Order DSB for 20 or more employees: Obligation, deadline and appointment certificate
As soon as 20 people in the company are constantly engaged in automated processing of personal data, Section 38 BDSG applies. We show you how to document the order in a legally compliant manner, report it and fill it internally and externally.
According to Section 38 Paragraph 1 BDSG, a data protection officer must be appointed as soon as at least 20 people are generally constantly involved in the automated processing of personal data. This threshold applies in addition to the obligations under Article 37 GDPR and affects the majority of medium-sized companies in Germany. The order must be made in writing, the appointment certificate must be handed over to the representative and reported to the responsible supervisory authority.
We explain the exact threshold, the formal requirements for the appointment certificate, the reporting deadline and the difference between internal and external orders. You will learn how the obligation differs from the risk analysis according to Article 37 Paragraph 1 Letters b and c GDPR and how you can organise the reporting line to management. The CIVAC compliance platform and officer-as-a-service model brings this process to verifiable completion in two business days.
Key Takeaways
- From 20 people with automated data processing, Section 38 BDSG applies, regardless of industry, risk or sales.
- An appointment certificate, notification to the supervisory authority and publication of contact details are mandatory; a formal form is not enough.
- External orders via CIVAC are completed within two working days, including the appointment certificate, reporting line and workspace.
What exactly Section 38 BDSG requires
§ 38 Para. 1 BDSG requires the appointment of a data protection officer as soon as at least 20 people are generally constantly involved in the automated processing of personal data. The standard supplements Art. 37 GDPR with a quantitative threshold that applies regardless of the risk profile of the processing.
Constantly does not mean exclusively or full-time. Anyone who regularly enters, changes, accesses or sends personal data in an IT system in their day-to-day business counts. E-mail correspondence, CRM maintenance, payroll accounting, applicant management and customer service typically fall under this.
The counting is based on headcount, not on the basis of full-time equivalents. Part-time workers, mini-jobbers, working students and temporary employees count in full, provided they regularly work with personal data. External service providers are generally not included if they act as processors.
In addition to the 20-person threshold, Article 37 Paragraph 1 Letters b and c GDPR apply independently. Anyone who carries out core activities in extensive, regular systematic observation or processes special data categories in accordance with Art. 9 GDPR is also required to order under 20 people. The role of the data protection officer is identical in both cases.
The threshold must be checked on a daily basis. Growth, branch openings or takeovers trigger the obligation on an ad hoc basis. The law does not provide for a waiting period; the appointment must be made immediately as soon as the threshold is exceeded.
The appointment certificate: form, content, storage
The order is made in writing or electronically in accordance with Section 38 Paragraph 2 i. V. m. § 6 para. 1 BDSG. An oral order is not permitted and, in the event of a dispute, will lead to problems with providing evidence to the supervisory authority. The appointment certificate is signed by the authorised representative.
In terms of content, the document must contain the name of the representative, the appointment date, the legal basis (Section 38 BDSG, Art. 37 GDPR), the list of tasks in accordance with Art. 39 GDPR and the reporting line to the highest management level. In the case of an external order, the contractual partner and the contract period are also named.
The appointment certificate must be handed over to the representative, archived in the personnel file or contract file and kept for the entire order period plus the retention period in accordance with commercial and tax law requirements. The appointment certificate, signed, filed, verifiable.
The contact details of the data protection officer must be communicated to the responsible supervisory authority in accordance with Article 37 (7) GDPR and published on the company website. The report is made using the state authority's online form; a confirmation of receipt should be kept on file.
The CIVAC platform provides a tested template that covers all mandatory fields and is stored in an audit-proof manner in the workspace after signature. Audit-proof, documented, Section 38-proof. The auditor calls, the evidence is ready.
Order internally or externally: the decision matrix
Art. 37 Para. 6 GDPR allows both the internal appointment of an employee and the external outsourcing to a service provider. Both models are recognised as equally valid, but differ significantly in terms of effort, liability and availability.
When ordering internally, the employee requires specialist knowledge in accordance with Art. 37 Para. 5 GDPR, sufficient resources in accordance with Art. 38 Para. 2 GDPR and protection against dismissal due to their tasks in accordance with Section 6 Para. 4 BDSG. Protection against dismissal takes effect one year after the end of the appointment. A conflict of interests with the main task must be ruled out, which regularly disqualifies managing directors, IT managers and HR managers.
External appointment shifts liability, further training and representation arrangements to the service provider. The costs can be planned and there are no downtimes due to vacation or illness. The external representative has experience from several mandates and knows the expectations of the respective supervisory authority.
If you have more than 250 employees or a high processing risk, a hybrid model is often recommended: an internal contact person for day-to-day business, an external DPO for the formal appointment. CIVAC supports both ways. Licence the workspace for your internal representatives, or have our representatives appoint them.
The decision should be documented, including justification. A later supervisory inquiry often first focuses on the choice of model and its justification in the light of Art. 38 Para. 2 GDPR.
Reporting to the supervisory authority: deadline and content
Art. 37 Para. 7 GDPR obliges the person responsible to provide the contact details of the data protection officer to the responsible supervisory authority. The standard does not specify a legal deadline, but the supervisory authorities expect notification immediately after the order is placed, usually within two weeks.
The state data protection authority at the headquarters is responsible. For groups with several locations, a group-wide order can make sense, provided the representative can be easily reached from each location in accordance with Art. 37 Para. 2 GDPR.
The report is made using the online form of the respective authority. Mandatory fields are company name, address, commercial register number, name and contact details of the representative and the order date. If the appointment is made externally, the law firm or consultancy commissioned will also be named.
Changes to the order, such as a change of representative or termination of the order, must also be reported. Missed updates regularly lead to complaints during routine checks and can be punished with fines of up to 10 million euros or 2 percent of global annual turnover in accordance with Article 83 (4) (a) GDPR.
The CIVAC FAQ documents the respective reporting path for all 16 state authorities, including the form URL and processing time. The workspace manages the report as an independent process with status tracking and confirmation of receipt.
Publication of contact details on the website
Art. 13 Para. 1 lit. b GDPR requires that the contact details of the data protection officer be published in the data protection declaration of the website. The obligation applies in addition to reporting to the supervisory authority and is subject to sanctions in its own right.
It is common practice to provide a name or job title, an email address and a postal address. The email should go directly to the representative and not go to the general mailbox, as confidentiality must be maintained in accordance with Art. 38 Para. 5 GDPR.
If the order is external, the law firm or consultancy is designated as the contact point. A separate functional address such as datenschutz@unternehmen.de with automatic forwarding to the external representative is permissible and common in practice.
The supervisory authorities regularly check the publication as the first step in an investigation. Missing or outdated information leads to complaints, often accompanied by a request to make improvements within 14 days. Repeated cases will be subject to fines.
In addition to the data protection declaration, it is recommended that it be included in the legal notice and in internal directories such as the processing directory in accordance with Art. 30 GDPR. The CIVAC templates for the DSB presence contain the tested text module for the data protection declaration.
Tasks according to Art. 39 GDPR in everyday operations
Art. 39 GDPR defines the catalogue of tasks: informing and advising the person responsible, monitoring compliance, training employees, advising on data protection impact assessments in accordance with Art. 35 GDPR and cooperation with the supervisory authority. The tasks are binding, delegation to third parties is only possible to a limited extent.
Recurring processes occur in everyday operations: processing requests from those affected in accordance with Articles 15 to 22 of the GDPR within one month, monitoring data breach reports in accordance with Article 33 of the GDPR within 72 hours, checking new processing activities and updating the directory.
The annual mandatory tasks include audits of the processors, Employee training, updating of technical and organisational measures in accordance with Art. 32 GDPR and report to management. The reporting obligation arises from Art. 38 Para. 3 GDPR and is a prerequisite for the direct reporting line.
In data protection impact assessments, the representative acts as an advisory body without assuming responsibility for decision-making. If the risk remains high, prior consultation with the supervisory authority must be initiated in accordance with Art. 36 GDPR, with a processing time of up to eight weeks.
CIVAC manages the recurring tasks in a workspace calendar with deadline control and escalation. 490 ready-to-use audit templates cover the typical audit reasons, from data subject law to data processor contracts.
Sanctions for missing or incorrect orders
Failure to appoint a mandatory data protection officer is punishable by a fine of up to 10 million euros or 2 percent of global annual turnover, depending on which amount is higher, according to Article 83 Paragraph 4 Letter a of the GDPR. The same level of sanctions applies to violations of the position of the representative in accordance with Art. 38 GDPR.
In addition, Section 43 Paragraph 1 No. 3 BDSG applies with a fine of up to 50,000 euros in the event of intentional or negligent non-appointment. In the case of legal entities, there is also the liability of the management in accordance with Section 130 OWiG, which is independently sanctioned as a breach of supervisory duty.
In practice, the supervisory authorities weight the question of the appointment as an indicator of the company's data protection maturity. Anyone who has failed to recognise the obligation to place an order is typically subject to more comprehensive and in-depth checks in subsequent audits, with correspondingly greater effort.
In the event of a data breach, the lack of an order significantly increases the sanctions situation. Reporting in accordance with Art. 33 GDPR formally requires the cooperation of the representative, whose absence is viewed as an organisational deficit in the fine procedure and is included in the amount of the sanction.
A late appointment does not completely cure the past, but reduces the risk of fines in future incidents. The authorities reward proactive improvements as long as they occur before a complaint is made. Deadline expires as soon as we become aware of it.
Costs and effort: internal versus external ordering
The costs of an internal appointment include training, ongoing training, replacement, resources for the task and protection against dismissal. Depending on the size of the company, a qualified internal DPO requires between 0.2 and 1.0 full-time equivalents of their working time for the representative role.
TÜV-certified basic training costs 2,500 to 4,000 euros, annual training costs a further 1,000 to 2,000 euros. In addition, there are personnel costs for the exempt working hours, which can be between 20,000 and 60,000 euros per year depending on the salary level.
External orders are typically billed as a flat rate or hourly quota. For medium-sized companies with 50 to 250 employees, the range is between 6,000 and 18,000 euros per year, depending on the industry, risk and extent of processing.
CIVAC offers both options within a fixed price range. The Workspace licence for internal representatives includes 490 audit templates, the appointment certificate, the report to the supervisory authority and the reporting line to management. The officer-as-a-service model provides an external DPO that can be ordered within two working days.
The comparison of the models should not only look at the direct costs, but also the liability risk, availability in the event of data breaches and the response time to requests from authorities. Others run compliance like a filing cabinet. We run it like software.
Can be ordered with CIVAC in two working days
The CIVAC Compliance Platform and Officer-as-a-Service bundles the appointment of a data protection officer in a defined process with a 2-working day SLA. Instead of two to six weeks of classic consultant coordination, you receive an appointment certificate, supervisory report, reporting line and workspace access in one delivery package.
The platform covers 25 representative roles, 93 controls according to ISO/IEC 27001:2022 and 490 ready-to-use audit templates. The data resides entirely in the EU, the reports are documented in an audit-proof manner and are immediately available for routine audits. The auditor calls, the evidence is ready.
Licence the workspace for your internal representatives, or have our representatives order it. Both models use the same infrastructure, templates and escalation path. Switching between models is possible at any time, without data loss or a new onboarding phase.
For medium-sized companies with 20 or more employees, the external DPO is often the more economical option, especially if no experienced internal person is available. For larger organisations, we recommend the workspace with an internal lead and CIVAC as an escalation authority.
The initial contact is made informally. We will check your order requirement within 24 hours, suggest the appropriate model and provide the appointment certificate for you to sign. Turn reading into an assignment. Write to info@civac.de or use the contact form on civac.de.
FAQ
For how many employees do we have to appoint a data protection officer?
As soon as at least 20 people are constantly involved in the automated processing of personal data, Section 38 (1) BDSG applies. Regardless of this, an obligation can still exist without this threshold according to Art. 37 GDPR, for example when processing special categories of data or extensive systematic monitoring.
Do part-time employees and working students count towards the 20-person threshold?
Yes, the count is based on headcount, not full-time equivalents. Part-time workers, mini-jobbers, working students and temporary employees are fully counted as long as they regularly work with personal data in IT systems in their day-to-day business. External processors are generally not included.
How long does it take for the DPO to report to the supervisory authority?
The report is made via the online form of the responsible state authority and should be completed within two weeks of ordering. A confirmation of receipt is usually sent within a few working days. Changes in the appointee or terminations are also subject to reporting.
Can the managing director himself become a data protection officer?
No, the managing director is leaving due to a conflict of interests in accordance with Article 38 (6) GDPR. The same regularly applies to IT managers, HR managers and marketing managers, as they are responsible for the processing, the lawfulness of which the officer is supposed to monitor. The supervisory authorities object to such constellations.
What fines are there for missing an order?
According to Art. 83 Para. 4 lit. a GDPR up to 10 million euros or 2 percent of the global annual turnover. In addition, Section 43 Paragraph 1 No. 3 BDSG applies up to 50,000 euros. The management is personally liable for breaches of supervisory duties in accordance with Section 130 OWiG.
How quickly can CIVAC appoint an external DPO?
The CIVAC SLA is two working days from the time the order is placed. During this period, you will receive the appointment certificate, the report to the supervisory authority will be prepared, workspace access will be set up and the reporting line to management will be defined. Classic consulting processes take two to six weeks.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.