77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
Who has to appoint a data protection officer? Obligations 2026 at a glance
Data Protection & Privacy

Who has to appoint a data protection officer? Obligations 2026 at a glance

20 August 202612 min readBy Lena Vogt
CIVAC

Obligation to appoint a data protection officer: three clear triggers, two common mistakes and a checklist that will give you clarity in 24 hours. Plus: What will change in 2026.

The obligation to appoint a data protection officer arises from Art. 37 Para. 1 GDPR and, additionally for Germany, from Section 38 Para. 1 BDSG. Anyone who constantly employs 20 or more people in the automated processing of personal data must order. Anyone who processes special category data in accordance with Art. 9 GDPR in their core business must also order. So the question is not abstract, but a calculation with clear variables. In practice, however, management overlooks three constellations that force an order to be placed even though the numerical threshold has not been reached. Anyone who counts incorrectly here risks being fined, and small and medium-sized companies in particular underestimate how quickly the threshold is exceeded in a growing organisation.

This article provides a reliable answer along the three mandatory triggers, classifies the typical errors and shows how to properly document the order. You will receive concrete threshold values, a decision path, a negative checklist and information on choosing between an internal or external data protection officer. CIVAC is a compliance platform and officer-as-a-service for 25 officer roles, ISO/IEC 27001:2022 certified, with EU data residency. We describe the scope of obligations, the risks of fines and the path to an audit-proof appointment certificate, signed, filed and verifiable. The answer applies to GmbH, AG, association, cooperative and to authorities with their own special rules.

Key Takeaways

  • The order requirement applies as soon as 20 people constantly process personal data automatically or core business, risk or special categories require this.
  • The order must be documented in writing, reported to the supervisory authority and made known internally, otherwise there is a risk of a fine according to Art. 83 Para. 4 GDPR of up to 10 million euros or 2 percent of the group turnover.
  • An external data protection officer is legally equivalent, more cost-effective than an internal full-time position and avoids conflicts of interest with IT management, HR or management.

Legal basis: Art. 37 GDPR and § 38 BDSG in relation

The GDPR names three mandatory circumstances in Article 37 Paragraph 1: firstly, authorities and public bodies with the exception of the courts in the context of their judicial activities, secondly, private bodies whose core activity requires extensive, regular and systematic monitoring of those affected, thirdly, private bodies whose core activity consists of the extensive processing of special categories according to Article 9 or criminal data according to Article 10. These three triggers apply across the Union and are equally applicable in every national legal system. The German legislator has added a fourth obligation in Section 38 Paragraph 1 BDSG, which applies independently of the core business: As soon as a controller or processor constantly employs 20 people with the automated processing of personal data, a data protection officer must be appointed. This threshold has no connection to Union law and is a special German approach that companies whose registered office or significant processing is in Germany must follow.

Four points are crucial in practice. Firstly, it's not just full-time employees that count. Working students, interns, part-time employees, trainees and managing directors are also included in the threshold analysis, provided they regularly work with personal data. Second, any automated processing ranges from email correspondence to CRM to HR software. However, manual file management without electronic support does not count. Thirdly, the controller and the processor do not add up; Each role is checked separately and the order requirement can arise individually in both roles. Fourth, the deadline is dynamic. Anyone who only just exceeds the threshold should clarify the role of the external data protection officer early on so as not to miss a deadline. The deadline runs from the moment we become aware of it, and the management becomes aware of it the moment the HR statistics show the threshold.

Mandatory trigger 1: Threshold value 20 employees according to Section 38 BDSG

The 20-person threshold is the most common mandatory reason in German SMEs. The decisive factor is permanent employment, not full-time equivalent. Four working students who work 10 hours in CRM every week count as four full-time employees. A managing director who processes customer files on a daily basis also counts. Seasonal peaks are relevant if they recur regularly and are typical for task performance. A tax consulting office that increases from 15 to 25 people during the tax return season exceeds the threshold seasonally and is therefore legally binding if this pattern occurs every year.

It is important to distinguish between the controller and the processor. A company that works as a controller with 15 people and uses a further 10 people as a processor for a customer is not above the threshold in any role, but must check whether the order processing can be viewed as a separate controller, for example if intended purposes are supported. Group structures are more complex: each legal entity counts separately. A holding company with 12 employees and a subsidiary with 18 employees must check in both units whether there is joint processing in accordance with Art. 26 GDPR, which suggests a consolidated view.

Anyone who consistently exceeds the threshold must place the order immediately. The law does not explicitly state a deadline, but the supervisory authorities expect an order to be issued within 30 days of the deadline being exceeded. In practical terms, this means: As soon as the HR statistics show the 20th employee with data access, the internal clock starts. Anyone who hesitates here risks a fine, which is regularly revealed in data protection audits. The supervisory authorities have also made it clear that a short-term shortfall, for example due to terminations, does not automatically cancel the obligation to order; Permanent employment is assessed overall, and fluctuations around the threshold point suggest a precautionary order.

Mandatory trigger 2: Core business, profiling and special data categories

Companies far below the 20-person threshold may also be required to order. Art. 37 Paragraph 1 Letter b GDPR is linked to the core activity. Extensive, regular and systematic monitoring of those affected occurs when profiling, tracking, credit rating, camera surveillance in public spaces, telematics in the insurance sector or comparable activities are part of the business model. The European Data Protection Committee has made it clear in its guidelines WP 243 that the size of the data set, duration, range and geographical extent are taken into account in an overall assessment. An advertising agency that builds retargeting profiles for customers is usually required to order, even though it only has five employees.

Lit. c is linked to special categories according to Article 9: health data, biometric data, ethnic origin, religious beliefs, political opinions, trade union membership, sexual orientation. A medical practice with five employees is therefore subject to the order requirement even though it does not reach the 20-person threshold. The same applies to a FinTech whose core activity is credit rating, to recruitment agencies with extensive profiling, to e-health providers, to rehabilitation facilities and to religious associations with membership management. Here the standard is stricter: As soon as the processing is extensive and related to core activities, the obligation applies regardless of the number of employees. The supervisory authorities in Bavaria, Baden-Württemberg and North Rhine-Westphalia have repeatedly made it clear over the past three years that a data protection impact assessment in accordance with Article 35 GDPR is a strong indication of the obligation to order. Anyone who is already carrying out a DPIA should check the order question at the same time, as the two are regularly linked and are asked together in official audits. A special constellation is made up of platform operators who, as contract processors, process health or creditworthiness data on a large scale; They also generally require an order, regardless of the number of employees, because the cumulative amount of data from the end customers determines the scope.

Who is NOT required to order: three common mistakes

Not every data processing automatically leads to an obligation to order. Three errors persist. Firstly: Even those who do not have to appoint a data protection officer remain fully responsible for compliance with the GDPR. The obligations under Articles 5, 6, 13, 14, 30, 32, 33, 34 and 35 GDPR apply regardless of the order. Anyone who thinks that with 15 employees that everything is allowed without a DSB is fundamentally mistaken. List of processing activities, technical and organisational measures, data breach reporting path, order processing contracts and data subject rights are still mandatory. A supervisory authority checks these obligations even without a DPO appointment. Anyone who has gaps here will be sanctioned.

Secondly: The voluntary appointment of a data protection officer is not only permitted, but often makes sense. It sends a signal to customers, B2B partners, insurance companies and auditors. Anyone who appoints voluntarily is subject to the same rules as the compulsorily appointed DPO: independence in accordance with Art. 38 Para. 3 GDPR, reporting line to the management, protection against dismissal in accordance with Section 38 Para. 2 i. V. m. § 6 para. 4 BDSG, duty of confidentiality, right to further training. A half-hearted voluntary order with an unclear reporting line leads to the same risk of fines as an incorrect mandatory order.

Third: order processing does not shift responsibility. Anyone responsible for handing over data to a processor remains responsible for the order in their company. The processor independently checks whether he himself is required to order. In practice, we see that small processors who process large data sets on behalf of customers underestimate the ordering obligation and rely on the order from the person responsible. This is legally incorrect and is regularly a problem in audits. Anyone who looks after customer data as a processor with 22 employees in a German data centre is obliged to place an order independently and must document this to the supervisory authority, even if the person responsible is located abroad and applies its own regulations there.

Risk of fines and supervisory authority practice

The failure to appoint a data protection officer or the appointment of a data protection officer incorrectly is subject to a fine in accordance with Article 83 (4) (a) GDPR. The limit is up to 10 million euros or 2 percent of global annual sales, whichever is higher. In practice, the penalties for pure ordering errors are lower, but the supervisory authorities regularly use the missing order as a door opener for further examinations. Experience has shown that anyone who has not named a DPO also has gaps in Article 30 or Article 32, and this is exactly where the fine becomes high. It is the cumulative effect of several violations that results in six-figure amounts in the final bill.

Exemplary decisions from recent years: In 2023, the State Commissioner for Data Protection of Lower Saxony imposed a mid-five-figure fine on a medium-sized mail order company for missing orders despite profiling. In 2024, the Berlin commissioner punished the late order from a digital health provider with a low six-figure amount. In 2025, the Bavarian supervisory authority sanctioned an insurance broker with a high five-figure fine because of a conflict of interest in the DSB office. The supervisory authorities usually justify the amount based on the role model effect, the duration of the violation, the industry affiliation and the lack of evidence of internal compliance structures. A proper appointment certificate, a documented report to the authorities and a clear reporting line noticeably reduce the risk of fines. The auditor calls, the evidence is ready. Anyone who documents properly here also shortens the duration of the examination from weeks to days because the supervisor does not have to dig further. The experience of the last two years shows that for documented and reported orders, supervisory authorities end the examination after the initial examination in 80 percent of cases, while undocumented orders regularly lead to on-site examinations with recording and questioning of witnesses.

Internal or external? Decision criteria for practice

The law leaves it open whether an internal employee or an external service provider is appointed. Both models are legally equivalent. The decision follows three criteria: expertise, independence, costs. An internal data protection officer must provide evidence of the specialist knowledge required under Article 37 (5) GDPR, which is usually acquired through certified courses such as TÜV, udis, GDD or comparable providers. Experience has shown that a three-day basic course is not enough; The supervisory authority expects at least 40 teaching units plus regular training of at least 16 hours per year. The supervisory authorities actively check expertise during audits and request evidence.

Independence is the most common stumbling block. Section 38 Paragraph 6 BDSG and Art. 38 Paragraph 6 GDPR prohibit conflicts of interest. Managing directors, IT managers, HR managers, marketing managers, sales managers and compliance managers are regularly unsuitable because they have a say in the purposes and means of processing. In many SMEs, this excludes the few remaining candidates. Here, the external data protection officer is often the only practical solution. The costs vary greatly, but for an SME with 50 to 250 employees they are usually between 250 and 800 euros per month plus expenses. In comparison, an internal DPO with a sufficient number of hours costs significantly more once additional wage costs, further training and replacement arrangements are taken into account. There is also the insurance aspect: external data protection officers have professional liability insurance that applies in the event of errors, while an internal DPO triggers employer liability in the event of damage. If you compare both models, you will usually choose the external model if you do a realistic full cost calculation, unless very large amounts of data have to be managed operationally on a daily basis. Hybrid models are also common: an internal coordinator oversees day-to-day operations, an external data protection officer formally takes over the ordering and external communication.

Formalia: appointment certificate, notification, internal announcement

The order must be documented in accordance with Article 37 Paragraph 7 GDPR and Section 38 Paragraph 1 BDSG and communicated to the responsible supervisory authority. In practice this means four steps. First: A written appointment certificate that states tasks in accordance with Art. 39 GDPR, reporting line to management, independence, duty of confidentiality, representation regulations and entitlement to further training. Second: A report to the responsible state supervisory authority via their online form or by email. Third: An internal announcement that makes the name and contact details of the data protection officer available to all employees, usually via intranet, noticeboards and onboarding documents. Fourth: External publication of the contact details on the website and in the legal notice so that those affected can exercise their rights.

Frequent errors in the appointment certificate: lack of reporting line, lack of protection against dismissal, lack of representation regulations in the event of vacation and illness, lack of training regulations, lack of resources. An appointment certificate based on a standard template does not automatically solve these points. Anyone who works cleanly here documents in an audit-proof manner and avoids questions from the authorities. In the CIVAC workspace you will find 490 ready-to-use audit templates, including an appointment certificate that contains all mandatory information as well as the reporting line to management. The appointment certificate, signed, filed, verifiable. If you take the opposite approach and rely on Officer-as-a-Service, you will receive the appointment certificate, the authorities report and the internal announcement as a package within two working days. The CIVAC SLA is therefore well below the classic market standard of two to six weeks for the onboarding phase of an external data protection officer and reduces the gap between mandatory entry and the actual order to a minimum. Anyone who reorders in the current financial year because an acquisition or a jump in growth has exceeded the threshold will particularly benefit from this speed because the risk of a regulatory inquiry is increased in this transition phase.

Special cases: Group, joint controller, international structures

According to Art. 37 Para. 2 GDPR, corporations can appoint a common data protection officer for a group of companies, provided that he or she can be easily reached from each branch. Accessibility is not just lip service: language skills in the respective national language, response times, local presence and availability for inquiries from those affected must be ensured. A corporate DPO based in Munich and responsible for a subsidiary in Madrid must be able to process Spanish-language inquiries or set up local support. The Spanish supervisory authority AEPD is actively checking accessibility and has imposed fines in several cases against German parent companies whose DPO could only be reached in German.

In the case of shared responsibility according to Art. 26 GDPR, the responsible parties involved must clearly define the roles. In practice, the joint controllers appoint a lead DPO who takes over operational coordination. International structures based outside the EU also require a representative in accordance with Art. 27 GDPR; The DSB obligation remains unaffected and applies throughout the Union to all processing within the scope of the GDPR. Authorities and public bodies are obliged to order regardless of the number of employees, as are those with professional secrecy in accordance with Section 38 Paragraph 1 Sentence 2 BDSG if the processing takes place in the exercise of their profession, for example for lawyers, tax consultants and doctors with extensive data processing. Anyone who has doubts should clearly document the mandatory inspection, including the reasons why an order is not necessary. This negative documentation is often crucial in official audits and is part of the regular compliance file. You can store this negative documentation as a versioned file in the CIVAC workspace and access it at any time during the audit. Anyone working with US parent companies should also check the data protection coordinator according to the EU-US Data Privacy Framework; This role does not replace the DPO under European law, but can be part of a consolidated compliance structure.

Turn the obligation into a clean order

The obligation to appoint a data protection officer is not a question of style, but rather a question of the interpretation of Article 37 GDPR and Section 38 BDSG. Three mandatory triggers, clearly defined thresholds, documented exceptions. Anyone who passes the exam cleanly will have clarity within 24 hours; Anyone who puts it off will have a problem in the audit. Others run compliance like a filing cabinet. We run it like software. CIVAC is a compliance platform and officer-as-a-service with 25 officer roles, 490 audit templates and an ISO/IEC 27001:2022 certified infrastructure in EU data residency. The appointment certificate, the notification to the authorities and the reporting line run through a uniform process, the documentation of which can withstand any supervisory authority.

You have two options. Licence the workspace for your internal representatives, or have our representatives order it. In the first case, you will receive the appointment certificate, the notification to the authorities and the reporting line as a template in your workspace, including a list of tasks in accordance with Art. 39 GDPR and an escalation path in the event of data breaches. In the second case, an external data protection officer from the CIVAC network takes over the function with an SLA of two working days, including professional liability and representation regulations. Both paths end with the same result: appointment certificate, signed, filed, verifiable. Turn reading into an assignment. Write to info@civac.de or use the contact form on the FAQ page if you would like to discuss your specific situation. We usually respond on the same working day and conduct a 30-minute initial conversation without a contract. During the conversation, we clarify the mandatory question, the choice of model, the transition phase and the specific effort for your industry and size class. Anyone who has clarified the DPO obligation today will have less unresolved item on the compliance agenda tomorrow and can concentrate on the operational issues.

FAQ

At what number of employees do I have to appoint a data protection officer?

In Germany, the obligation under Section 38 Paragraph 1 BDSG applies as soon as 20 people constantly process personal data automatically. All employees with data access are counted, including working students, interns and managing directors. Regardless of this, the obligation under Art. 37 GDPR can apply to just one employee if the core business includes profiling or special data categories.

Do I have to report the order to the supervisory authority?

Yes, according to Art. 37 Para. 7 GDPR, the appointment must be reported to the responsible supervisory authority. The state authorities provide online forms for this purpose. The report contains the name, contact details and position of the data protection officer. Without notification, the order is formally incomplete and can result in a fine according to Art. 83 Para. 4 GDPR.

Can the managing director himself be a data protection officer?

No. Managing directors decide on the purposes and means of processing and are therefore in a conflict of interest according to Art. 38 Para. 6 GDPR. IT managers, HR managers and compliance managers are also generally unsuitable. The supervisory authorities have confirmed this position several times. Anyone who still orders here risks the order being ineffective.

How much does an external data protection officer cost in medium-sized businesses?

For an SME with 50 to 250 employees, the standard monthly flat rate is 250 to 800 euros plus project-related expenses. An internal data protection officer with a sufficient number of hours usually incurs significantly higher full costs as soon as additional wage costs, further training and representation are taken into account. The choice depends on size, industry and risk profile.

How long do I have to place the order once the obligation takes effect?

The GDPR does not specify an express deadline. The supervisory authorities expect an order within 30 days of the obligation occurring. Anyone who exceeds the 20-person threshold or starts a new core activity should initiate the appointment immediately, as delays in audits are regularly penalized.

What happens if I don't appoint a data protection officer even though I should?

Failure to place an order is subject to a fine in accordance with Article 83 Paragraph 4 Letter a of the GDPR, with a limit of up to 10 million euros or 2 percent of global annual turnover. In practice, the penalties for pure ordering errors are lower, but the missing order often serves as a reason for supervisory authorities to carry out further inspections with a higher risk of fines.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles