77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
Internal or external data protection officer: The comparison for the management
Data Protection & Privacy

Internal or external data protection officer: The comparison for the management

29 July 202612 min readBy Lena Vogt
CIVAC

Internal or external data protection officer? We compare costs, liability, independence, availability and auditability soberly. With concrete numbers, paragraphs and a decision matrix that you can use immediately in the next board meeting.

According to Art. 37 GDPR and § 38 BDSG, many German companies must appoint a data protection officer as soon as at least 20 people constantly process personal data automatically or a core activity includes extensive processing of special categories. The obligation is clearly formulated and has not changed since 2018. The question is not whether, but who: an internal employee with a dual function or an external service provider with a full mandate, supplemented by the hybrid variant that is increasingly being chosen in practice. Both basic models are legally equivalent. From an economic, organisational and liability perspective, they are very different, and the consequences of a wrong choice often only become apparent during the first supervisory procedure, the first reportable data breach or as part of a customer audit according to ISO/IEC 27001:2022.

This article compares both variants based on seven decision factors: costs, liability, independence, availability, expertise, audit suitability and scalability. You will receive a decision matrix that you can use in the next management meeting, as well as a clear overview of when CIVAC's hybrid model makes sense as a compliance platform and officer-as-a-service. In the end, you will know which variant suits your size, industry and risk situation, which clauses belong in the appointment certificate and how to properly document the report to the responsible supervisory authority in accordance with Art. 37 Para. 7 GDPR. You are reading a comparison that uses paragraphs, numbers and audit logic, not advertising promises.

Key Takeaways

  • For small and medium-sized companies, an internal DPO often costs more than an external one because training, further education and representation arrangements generate hidden personnel costs.
  • The obligation of independence according to Article 38 Para. 3 GDPR is more difficult to enforce internally because the DPO must remain exempt from instructions from superiors who assess him professionally.
  • The appointment certificate, the catalogue of tasks and the reporting line to the management must be documented identically in each model, otherwise Section 43 BDSG applies in a supervisory audit.

Legal obligation: Who needs a DPO anyway?

The obligation to name results from Article 37 Paragraph 1 GDPR and Section 38 BDSG. This includes companies in which at least 20 people constantly process personal data automatically, including working students, interns and marginally employed people. Also included are those responsible whose core activity is the extensive processing of special categories in accordance with Art. 9 GDPR, such as health data in doctors' practices, clinics and care facilities, or criminally relevant data in security companies. Public bodies are also obliged, regardless of the number of employees. Anyone who has to carry out a data protection impact assessment in accordance with Art. 35 GDPR should also appoint a DPO, even if the formal threshold has not been reached, because the DPIA obligation signals an increased risk exposure that can hardly be controlled in an audit-proof manner without a representative.

The obligation does not end with the appointment. According to Art. 39 GDPR, the DPO must check processing records, advise management, coordinate training, participate in impact assessments and be the contact person for the supervisory authority. Failure to do so can be punished with up to 10 million euros or 2 percent of global group sales, Art. 83 Para. 4 GDPR, whichever is higher. Anyone who documents the designation but does not live the role risks the full amount of the fine. Anyone who appoints an external data protection officer does not shift the duties, but rather outsources the execution to a specialist who is not subject to instructions and who nevertheless adheres to the reporting line to management. CIVAC secures this process as a compliance platform and officer-as-a-service and connects the order with the digital directory of all processing. The appointment certificate, signed, filed, verifiable. Anyone who ignores the obligation not only risks the fine, but also the loss of customer contracts in which an effectively appointed DPO is now a standard clause.

Cost comparison: What a DSB really costs

The simple calculation is: an internal DPO charges the personnel budget with a fraction of his working time, an external DPO charges a monthly fee. This calculation falls short and regularly leads to wrong decisions by management. An internal DPO requires certified basic training (TÜV, DEKRA, udis, GDD) for 2,500 to 4,500 euros, annual training of at least 32 hours for 1,200 to 2,000 euros, a trained representative for vacation and sickness, specialist literature and database access, software licences for directories and DPIA, as well as a protected reporting channel to management. For a medium-sized company with 50 to 200 employees, these items add up to 8,000 to 14,000 euros per year, without an hour of productive DSB work being done and without taking into account the opportunity costs of the working time tied up for this.

An external DSB in a medium-sized company is typically between 250 and 1,200 euros per month, depending on the industry, amount of data, international transfers and audit density. Included are the appointment certificate, processing directory, employee training, contact with supervisory authorities, inquiries from those affected and on-call availability in the event of data breaches. The 72-hour deadline according to Art. 33 GDPR can hardly be reliably met with an internal half-day DSB because weekends and bridging days fall within the deadline. CIVAC bundles these services as a compliance platform and officer-as-a-service: Licence the workspace for your internal representatives or have our representatives order it. Both models result in the same file location, the same audit depth and the same 490 ready-to-use templates. Others run compliance like a filing cabinet. We run it like software.

Liability: Who is responsible in the event of damage

The DPO's liability is limited, but not zero, and is often misunderstood in practice. According to Art. 38 Para. 3 GDPR, a DPO may not be removed or disadvantaged because of the fulfilment of his or her duties. He is not liable for data protection violations by the person responsible, but is liable for his own grossly negligent errors in advice, such as an obviously inadequate impact assessment or a failure to warn. In the case of an internal DPO, the internal liability privilege usually applies according to established BAG jurisprudence: slight negligence is covered, moderate negligence pro rata, gross negligence pro rata to full, intent fully. Professional liability insurance for internal DPOs is common, but the amount is often inadequate.

An external DPO takes out financial loss liability insurance in the range of 1 to 5 million euros, higher in special cases. This covers consulting errors in the creation of lists, impact assessments, training concepts and reports to the supervisory authority. Important to know: the liability of the person responsible, i.e. the company itself, remains unchanged according to Art. 82 GDPR, regardless of the DSB model. An external DPO does not shift responsibility, but rather increases the likelihood that errors will be discovered and documented before the damage occurs. During a supervisory audit, the person responsible, not the DPO, is always confronted with the fine, and the amount depends on Art. 83 GDPR. The CIVAC FAQ explains the liability issues in detail and names the typical insurance coverage for each of the 25 agent roles. The auditor calls, the evidence is ready. In practice, fines are rarely directed at the DPO personally, but are often directed at the person responsible, who either ignored the DPO reports or was unable to provide evidence of an effectively appointed DPO. The appointment certificate is therefore the first document that is requested in a supervisory procedure.

Independence: The underestimated stumbling block

Art. 38 Para. 3 GDPR requires that the DPO carries out his tasks without instructions and reports directly to the highest management level. Art. 38 Para. 6 GDPR prohibits conflicts of interest from other tasks. This is precisely where the internal model regularly collides with reality: a DPO who is also the IT manager, human resources manager, managing director or data protection officer runs into conflicts of interest. He would have to control himself when checking a processing list from his own area of ​​responsibility and he would have to criticize his own decisions in front of the management. The supervisory authorities (LfDI Baden-Württemberg, BayLDA, BfDI, HmbBfDI) have determined in several resolutions and fine proceedings that IT managers, managing directors, human resources managers and compliance officers are not allowed to be DPOs at the same time. In 2020, the Belgian supervisory authority imposed a fine of 50,000 euros precisely because of this personal union.

An external DPO is structurally independent. He is not in the hierarchy, has no competing goals, no interest in promotion and no colleagues who filter his reports from management. This is exactly the most common reason why medium-sized companies with between 50 and 500 employees choose the external route, even if suitable professional staff are available internally. The appointment certificate should explicitly state the reporting line: direct access to management, written reports twice a year, right to escalate if risks are not resolved, participation in relevant management meetings related to data protection. These clauses belong in every CIVAC workspace and in every officer-as-a-service order, documented and Article 38-proof. Anyone who licences the workspace receives the same clause texts for their own internal order and can adapt them to the size of the company. Licence the workspace for your internal representatives or have our representatives appointed; in both cases the independence rule will be adhered to structurally, not just formally.

Availability and response time: 72 hours is short

Art. 33 GDPR requires you to report a data breach within 72 hours of becoming aware of it. The clock starts on awareness. Anyone who notices a wave of phishing on Friday evening has until Monday morning to send a complete report to the responsible supervisory authority, including a description of the type of breach, the categories of affected persons, the likely consequences, the technical and organisational measures taken and the contact details of the DPO. An internal DPO, who performs the function in addition to other tasks, is rarely available on weekends. A representation arrangement is mandatory, but is classified as insufficiently documented in two out of three audits because the representative neither knows the directory nor has the authority to report.

An external DPO contractually ensures on-call availability, usually on weekdays from 8 a.m. to 6 p.m., with an emergency number for weekends and public holidays. CIVAC guarantees an SLA of two business days for the order itself and a four-hour response to reported data breaches, each with an escalating reporting line to management. The 490 ready-to-use audit templates in the workspace cover reporting forms for every German state data protection authority, notification of those affected in accordance with Art. 34 GDPR and internal documentation. Anyone who licences the workspace receives the same templates for their own representative. Anyone who orders Officer-as-a-Service lets CIVAC meet the deadline and only takes care of the release. Licence the workspace for your internal representatives or have our representatives order it; in both cases the same operational machine runs in the background. The SLA is fixed in the appointment certificate so that in an emergency, management does not have to negotiate response times but can rely on a signed contract.

Expertise: What a DPO must be able to do today

The expertise of the DSB is not conclusively defined in Article 37 Para. 5 GDPR, but is specified by the supervisory authorities. Required are: in-depth knowledge of the GDPR and the BDSG, familiarity with the industry-specific regulations (TTDSG, KHZG, IT Security Act, NIS 2 Implementation Act, KRITIS Regulation), practical experience with processing directories and impact assessments, IT technical understanding (encryption, pseudonymization, cloud architectures, Schrems II-compliant transfer mechanisms), audit experience ISO/IEC 27001:2022 and communicative sovereignty towards supervisory authorities, works councils and management. An internal DPO regularly needs 12 to 18 months to cover this breadth independently, and at least three complete audit cycles before it can act confidently in audit situations.

An external DPO has this breadth. At CIVAC, all DSB mandates are supervised by representatives who have at least five years of professional experience, TÜV or udis certification and ISO/IEC 27001:2022 training. The cross-sectional perspective from several mandates is valuable: Anyone who looks after 30 medium-sized customers will see the same error in 30 variants and can address it in advance before it occurs with the 31st client. An internal DPO only sees his own organisation and relies on conferences and specialist literature to know the state of the market. For highly specialised sectors (research, pharmaceuticals, banks with BAFIN supervision, KRITIS sectors) an internal DPO who has the technical depth can make sense. For medium-sized businesses outside of these specialties, the breadth of the external model clearly predominates. A look at the Overview of the 25 officer roles shows how closely the DPO, ISB and compliance officer have to work together, and how helpful it is to get all three from a single source.

Audit suitability: What the auditor wants to see

A supervisory inspection does not begin with questions, but rather with a written catalogue of file requirements, which is typically received three to five working days before the on-site appointment. The auditor wants to see the appointment certificate, the processing list in accordance with Art. 30 GDPR including all updates from the last 24 months, the data protection impact assessments carried out in accordance with Art. 35 GDPR, the training records from the last three years with lists of participants and content documentation, the reports from the DPO to the management, the representation regulations, the procedure for handling requests from those affected in accordance with Art. 12 to 22 GDPR and the list of all Data breach reports. If these documents are complete and consistent, the on-site inspection takes 4 to 8 hours. If something is missing, the review is continued in writing and the risk of a fine increases significantly.

An internal DPO without a structured workspace often manages these documents in Outlook, SharePoint folders and Excel lists with unclear versions. During the check, the search begins and inconsistencies become visible. An external DPO with the CIVAC workspace stored all documents in an audit-proof structure, versioned, with a time stamp, responsibility and electronic signature. The 490 audit templates cover the file catalogue of the most common state data protection authorities, including the typical forms for each state. Audit-proof, documented, Section 30-proof. This also applies to the licensed workspace in the internal model, because the platform is identical. Anyone switching from another provider can use the CIVAC platform to catch up on the document situation in less than two weeks because templates, directory structure and report formats are immediately available. The auditor calls, the evidence is ready.

Decision matrix: When which model fits

The decision follows three axes: size, risk class, in-house expertise. Internal model recommended: from 250 employees, with their own legal or compliance department, in highly specialised industries (pharmaceuticals, clinical research, KRITIS sectors with their own ISB), if data protection is an economically relevant core business and a full-time position seems justified. The prerequisite is a clarified reporting line directly to the management, a documented and trained representative, an annual training budget of at least 1,500 euros per person and a clear demarcation from IT, HR and management tasks. An internal DPO function without these requirements is formally set up, but is practically not audit-proof.

External model recommended: 20 to 250 employees, medium-sized companies without their own legal department, high audit frequency by customers (ISO 27001, TISAX, BAFIN audit, customer compliance questionnaires), frequent data breach risks due to IT outsourcing, international processing Third country transfer and standard contractual clauses. The monthly costs of 250 to 1,200 euros are calculable and immediately provide a complete set of files, including all relevant contracts for order processing. Hybrid model recommended: 50 to 500 employees with an expert internal data protection coordinator who uses the licensed CIVAC workspace and relies on the external DPO for peak loads (audit, data breach, DPIA, supervisory procedures). The hybrid model combines in-house knowledge with external audit resistance. In concrete terms, this means: Licence the workspace for your internal representatives or have our representatives order it, both of which can be displayed at CIVAC under one appointment certificate and with a single invoice per quarter. The choice between the three models should be checked at the latest every time the number of employees doubles, every time there is a change in industry and every major acquisition, because the audit requirements shift accordingly.

From comparison to ordering: This is how you proceed

The comparison does not end in a table, but in an appointment certificate. Three steps lead you there: First, a brief analysis of your data processing (number of employees, industry, audit requirements, existing compliance functions, international transfers) in a 30-minute appointment. Secondly, written model proposal with a list of tasks in accordance with Art. 39 GDPR, reporting line, fees, representation regulations and escalation rights. Thirdly, appointment certificate with effect from the first of the next month, notification to the responsible supervisory authority in accordance with Art. 37 Para. 7 GDPR and entry in the workspace directory. CIVAC delivers these three steps as a compliance platform and officer-as-a-service in an SLA of two working days, instead of the industry-standard two to six weeks, and can take over the migration of existing DPO documentation if desired.

If you are still unsure whether an internal, external or hybrid DPO is suitable for your situation, write to us briefly about your situation, preferably with two lines about the industry, number of employees and current data protection list. We will respond within one working day with a technical assessment and a reliable model proposal. Turn reading into a mandate.: info@civac.de or via the contact form on civac.de. You will not receive a sales presentation, but rather a concrete answer that you can present to management without modification. If the model fits, the appointment certificate follows within the SLA. If not, we will tell you too and suggest the appropriate route. For us, turning reading into an order means: an appointment certificate, a reporting line, a workspace, a documented audit status and an SLA that is resilient. This means that the DSB question has been clarified not only legally, but also operationally.

FAQ

When are companies in Germany obliged to appoint a data protection officer?

According to Section 38 BDSG, the obligation applies as soon as at least 20 people constantly process personal data automatically, including working students and interns. Regardless of the number of employees, it applies to extensive processing of special categories according to Art. 9 GDPR, such as health or religious data. Public bodies are also always obliged. The obligation arises from the day on which the threshold is permanently exceeded.

Can the managing director or IT manager also be the data protection officer?

No. The supervisory authorities reject this personal union because Article 38 Para. 6 GDPR prohibits conflicts of interest. Managing directors, IT managers and HR managers are not allowed to be DPOs at the same time because they decide on exactly the processing that the DPO should control. Other functions are only permitted if there is no professional self-control and no reporting line is violated.

What costs does an external data protection officer cause in medium-sized companies?

In medium-sized companies with between 20 and 250 employees, the fee is typically 250 to 1,200 euros per month, depending on the industry, international transfers and audit density. Included are the appointment certificate, processing directory, training, supervisory contact and on-call availability. CIVAC offers fixed packages with a transparent SLA of two business days for orders and a four-hour response in case of data breaches.

How long does it take to appoint an external DPO from CIVAC?

The order is placed within two working days from the signing of the contract. This includes the appointment certificate with a list of tasks in accordance with Art. 39 GDPR, reporting line to the management and notification to the responsible supervisory authority in accordance with Art. 37 Paragraph 7 GDPR. Two to six weeks are typical in the industry. CIVAC shortens this through the platform, prepared audit templates and a fixed onboarding process.

Is the external data protection officer liable for data breaches in the company?

No, the liability of the person responsible under Art. 82 GDPR remains with the company. The external DPO is only liable for its own grossly negligent advice errors, such as a clearly inadequate impact assessment. These risks are covered by its financial loss liability insurance, at CIVAC with a coverage amount in the single-digit million range per claim. The appointment certificate documents these limits in writing.

Can I switch from the internal DSB model to an external or hybrid?

Yes, a change is possible at any time. CIVAC takes over the existing documentation, checks it for auditability, closes gaps and migrates it to the workspace. The old order is revoked and the new one is reported to the supervisory authority. The process typically takes two to three weeks and includes a handover meeting with the internal predecessor to secure knowledge.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles