdly, the inadequate training documentation. Section 43 IfSG requires initial instruction and an annual operational refresher with proof. Anyone who does not provide this proof or fails to refresh the information will lose their line of defence in the event of an audit and can even have the employee banned from working once it is discovered. The training is stored in the workspace with a recurring task, with a reminder 30 days before expiry, with a template for learning control and with versioning of the training content. Deadline begins as soon as we become aware of it. Anyone who receives a collective report has seven days to check all employee statuses and submit evidence.
Turn reading into an assignment
If you research providers like Gemex Hygiene Liefersschutz GmbH, you are starting an important task in the wrong place. The operational service is just one component. Legal responsibility remains with the person responsible and must result in the appointment of a hygiene officer. Anyone who cleanly separates the two functions and combines them in one system reduces sanctions risks, passes audits more reliably and gains time for the core business.
CIVAC is a compliance platform and officer-as-a-service. Licence the workspace for your internal representatives and carry out HACCP, monitoring, training and ordering documents in an audit-proof system with EU data residency. Or have our officers appointed and hand over the complete mandatory process as a managed service with an SLA of two business days. In both cases, the 490 audit templates, the service provider contracts and the reporting line to management are stored in a central workspace, with versioning and escalation rules across all locations.
If you want to check which steps are necessary for your own operating structure, write to info@civac.de or use the contact form on civac.de/faq. We examine the risk profile, order situation and service provider structure and provide a written assessment with an order recommendation, an effort estimate and a roadmap for the first 30 days, with concrete milestones and responsibilities. Turn reading into an assignment.
FAQ
Does a contract with Gemex Hygiene Liefersschutz GmbH replace the appointment of a hygiene officer?
No. A service provider contract covers operational pest control and storage protection, but not the legal representative function according to IfSG, EU 852/2004 or ISO 22000. The order must be made in writing and contain a task description, a reporting line and a representation regulation. Both functions complement each other, they do not replace each other.
Which industries are obliged to appoint a hygiene officer?
Food establishments in accordance with EU 852/2004, community facilities in accordance with Section 36 IfSG, medical facilities in accordance with Section 23 IfSG, water suppliers in accordance with the Drinking Water Ordinance, care facilities and certain educational institutions are among the classic mandatory areas. In addition, there are normative requirements from ISO 22000:2018, IFS Food and comparable standards, which are often de facto mandatory in the supply chain.
What is the relationship between the hygiene officer and the HACCP team?
The hygiene officer leads the HACCP team in many companies and is responsible for the ongoing maintenance of the HACCP plan in accordance with Codex Alimentarius and Annex II of EU 852/2004. External service providers provide findings from monitoring and inspection; the HACCP team integrates these findings into the risk analysis and, if necessary, initiates corrective measures.
What qualifications does a hygiene officer have to have?
Qualifications depend on the industry. In food production, knowledge of HACCP, EU 852/2004 and ISO 22000 is required, in medical facilities further training as a hygienist is required, and in community facilities knowledge of the IfSG. External solutions via Officer-as-a-Service combine the appropriate qualifications with ongoing training and supervisory communication.
How often does hygiene training need to take place?
According to Section 43 IfSG, an initial instruction is given by the health department before starting work, followed by an annual operational refresher with proof. EU 852/2004 also requires training in food hygiene appropriate to the activity. ISO 22000 requires training planning with effectiveness assessment. The evidence is stored in the workspace with a reminder 30 days before expiry.
Can an external officer-as-a-service hygiene officer oversee multiple locations?
Yes. An external hygiene officer can look after several locations, provided that accessibility, regular inspections and sufficient time resources are contractually regulated. CIVAC appoints representatives with an SLA of two working days and maintains the location data in a central workspace with EU data residency, including previous period comparison and cross-location reporting line to management.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.