When is a data protection officer mandatory? The thresholds according to BDSG and GDPR in plain text
20 employees with automated data processing, core activity profiling or special data categories: three mandatory thresholds according to Section 38 BDSG and Art. 37 GDPR. We explain the pitfalls and show when an external data protection officer is cheaper and safer than the internal solution.
The obligation to appoint a data protection officer in Germany arises from two legal sources: Art. 37 GDPR regulates three core offenses across the EU, Section 38 BDSG supplements the national employee threshold of 20 people. Those responsible who ignore these thresholds risk a fine of up to 10 million euros or 2 percent of global annual turnover in accordance with Article 83 (4) (a) GDPR. In addition, there is the personal liability of the management according to Section 43 GmbHG, because the obligation to order is an original compliance obligation of the management bodies. Supervisory authorities regularly check the order on an ad hoc basis, after data breaches or as part of key audits by several state data protection authorities, which have been coordinating more intensively since 2024.
This article explains the three thresholds, names the common misinterpretations and shows how you can document the order in an audit-proof manner. We give concrete numbers, paragraphs and deadlines instead of marketing phrases. In the end, you will know whether your company needs to appoint a data protection officer, whether an internal or external DPO makes more sense and what evidence must be available within 24 hours of an audit by the state data protection authority. We also consider special cases such as group structures, associations, contract processors and public bodies in which the threshold logic differs or additional obligations apply. Finally, we show the economic comparison of internal and external orders as well as the typical pitfalls in the appointment certificate, which regularly lead to complaints in supervisory audits.
Key Takeaways
- If there are 20 or more employees who constantly process personal data automatically, a data protection officer must be appointed in accordance with Section 38 (1) BDSG.
- Regardless of the number of employees, the DSB obligation applies to core activities such as profiling, processing of special categories of data in accordance with Art. 9 GDPR or an obligation to carry out data protection impact assessment.
- The order must be made in writing, with an appointment certificate, a clear reporting line to the management and reporting the contact details to the supervisory authority in accordance with Art. 37 Para. 7 GDPR.
The three thresholds of the DSB obligation at a glance
The obligation to appoint a data protection officer follows three independent thresholds. If a company fulfils even one of these, the ordering obligation takes effect immediately. First: Article 37 Paragraph 1 Letter b GDPR obliges those responsible whose core activity consists of extensive, regular and systematic monitoring of data subjects. Typical examples are advertising networks, tracking providers, security services with large-scale video surveillance, platforms with behaviour analysis, telematics insurers or adtech providers.
Secondly, anyone who processes special categories of personal data according to Art. 9 GDPR or data about criminal convictions according to Art. 10 GDPR as their core activity falls under the obligation, regardless of the number of employees. This affects doctors' practices, hospitals, nursing services, law firms, personnel service providers with background checks and genetic laboratories. Third: Section 38 (1) BDSG supplements the national threshold of 20 people who are constantly involved in the automated processing of personal data. With the reform through the Second Data Protection Adaptation and Implementation Act, the limit was raised from ten to twenty in 2019.
Practical note: The threshold counts heads, not full-time equivalents. Part-time employees, working students and mini-jobbers with computer work count. Anyone who regularly writes emails, uses a CRM or works in human resources is a “processing person” within the meaning of the standard. Supervisory authorities interpret the term broadly because the reform should relieve the burden on small and medium-sized businesses, not weaken data protection. An external data protection officer takes over the duty from the day the order is placed, without internal personnel costs and without a lock-in for protection against dismissal. This is particularly attractive for growing companies whose personnel planning shifts every month. Even in the event of reorganizations, carve-outs or M&A transactions, the order remains stable without having to fill internal positions. This significantly reduces the risk of a breach of duty due to staffing gaps.
The 20-person threshold according to Section 38 BDSG in detail
The national threshold from Section 38 Paragraph 1 Sentence 1 BDSG is the most common triggering condition in practice. It applies if a controller or processor usually employs at least 20 people on an ongoing basis with the automated processing of personal data. Three criteria are crucial: “usually”, “at least 20 people” and “constantly automated”. Each characteristic raises its own questions of interpretation, which have been clarified several times in supervisory practice since 2019.
"As a rule" means the average over a longer period of time, not the exact status as of the reporting date. Anyone who regularly fluctuates between 18 and 22 employees should treat the threshold as exceeded and order it. “People” means heads, not full-time equivalents. Managing directors, freelancers with permanent data access and temporary workers are also included, provided they are integrated into the organisation. “Constantly automated” occurs as soon as processing using IT resources is part of the recurring task. Just accessing the CRM once a week is enough. HR software, accounting, ERP systems and mail clients are also included.
People who work exclusively with paper files or who carry out pure production or warehouse activities without data contact are not included. In practice, service providers, agencies and consulting firms reach the threshold much earlier than they themselves assume. An 18-person tax office with two additional working students is required. Craft businesses with modern order management and online appointment scheduling also reach the limit as soon as they grow over 20 data-touching heads. CIVAC documents the threshold check in the audit-fest workspace: appointment certificate, signed, filed, verifiable. This means that evidence is permanently available to the supervisory authority, including quarterly re-validation of the number of people. Anyone who reaches the threshold for the first time has no express legal deadline for appointment, but in supervisory practice "immediately" is considered appropriate, i.e. within a few weeks. Anyone who delays the order for more than three months will quickly come under pressure to justify themselves during an audit and should be able to provide documented reasons for the delay.
DSB obligation regardless of the number of employees
Three constellations force ordering even for small teams. Firstly, the core activity is profiling: Anyone who operates scoring, tracking, behaviour analysis or personalized advertising as a business model is required to order, regardless of the number of people. This includes a marketing agency with five employees that sells customer journey tracking as a core service. SaaS providers with user behaviour analysis, newsletter platforms with click tracking or e-commerce providers with dynamic pricing also meet the requirement.
Secondly, special categories of data: health data, biometric data, data on racial or ethnic origin, religious beliefs, trade union membership, sexual orientation and genetic data trigger the obligation as soon as the processing is a core activity. Doctors' practices, physiotherapy, midwives, nursing services and psychological practices are affected, often from the very first employee. This also includes personnel service providers with drug screening, insurance companies with health issues or research institutions with ethical studies.
Thirdly, the DPIA obligation: Where Art. 35 GDPR requires a data protection impact assessment, most supervisory authorities believe that a DPO is actually required. The authorities publish mandatory lists of processing operations that necessarily trigger a DPIA. These include biometric access systems, AI-supported applicant selection, telematics tariffs and large-scale video surveillance. Important: The three thresholds are cumulatively independent. Anyone who meets both an employee threshold and an objective threshold still only owes a DSB, but they have to appoint one faster and with higher qualifications. The CIVAC workspace checks the thresholds using a role check and delivers the appointment certificate within two working days, including the individual justification for the respective threshold category. This justification is particularly crucial for later tests because it documents the interpretation of the threshold. In practice, supervisory authorities accept any objectively viable justification, but not a blanket assumption or a mere reference to size classes.
Internal or external data protection officer? The cost accounting
An internal DPO must be appointed, trained and released for the task. The market standard is 0.3 to 0.5 full-time positions, depending on the industry and risk. With a gross annual salary of 70,000 euros for a suitable specialist, pure personnel costs arise from 21,000 to 35,000 euros per year. In addition, there is a training budget (training at least 24 hours a year), specialist literature, software licences for processing directories and risk analysis, membership in professional associations, travel costs for supervisory authority workshops and the dismissal protection privilege according to Section 6 Paragraph 4 BDSG, which effectively makes the internal DPO non-cancellable. Changing is laborious and expensive.
An external DPO is appointed via a service contract. The usual market rate in Germany is 6,000 to 24,000 euros per year, depending on the number of employees, industry and scope of processing. Advantages: no personnel costs, no lock-in against dismissal protection, direct technical expertise, liability insurance for the service provider with typically 1 to 5 million euros in coverage, clear reporting lines and a professional exchange on current supervisory practices. Disadvantages: less physical presence, need for a structured interface, higher requirements for internal processes for information transfer.
Rule of thumb: Up to around 100 employees, the external DPO is almost always more economical. Between 100 and 250 employees, a cost-benefit analysis is worthwhile; for 250 or more employees, a mixed solution with an internal coordinator and external technical management is increasingly recommended. CIVAC offers both models: Licence the workspace for your internal representatives, or have our representatives order it. The workspace replaces fragmented Excel lists with an audit-proof ISMS cockpit according to ISO/IEC 27001:2022 with 93 controls. Both models share the same technical basis, so that a later switch between internal and external is possible without data migration. The data residence is in the EU, all client data remains on servers in Germany and Ireland.
Order, appointment certificate and report to the supervisory authority
The order must be made in writing, ideally as an appointment certificate with clear content. What is necessary is: full name, address for summons, list of tasks in accordance with Art. 39 GDPR, reporting line to the management, start and duration of the appointment, intellectual property rights in accordance with Art. 38 GDPR and provisions for termination. When ordering externally, the contract is concluded with the service provider; the appointment certificate names the natural person who will carry out the task. The legal requirements for the appointment certificate are not regulated in a single standard, but arise from the interaction of Articles 37 and 38 GDPR as well as Section 6 BDSG.
The contact point must be named within the authority; the direct email address of the DSB plus a separate collective mailbox is usual. According to Art. 37 Para. 7 GDPR, the contact details must be provided to the supervisory authority. In Bavaria, reporting is done via the BayLDA online form, in North Rhine-Westphalia via the LDI NRW, in Baden-Württemberg via the LfDI, and in Berlin via the BlnBDI. The report must be made immediately after the order is placed, a period of a few working days is appropriate, delays of more than four weeks are viewed critically in supervisory practice.
The contact details of the DSB must also be published on the website, usually in the data protection declaration with a clear statement: "You can reach our data protection officer at dsb@unternehmen.de". Publication of the natural person is not mandatory; a functional address is sufficient. Others run compliance like a filing cabinet. We run it like software.: The CIVAC workspace generates the appointment certificate, notification and data protection declaration module in one process, each versioned with a time stamp and proof of signature. The audit trail meets the requirements of ISO/IEC 27001:2022 for verification.
Duties and protective rights of the DSB according to Articles 38 and 39 GDPR
Art. 39 GDPR lists the five core tasks: informing and advising the person responsible and employees, monitoring compliance with the GDPR and national data protection law, advice on data protection impact assessments, cooperation with the supervisory authority and function as a contact point for those affected and the authority. The list is not exhaustive, but extensions must be compatible with the independence of the DSB. In practice, training activities, representation towards processors and participation in internal audits are also included.
Art. 38 GDPR protects this independence: The DPO may not receive any instructions regarding the exercise of his duties, he reports directly to the highest management level, he may not be dismissed or disadvantaged because of the fulfilment of his duties, he is obliged to maintain secrecy. Conflicts of duties are not permitted: Anyone who decides what is processed as an IT manager, HR boss or managing director is not allowed to monitor themselves. This incompatibility regularly leads to fines; in one well-known case, the BayLDA imposed 50,000 euros because the DPO was also the IT manager. The sales manager and the marketing manager are also usually incompatible.
The resources must be sustainable: time, budget, access to processing activities, training budget, technical equipment. Management is responsible for this obligation to provide resources; violations are regularly punished in audits. In supervisory practice, an internal DPO without exemption is seen as an indication of an appointment that is not meant seriously. The CIVAC workspace documents the resource allocation, the reporting line and the annual activity reports in one place, checked according to 93 controls of ISO/IEC 27001:2022. This means that formal proof of functionality is available at all times. Audit-proof, documented, Section 38-proof. The annual reporting requirement to management is also reflected in the system, with templates for activity reports, risk assessments and training status.
Fines, liability and regulatory audits
If you do not order a DSB despite the obligation, you risk a fine of up to 10 million euros or two percent of the previous year's worldwide annual turnover, depending on which amount is higher, according to Art. 83 Para. 4 lit. a GDPR. The supervisory authorities in Germany impose fines pragmatically: 20,000 to 200,000 euros are common for medium-sized companies, seven- and eight-figure amounts for corporations. There are also requirements, prohibitions and orders. In individual cases, processing was temporarily prohibited, which severely disrupted business operations.
The management is personally liable in accordance with Section 43 Paragraph 2 GmbHG for damages caused by a breach of duty by the compliance organisation. Section 130 OWiG sanctions the violation of the supervisory obligation with a fine of up to 1 million euros per violation. In corporations, this results in chain liability from the subsidiary through its management to the group board. D-O insurance generally only covers negligence, not the intentional waiver of a DPO appointment despite a recognizable obligation.
Authority audits are carried out on an ad hoc basis, following complaints, data breaches or whistleblower reports, or on an industry-specific basis as part of key audits by the state data protection authorities. The authority typically requires an appointment certificate, proof of activity, a processing list in accordance with Art. 30 GDPR, technical-organisational measures in accordance with Art. 32 GDPR and the latest proof of training. The auditor calls, the evidence is ready. This is the standard that the ISO/IEC 27001:2022 transition requires for information security and which applies analogously to data protection. The deadline for submission is usually two weeks, in urgent cases 24 hours. When conducting data breach inspections, the authority regularly requires the complete process in accordance with Art. 33 GDPR within 72 hours, including risk assessment, action plan and information for those affected. Anyone who does not have systematic documentation here will regularly lose the dispute with the authorities during the preliminary examination.
Special cases: corporations, associations, processors, public bodies
Group structures: According to Art. 37 Para. 2 GDPR, a group of companies may appoint a common DPO as long as this can be easily reached from each branch. In practical terms this means: same language, same time zone, short response time. The solution is generally practical for German medium-sized businesses; in international structures with several supervisory authorities, a lead DPO plus local contact points is recommended. The leadership of the respective supervisory authority is based on Art. 56 GDPR and must be carefully clarified in the group context.
Associations: The DSB obligation also applies to registered associations as soon as the 20-person threshold is reached for volunteers or full-time employees who process member data automatically. Sports clubs, church communities and welfare associations regularly underestimate this. For church bodies, DSG-EKD and KDG apply, which are structurally parallel to the GDPR but have their own supervisory authorities and fine systems. Diakonie, Caritas and free church organisations must adapt their orders to this framework.
Processors: Section 38 BDSG also applies to processors. Anyone who processes data for third parties as a cloud provider, hosting provider or payroll office and employs more than 20 people internally to process it is required to order. Public bodies: According to Art. 37 Para. 1 lit. This also includes self-owned companies, municipal companies and public law institutions, as well as public broadcasters. If you are acting in one of these special cases, it is best to check the thresholds using the FAQ service and obtain a formal assessment, ideally before the next annual financial statements. For cross-border activities, it should also be clarified which supervisory authority is in charge and whether a representative is required in accordance with Article 27 GDPR. A clear assignment of the DPO also makes sense for joint controller constellations according to Art. 26 GDPR.
From threshold check to reliable ordering
The DSB obligation is not a question of interpretation, it is a threshold check with clear legal consequences. Anyone who reaches the 20-person threshold, carries out core activity profiling, processes special categories of data or carries out an activity subject to DPIA has no choice. The only sensible question is: internal or external, with which reporting line and what depth of documentation. CIVAC is a compliance platform and officer-as-a-service that solves exactly this question, with 25 officer roles, 490 ready-to-use audit templates and EU data residency for all client data.
Licence the workspace for your internal officers, or have our officers appointed. The workspace delivers threshold checks, appointment certificates, reports to the supervisory authority, processing records and proof of activity as an integrated process. The appointment certificate will be available within two working days, instead of the industry standard two to six weeks. 490 ready-to-use audit templates cover the most common audit situations, from DPIA to TOMs to order processing agreements. The reporting line to the management is shown in the system, as are the escalation paths to the supervisory authority.
If you are unsure whether your company reaches the threshold, we will check this in the initial consultation. If you have already been ordered, we will take over ongoing operations or the audit-proof cockpit. Turn reading into a mandate.: Write to info@civac.de or use the contact form on civac.de. We will contact you within one working day with a concrete assessment of your obligation, including a draft appointment certificate and an estimate of the annual operating costs. This initial analysis is binding and has no cost risk for you. The clock starts on awareness. Anyone who postpones risks that the next regulatory inspection will arrive faster than the internal clarification. We make the choice between internal appointments and Officer-as-a-Service together, transparently and without persuasion.
FAQ
For how many employees do I need a data protection officer?
According to Section 38 Paragraph 1 BDSG, you are required to order as soon as you usually employ at least 20 people on a permanent basis with the automated processing of personal data. Heads count, not full-time equivalents. Regardless of this, the obligation under Art. 37 GDPR applies to the core activity of profiling, processing of special data categories or the DPIA obligation, starting with the first employee.
Do working students and part-time employees count toward the 20-person threshold?
Yes. Section 38 BDSG counts people, not full-time equivalents. Working students, part-time employees, managing directors and freelancers with regular data access count, as do temporary workers with organisational involvement. What is crucial is that the person is constantly busy with automated data processing, i.e. using CRM, email or ERP. Weekly access is also often sufficient for the “constant” feature.
Does a medical practice with five employees have to appoint a DPO?
Yes. Medical practices process health data in accordance with Art. 9 GDPR as a core activity. This means that Article 37 Paragraph 1 Letter c GDPR applies regardless of the number of employees. Even the solo doctor with an assistant is required to order as soon as the electronic patient file or a practice management system is used. This applies analogously to dentists, physiotherapists, alternative practitioners and also to company medical services.
How much does an external data protection officer cost per year?
The usual market rate in Germany is 6,000 to 24,000 euros net per year, depending on the number of employees, industry and scope of processing. Medium-sized companies usually pay between 9,000 and 15,000 euros. Compared to the internal DSB with pure personnel costs of 21,000 to 35,000 euros, the external solution is almost always more economical up to around 100 employees. In addition, there is the service provider’s liability insurance.
What fines will I face if I do not order a DSB?
According to Article 83 (4) (a) GDPR, up to 10 million euros or two percent of global annual turnover, whichever is higher. In German supervisory practice, typical fines for medium-sized companies are between 20,000 and 200,000 euros. In addition, there is the personal liability of the management according to Section 43 GmbHG and Section 130 OWiG with up to 1 million euros per violation.
How quickly can CIVAC appoint an external DPO?
The appointment certificate is ready within two working days, including threshold check, draft contract, notification to the supervisory authority and data protection declaration module. Classic service providers require two to six weeks. The SLA applies to standard cases without special group structures or regulated industries, where we discuss deadlines individually. Write to info@civac.de for a concrete assessment of your obligation.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.