77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
Order DSB: Obligation, deadline and appointment certificate according to § 38 BDSG
Data Protection & Privacy

Order DSB: Obligation, deadline and appointment certificate according to § 38 BDSG

29 July 202612 min readBy Lena Vogt
CIVAC

Anyone who has to appoint a data protection officer rarely has time to lose: Obligation according to Section 38 BDSG, report to the supervisory authority, appointment document in the audit. This guide separates compulsory from freestyle and shows the operational path.

According to Section 38 BDSG, non-public bodies must appoint a data protection officer as soon as at least 20 people are generally constantly involved in the automated processing of personal data. In addition, there are the cases according to Art. 37 Paragraph 1 GDPR: core activity with extensive regular monitoring of those affected or extensive processing of special categories according to Art. 9 GDPR. Anyone who breaks these thresholds doesn't order at some point, but immediately. The supervisory authority expects a written order, proper proof and a report of the contact details in accordance with Art. 37 Para. 7 GDPR. Without these three elements, the DPO appointment is vulnerable in the audit, and usually with unpleasant consequences for management and those responsible.

This article answers four questions precisely: When do you have to appoint a DPO, what does the appointment certificate look like in a legally secure manner, how do you report the order correctly, and how do you get from the decision to the appointed, registered and working data protection officer in two working days? We separate duty from choice, name the operational levers and show which evidence counts in the audit and which does not. CIVAC is a compliance platform and officer-as-a-service in which the appointment certificate, reporting line and audit templates run hand in hand. The appointment certificate, signed, filed, verifiable.

Key Takeaways

  • The DSB obligation results from Section 38 BDSG (20-person threshold) and Art. 37 GDPR (core activity or Art. 9 data); Both facts must be examined independently.
  • The order must be made in writing, the DPO must be reported to the supervisory authority and the contact details must be published in the data protection declaration.
  • An external DPO via Officer-as-a-Service decouples the mandate from personnel risk because representation, accessibility and documentation are contractually guaranteed.

Who needs to order a DPO: Thresholds from BDSG and GDPR

The obligation to order follows two tracks that must be checked separately. Section 38 (1) BDSG requires a data protection officer as soon as at least 20 people are generally constantly involved in the automated processing of personal data. Part-time employees, working students, interns and temporary workers count as long as they have regular access. This means that the German threshold is low compared to other European countries. In addition, Art. 37 Para. 1 GDPR applies regardless of the number of people as soon as the core activity consists of extensive, regular monitoring of those affected or special categories according to Art. 9 GDPR as well as criminal data according to Art. 10 GDPR are extensively processed.

Three typical constellations from practice: An online shop with 18 employees, but profiling and remarketing on a large scale, is according to Art. 37 Para. 1 lit. b GDPR mandatory. A tax law firm with 22 employees falls under Section 38 BDSG as soon as almost everyone works with client data automatically. A hospital service provider processes health data extensively and is also obliged to do so in accordance with Article 37 (1) (c) GDPR. Anyone who is obligated and does not order risks fines according to Art. 83 Para. 4 GDPR of up to 10 million euros or 2 percent of the global annual turnover.

An initial, documented threshold check therefore belongs in the appointment process for the data protection officer and in the processing directory according to Art. 30 GDPR. The review should be repeated annually because growth, outsourcing decisions and new products can move the threshold in either direction. A documented negative finding provides as reliable protection in the audit as an order, as long as the justification is clear and the threshold test specifies the deadline and the underlying processing activities.

The appointment certificate: mandatory content and formal requirements

The order is placed in accordance with Art. 37 Paragraph 1 GDPR in conjunction with Section 38 BDSG. A mandatory written form is not explicitly required in the GDPR text, but the supervisory authorities expect a written appointment certificate as verifiable proof. In practice, the following applies: without a certificate, there is no verifiable order time, no verifiable list of tasks, and no documented promise of freedom from instructions. The appointment certificate must contain at least the name and contact details of the person appointed, the order date, the scope of tasks in accordance with Art. 39 GDPR, the reporting line to the highest management level in accordance with Art. 38 Paragraph 3 GDPR and the assurance of the necessary resources. This also includes an express clarification of the freedom to issue instructions in accordance with Article 38 Paragraph 3 of the GDPR and confidentiality in accordance with Section 6 Paragraph 5 of the BDSG.

For the internal DPO, the special protection against dismissal from Section 38 Paragraph 2 in conjunction with Section 6 Paragraph 4 of the BDSG is added. This protection against dismissal only ends one year after dismissal and binds the company beyond the actual mandate. For external DPOs, the service contract regulates representation arrangements, response times, insurance sum and escalation path. The insurance should have at least five million euros in coverage, because claims for damages according to Art. 82 GDPR can be significant, especially when extensive profiling or when processing special categories of data.

CIVAC provides the appointment certificate as a versioned audit template in the workspace and automatically links it to the reporting line, task list and audit calendar. The auditor calls, the evidence is ready. Anyone who goes the external route will find the operational description of the DSB mandate, including interfaces to IT security and compliance, in the Role Overview. Audit-proof, documented, Section 38-proof. The certificate is saved in the workspace with a time stamp and signature, so that any subsequent audit access proves the time of order without any search effort.

Reporting to the supervisory authority and publication

The reporting obligation begins with the order. Art. 37 Para. 7 GDPR requires that the contact details of the data protection officer be communicated to the responsible supervisory authority. In Germany, the respective state data protection authority is responsible, such as the BayLDA in Bavaria, the LfDI Baden-Württemberg or the BlnBDI in Berlin. Reporting is usually done via online forms; Some authorities also require confirmation of the order by uploading the appointment certificate. A missing or delayed report is considered a violation subject to a fine in accordance with Article 83 Paragraph 4 Letter a of the GDPR and becomes visible in many federal states during the first event-related check.

In parallel, the contact details of the DSB must be published in the data protection declaration of the website and in the information in accordance with Articles 13 and 14 of the GDPR. It is recommended to use a generic email address, such as datenschutz@unternehmen.de, instead of a personal address, so that changes can be made without chains of changes. Anyone who publishes a personal address risks subsequent performance costs in all published data protection notices, in order processing contracts and in the supervisory report after a change of mandate. For corporations with numerous websites, this effort quickly increases.

The publication serves the rights of those affected in accordance with Articles 15 to 22 of the GDPR: information, correction, deletion, data portability, objection. Anyone who works properly here avoids supervisory inquiries and creates the basis for the orderly processing of inquiries within the monthly deadline in accordance with Art. 12 Para. 3 GDPR. CIVAC keeps the registration confirmation in the workspace and reminds you of address changes when changing mandates. Deadline begins as soon as we become aware of it. The template for the registration letter is available and is addressed to the responsible state authority, so that the second half of the working day is sufficient for the supervisory report and the ordering process is fully documented at the end of the second working day.

Internal, external or hybrid: which model suits which company

The GDPR allows both models, and the choice is an operational one, not a purely legal one. An internal DPO knows the processes, but is at risk of bias: managing directors, IT managers, human resources managers and marketing managers are excluded according to Section 6 Paragraph 5 BDSG because they are also responsible for data-intensive processing. In smaller companies the choice is therefore narrow. In addition, there is special protection against dismissal in accordance with Section 6 Paragraph 4 BDSG, which creates a binding employment law that goes beyond the mandate. External DPOs provide routine, representation arrangements and insurance coverage; They are subject to the same requirements under Art. 38 GDPR and must regularly demonstrate their expertise.

The rule of thumb: up to 100 employees or in heavily regulated industries such as health, insurance, financial services, the external route predominates. If you have 250 employees or more, a hybrid solution with an internal coordinator and external specialist responsibility is worthwhile. For internationally active corporations, language and time zone coverage must also be checked, as the 72-hour period according to Art. 33 GDPR also runs over holidays and weekends. Anyone who has not secured mandates over the summer break or at the turn of the year risks reporting in arrears and thus an additional supervisory referral.

CIVAC covers both models in a dual framework: Licence the workspace for your internal representatives, or have our representatives appointed. The appointment certificate, the reporting line to management, the audit templates according to Art. 30 GDPR and the 72-hour reporting path according to Art. 33 GDPR run via the same workspace in both models. Others run compliance like a filing cabinet. We run it like software. If you would like to compare both models, you can find the operational differences including cost and escalation paths in the FAQ overview.

Tasks according to Art. 39 GDPR: What the DPO has to do from day 1

Art. 39 GDPR defines five core tasks that must be adhered to from day one. First: informing and advising the person responsible and the employees about their obligations under the GDPR, BDSG and other data protection regulations. Second, monitoring compliance with these regulations, including strategies for assigning responsibilities, staff awareness and training, and related audits. Third: Advice on data protection impact assessments in accordance with Art. 35 GDPR and monitoring their implementation. Fourth: cooperation with the supervisory authority. Fifth: contact point for the rights of those affected and for employees.

These obligations are not symbolic. A missing DPIA for AI applicant management, a missing proof of training or an unanswered request for information will be visible in the examination and can trigger individual supervisory procedures. The operational answer is: documented audit calendar, documented audits, documented training, documented DPIAs. In the CIVAC workspace, the 490 audit templates are linked to the audit calendar and task list, so that each task item from Art. 39 GDPR has its evidence path. The templates are based on the testing schemes of the German supervisory authorities and will be updated with new guidelines from the EDPB.

Anyone who does this cleanly also fulfils Art. 5 Para. 2 GDPR, the accountability requirement. Accountability requires not only compliance with the principles set out in Article 5 Para. 1 GDPR, but also proof of them. A DPO without documented task performance is a risk in the audit, not protection. The appointment certificate, signed, filed, verifiable. If you want to see the data protection officer's list of tasks as a basis for the mandate, you will find the operational description with interfaces, reporting line and typical annual cycle in the DSB role profile. The templates for training, DPIAs and the processing directory are stored there as modules and can be adapted per mandate.

What happens without an order: fines, supervision, liability

Failure to order is a violation of Art. 37 GDPR and is subject to a fine under Art. 83 Para. 4 lit. a GDPR: up to 10 million euros or 2 percent of the global annual turnover of the previous financial year, whichever is higher. The supervisory authorities in Germany have proven several times that the lack of a DPO appointment is punished as a separate violation, often in connection with other findings such as an inadequate record of processing activities in accordance with Art. 30 GDPR or delayed data breach notification in accordance with Art. 33 GDPR. The 72-hour period runs from knowledge, not from order.

There are also civil law risks: claims for damages from those affected in accordance with Art. 82 GDPR, reputational risks in reporting obligations to supervisors and those affected, and in the B2B context, the loss of orders because clients have the data processor's DSB order documented in accordance with Art. 28 GDPR. An order fails not because of prices, but because of a lack of evidence. Anyone who delays the order increases the scope for attack and reduces the scope for negotiation. In tenders in the public sector, the lack of a DSB order is an exclusion criterion in many tenders.

A missing order cannot be cured through subsequent activity, because the time of the order remains documented. Even a retroactive appointment certificate would be recognizable as such in the audit and would not eliminate the original breach of duty. Turn reading into an assignment. The operational consequences can all be averted if the order, notification and proof are received within a few working days and the DPO is integrated into the inspection calendar and reporting line from the first day. Anyone who acts quickly here reduces the risk of fines and restores the ability to deliver to B2B customers without a transition phase.

Timeline: From decision to order in two working days

A DSB appointment typically takes between two and six weeks: selection of the person or service provider, contract negotiation, onboarding, handover of tasks, reporting to the supervisory authority. With the CIVAC path, two working days are realistic because the appointment certificate, reporting line, catalogue of tasks and registration letter are available as versioned audit templates and are linked to the appointed person in the workspace. Day 1: Document threshold check, define model (internal, external, hybrid), sign appointment certificate, activate reporting line. Day 2: Report to the supervisory authority, publish contact details in the data protection declaration and employee information, activate the task list and document interfaces to IT and HR.

From day 3, the recurring duties run productively: maintain the directory in accordance with Art. 30 GDPR, inventory order processing in accordance with Art. 28 GDPR, plan DPIAs in accordance with Art. 35 GDPR, roll out the training plan. The audit calendar in the workspace reminds you of quarterly reports to management in accordance with Art. 38 Para. 3 GDPR and of the annual effectiveness audit. Anyone who orders an external DPO via CIVAC will, in the same step, receive a written representation policy and 24-hour availability for data breaches, secured by a documented escalation matrix.

This shortens the response time within the 72-hour period according to Art. 33 GDPR and closes the most common audit gap: documented responsiveness. The SLA of two working days replaces the classic onboarding bottleneck. In industries with seasonal or quarterly closing burdens, this shortened provision is the real lever because it prevents the DSB obligation from becoming a permanently open position on the risk list. Audit-proof, documented, Section 38-proof. Once you have set up the order path, you can reuse it for other officer roles from the same workspace, such as information security officer or whistleblower protection. The reusable audit templates make multi-role operations economically plannable.

Interfaces: DSB, ISB, compliance and whistleblower protection

The DSB never works in isolation. The interface to the information security officer is close: technical and organisational measures according to Art. 32 GDPR overlap with the ISMS according to ISO/IEC 27001:2022 and with the NIS 2 obligations for essential and important facilities that are to be implemented in Germany via the NIS2UmsuCG. A data breach is often also a security incident, which triggers two parallel reporting channels: 72 hours to the data protection supervisory authority in accordance with Art. 33 GDPR and 24 hours of early warning plus 72 hours of follow-up notification to the BSI in accordance with NIS-2. Anyone who does not manage both paths in one workspace loses time and risks contradictory statements of facts to two supervisory authorities.

The interface to the internal reporting office according to the HinSchG must also be taken into account. Information relating to data protection must be received via the reporting office and processed further in compliance with confidentiality. The reporting office representative works confidentially, the DPO works without instructions, and both roles must coordinate without role conflict. Compliance, money laundering prevention and LkSG can also have data protection touchpoints, for example in sanctions list screenings, supplier audits and reporting to BAFA. The hygiene officer or the occupational physician also process health data and require a clear data protection basis.

CIVAC maps these interfaces as a role overview in the workspace, so that the DPO, ISB, compliance officer and reporting office officer carry out their tasks with clear reporting lines. A common audit calendar prevents duplication of work and closes audit gaps between mandates. Anyone who orders multiple roles via the same workspace benefits from uniform templates, a uniform reporting line and a uniform evidence architecture. This measurably reduces the compliance organisation's total operating costs and simplifies the annual management review and reports to the supervisory board or advisory board. Consolidated evidence also reduces the effort involved in external audits.

From appointment to verifiable mandate: The CIVAC path

The order is the beginning, not the end. What counts over the next few years is the evidence: appointment certificate, reporting line, audit calendar, audit templates, proof of training, DPIAs, data breach logs, reporting confirmations. CIVAC is a compliance platform and officer-as-a-service that maintains this evidence as connected data objects in the workspace and secures it via 490 ready-to-use audit templates, a 72-hour reporting path in accordance with Art. 33 GDPR and EU data residency. The 25 officer roles can be ordered from the same workspace, so that DPO, ISB, compliance, whistleblower protection and hygiene officer work in a uniform architecture. This architecture is tailored to the requirements of German and European supervisory authorities.

The dual frame remains: Licence the workspace for your internal representatives, or have our representatives order it. In both models, the order time is not in two to six weeks, but in two working days. The mandate is not completed when the certificate is signed, but rather when the audit calendar is running, the reporting line is active and the first DPIAs are documented. Only then is the order complete in terms of supervision and verifiable in terms of accountability in accordance with Article 5 Para. 2 GDPR.

Turn reading into a mandate.: Send us the threshold check and the desired reporting line to info@civac.de or use the contact form on civac.de. We create an appointment certificate, registration letter and task list and hand over the workspace ready for use. The auditor calls, the evidence is ready. If you would like to check the operational details in advance, you will find the answers to the contract term, representation, insurance and escalation in the FAQ. This creates a verifiable mandate instead of lip service, and the DPO obligation according to Section 38 BDSG disappears from management's risk list.

FAQ

At what number of employees do you have to appoint a DPO?

According to Section 38 Paragraph 1 BDSG, there are usually 20 people who are constantly involved in the automated processing of personal data. Regardless of this, Art. 37 Para. 1 GDPR applies in the case of extensive regular monitoring of those affected or in the case of extensive processing of special categories of data in accordance with Art. 9 GDPR. Both facts must be examined separately and updated annually.

Does the appointment of a DPO have to be made in writing?

The GDPR does not require an explicit written form, but the supervisory authorities expect a written appointment certificate as verifiable proof. Without a certificate, the order time, catalogue of tasks and confirmation of freedom from instructions are missing from the audit. In practice, the certificate should be signed, versioned and stored in the workspace so that the proof is immediately available in the event of a supervisory request. Anyone who only keeps the certificate as a non-versioned file document risks disputes about the actual order time.

How do you report the DPO to the supervisory authority?

Via the online form of the responsible state data protection authority in accordance with Art. 37 Para. 7 GDPR. Some authorities also require the appointment certificate to be uploaded. A missing or late report is subject to a fine in accordance with Article 83 Paragraph 4 Letter a of the GDPR. The contact details must also be published in the data protection declaration and mentioned in the information in accordance with Articles 13 and 14 GDPR.

What fines threaten without a DSB appointment?

According to Article 83 (4) (a) GDPR, up to 10 million euros or 2 percent of global annual turnover, whichever is higher. Supervisory authorities punish the lack of an order as a separate violation, often combined with findings on Art. 30 GDPR or Art. 33 GDPR. In addition, there are civil law claims for damages from those affected in accordance with Art. 82 GDPR.

When does an external DPO make more sense than an internal one?

If there is a narrow internal selection, if there are risks of bias according to Section 6 Paragraph 5 BDSG or in highly regulated industries such as health, insurance and financial services, the external path usually makes more sense. External DPOs bring with them representation arrangements, insurance coverage and routine in supervisory dialogue. Internationally active companies also benefit from 24-hour availability for the 72-hour period in accordance with Art. 33 GDPR and for vacation or sick leave.

How quickly can CIVAC order a DPO?

Within two working days, because the appointment certificate, reporting line, catalogue of tasks and registration letter are available as versioned audit templates in the workspace and only need to be linked to the client's data. The classic duration of two to six weeks is no longer applicable. From day 3, the recurring obligations run productively, including processing records in accordance with Art. 30 GDPR, order processing in accordance with Art. 28 GDPR and data protection impact assessments in accordance with Art. 35 GDPR.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles