Data Protection Officer
Data breaches, DPIAs, DPA reviews, records of processing, privacy policies. Appointed externally or handled in-house, with the 72-hour breach clock always running.
Art. 37 GDPR · § 38 BDSG
Talk to us about Data Protection Officer
Three lines and you are in our inbox. We reply within one business day.
What does a Data Protection Officer do?
The Data Protection Officer (DPO) supervises GDPR and German Federal Data Protection Act (BDSG) compliance inside an organisation. The role acts as the interface between management, data subjects and the supervisory authority. Under Article 39 GDPR, the DPO informs and advises controllers, monitors compliance with data protection rules, advises on Data Protection Impact Assessments under Article 35, and cooperates with the supervisory authority.
The DPO is not a decision-making role but an advisory and oversight function. Legal responsibility for data protection remains with management as the controller within the meaning of Article 4 No. 7 GDPR. Despite this, the position is instruction-free: Article 38 Para. 3 GDPR explicitly prohibits the employer from giving the DPO instructions on how to perform their duties.
In practice the DPO handles concrete tasks: maintaining the records of processing activities (RoPA) under Article 30, reviewing data processing agreements under Article 28, drafting and updating privacy notices, training staff, handling data breaches within the 72-hour notification window under Article 33, and managing data-subject requests under Articles 15 to 22 GDPR. Larger organisations add vendor audits, tool risk assessments, and contributing to DPIAs.
Two provisions govern the appointment itself. Article 37 Para. 1 GDPR keys off the nature of the activity, while section 38 Para. 1 BDSG keys off the number of employees permanently engaged in automated processing of personal data. Under Article 37 Para. 7 GDPR the contact details must be published and communicated to the supervisory authority, a step routinely forgotten after the appointment and immediately visible in an inspection. Article 38 Para. 2 GDPR obliges the controller to provide the resources and the access to processing operations the role needs. Article 38 Para. 6 GDPR permits other tasks only where no conflict of interest arises, which in practice rules out leadership roles in IT, HR or marketing. Protection against removal follows from Article 38 Para. 3 GDPR and, through section 38 Para. 2 BDSG, from section 6 Para. 4 BDSG; at non-public bodies it applies only where the appointment is mandatory, and the protection against dismissal presupposes an employment relationship. Under Article 39 Para. 2 GDPR the DPO works risk-based, prioritising by the risk of the processing rather than by whoever asks loudest.
DPO duties
- Inform and advise the controller and all staff processing personal data (Art. 39 Para. 1 lit. a GDPR).
- Monitor compliance with GDPR, BDSG and internal data protection policies.
- Support the controller in building and updating the records of processing activities that under Article 30 Para. 1 GDPR the controller keeps.
- Review data processing agreements (DPAs) under Article 28 GDPR and advise the controller, who signs them off.
- Advise on Data Protection Impact Assessments (DPIAs) for high-risk processing under Article 35 GDPR.
- Support breach handling including the notification the controller submits to the supervisory authority within 72 hours under Article 33 Para. 1 GDPR.
- Monitor how data-subject rights under Articles 15 to 22 GDPR are handled (access, rectification, erasure, objection).
- Run regular data protection training for every employee with access to personal data.
- Act as point of contact for the supervisory authority and accompany regulatory audits.
- Deliver an annual activity report to management covering risk posture and improvement recommendations.
Appointment and qualifications
The obligation to appoint a DPO stems from two parallel norms. Article 37 Para. 1 GDPR requires appointment when core activities consist of regular and systematic monitoring of data subjects on a large scale or large-scale processing of special categories under Article 9. § 38 Para. 1 BDSG broadens the obligation: appointment is mandatory once at least 20 persons are continuously engaged in automated processing of personal data. Section 38 Para. 1 sentence 2 BDSG applies regardless of headcount where processing is subject to a data protection impact assessment under Article 35 GDPR, or where personal data is processed commercially for transfer or for market or opinion research.
The GDPR prescribes no particular form for the appointment; in practice it is recorded in writing and states position and scope. Article 37 Para. 7 GDPR requires the contact details to be published and communicated to the supervisory authority. The DPO can be internal staff or external on a service contract. Article 37 Para. 6 GDPR explicitly permits both models. The professional qualification must match the risk of the processing: demonstrable expertise in data protection law and IT security is mandatory, while certifications such as TÜV-DPO or IAPP CIPP/E are common market practice but not legally required.
- 20 or more persons at the controller or processor continuously engaged in automated processing of personal data (§ 38 Para. 1 sentence 1 BDSG).
- Core activities involve large-scale regular monitoring of data subjects (Art. 37 Para. 1 lit. b GDPR).
- Core activities consist of large-scale processing of special categories (Art. 9) or criminal data (Art. 10 GDPR) (Art. 37 Para. 1 lit. c GDPR).
- Public bodies regardless of size (Art. 37 Para. 1 lit. a GDPR).
- Regardless of headcount where processing requires a data protection impact assessment, or for commercial transfer, market or opinion research (§ 38 Para. 1 sentence 2 BDSG).
- Voluntary appointment is advisable for any organisation with material data protection risk.
Sectors most affected
- Healthcare (clinics, hospitals, care providers)
- Banking, insurance, financial services
- Staffing, HR-tech, recruiting platforms
- Online marketing, AdTech, market research
- Telecoms and internet services
- E-commerce and online marketplaces
- Mid-market manufacturing, retail, logistics
- Public administration and municipal bodies
- Education above primary level
- SaaS and cloud providers (typically as processors)
How CIVAC delivers the DPO role
CIVAC offers both models on one platform: external DPO appointment or workspace licence for your in-house team. Within 48 hours your engagement is set up, the written appointment recorded and the workspace operational.
The workspace covers every mandatory task: versioned records of processing activities, DPA templates aligned with Article 28 GDPR, guided DPIAs under Article 35, breach workflow with the 72-hour clock and pre-set notification paths, training library with proof of completion, and an append-only audit trail every inspector recognises. Notifying the authority of the contact details under Article 37 Para. 7 GDPR is created as a task and recorded, rather than being left undone once the appointment is signed. Data-subject requests run as dated items against the one-month deadline in Article 12 Para. 3 GDPR, and the annual report to management is assembled from the same records.
Frequently asked questions about the DPO
Need this officer role for your organisation?
Appoint our experts as your external officer or license CIVAC for your in-house team. Get in touch and we walk you through the right setup.