Ailance Alt TM Logo

External Data Protection Officer vs. the Legal Services Act

External Data Protection Officer and Legal Advice

from R. Olschewsk

Data protection regulations and the related decisions are becoming increasingly complex, and specific issues often require a thorough legal review.

The admissibility or inadmissibility of proceedings often depends on even minor changes to the contracts, wording of Consent or procedures. The Act on Extrajudicial Legal Services (RDG) regulates whether this legal review may be carried out by the data protection officer. According to Section 2 RDG, legal services are any activity in specific third-party matters as soon as it requires a legal examination of the individual case.

Although the Legal Services Act stipulates that providing legal advice or reviews free of charge is permissible within the scope of ancillary duties to a primary duty, legal services related to another activity are permitted if they constitute an ancillary service that is part of the professional or job description. Whether a service constitutes an ancillary service must be assessed based on its content, scope, and factual connection to the primary activity, taking into account the legal knowledge required for the primary activity. The primary duty of the data protection officer is to monitor the company’s procedures involving personal data and to raise employee awareness of the Data protection (Section 4g of the Federal Data Protection Act (BDSG)).

However, if the external data protection officer primarily conducts legal reviews or provides legal representation in the context of contract negotiations, and regularly drafts contracts—such as service or employment contracts—as well as reviews works agreements or international IT contracts, the situation becomes problematic. If the external data protection officer provides legal advice without the appropriate attorney’s license, they are likely no longer acting in compliance with the law. Clients should then be particularly cautious, because exceeding one’s scope of authority would likely no longer be covered by the data protection officer’s professional liability insurance in the event of a claim. Ultimately, it is even questionable whether the „inexpensive“ IT specialists trained in data protection law—who are frequently found on the market—can fully grasp the complexity of the relevant legal issues when providing legal advice. When dealing with complex legal issues, external data protection consultants should collaborate with specialized attorneys to protect both themselves and their clients from providing incorrect advice. Ideally, the data protection officer should even hold dual qualifications as both an attorney and a data protection consultant and also have a strong network of IT security experts.

Further information:

laws-on-the-internet.com/rdg/

Picture of Marcus Belke

Marcus Belke

Marcus Belke is the CEO of 2B Advice GmbH. He drives innovation in data protection compliance and risk management and is responsible for the further development of Ailance, the next-generation compliance platform.

Share this post:

External Data Protection Officer vs. the Legal Services Act