Who must appoint a data protection officer under EU rules?
EU and German data protection laws provide for different situations in which a Data Protection Officer (DSB) must be appointed. It is often overlooked that even if these regulations do not apply to your specific case, all companies (as well as all government agencies and organizations) must comply with the provisions of the GDPR.
This means that even if you are not required to do so, you should still have a data protection officer to assist you with your data protection obligations.
Similar articles from our blog: What are the costs of a data protection officer? Read here
When is there an obligation to appoint a DPO in the narrower sense?
The duty under German law
In its Federal Data Protection Act (Section 38) adopted strict regulations.
Insofar as twenty people are constantly working with the automated Processing personal data, companies must appoint a data protection officer. The following elements must be taken into account here. The number of employees in a company can be included in the overall assessment. Employees who do not have access to data processing equipment with which personal data processed, such as cleaning staff or assembly line workers, should not be taken into account. The status of the persons processing the Processing in the company is irrelevant. It does not matter whether they are full-time or part-time employees, freelancers or temporary workers, as well as trainees, volunteers and interns, and the management also counts as one of the twenty people mentioned above.
As a general rule and at all times, the goal is to avoid considering one-time changes.
The number of employees alone is not sufficient to rule out the obligation to designate a data protection officer. The impact of the company’s activities on natural persons also plays an important role here. If these activities are likely to pose a high risk to the rights of natural persons, a so-called Data Protection Impact Assessment must be conducted; that is, the risks must be examined in detail, and the measures taken by the company to reduce these risks must be taken into account. Companies that carry out processing operations subject to such data protection impact assessments not just once but on a recurring basis must also appoint a data protection officer. For example, if a gas station installs a Video Surveillance If an organization is required to conduct a data protection impact assessment only once, it is not required to appoint a data protection officer.
An obligation also exists if your company personal data on a commercial basis for the purpose of Transmission processed, whereby “commercial” is not to be interpreted in the conventional sense—that is, it also includes activities that do not generate a profit but are carried out for a certain period of time. In practice, this includes companies such as credit bureaus, which check individuals’ creditworthiness, or firms that provide address data to third parties for advertising purposes.
The fact that the data is transmitted anonymously does not constitute an exception to the obligation to provide a name. If you personal data If you process data for market research or opinion polling on behalf of clients, you must also have a data protection officer.
The obligation under EU law
In contrast, most member states of the European Union have not adopted any specific regulations regarding the DPO, so that only the provisions of the General Data Protection Regulation (GDPR, Article 37) must be taken into account.
According to Art.37 para.1 lit.b GDPR there is initially an obligation to designate if the core activity of the company requires extensive regular and systematic monitoring of individuals in the sense of observing their behavior (such as the click behavior of a user on the company's website). The number of data subjects, the amount of data processed and the geographical scope of data collection as well as the duration must be taken into account. For this purpose, only processing operations that are either continuous or repeated and that follow a specific plan and organization should be included.
Finally, it should be noted that the processing operations that are inextricably linked to the core activity should also be considered as one of the core activities, as in the case of healthcare services in hospitals, which cannot be carried out without the core activity. Processing the Health data for patients are possible.
There is also an obligation to designate (Art.37 para.1 lit.c GDPR), if the core activity in the extensive Processing special categories of data or personal data relating to criminal convictions, and Criminal offenses exists. The Processing In most companies, the processing of special data only concerns sick notes, certificates of incapacity for work, pregnancy (maternity protection) and (in the case of Germany and Austria) religious affiliation. However, these are not core activities and these processing operations can be regarded as minor, so that Art.37 para.1 lit.c GDPR can be interpreted as not applicable.
Most companies can benefit from having a data protection officer
If we summarize the aforementioned regulations, we could conclude that companies operating in Germany are only exempt from the requirement to appoint a data protection officer in exceptional cases, and that companies in other EU countries are only required to appoint a data protection officer in a limited number of cases.
That would be a mistake, because even without a designation requirement, the obligations under the GDPR must be observed. Therefore, at least one employee should be assigned to this task and verify that all processing of personal data complies with the legal framework.
At the end of a pure cost-benefit analysis, companies often find that it is cheaper to appoint a data protection officer than to take the risk of disregarding data protection regulations. In addition to the Fineand to the costs of the proceedings (before the Regulatory Authority and, if necessary, the legal proceedings), the company may suffer a loss of trust from its customers.
However, as smaller companies in particular are often faced with data protection obligations (responding to requests from data subjects, Documentation,…) are overwhelmed, it’s worth seeking help from an external data protection officer.
In general, what is the advantage of appointing an external data protection officer? Unlike an in-house employee, who needs time to get up to speed, may make mistakes due to a lack of experience—such as misjudging a situation—and may ultimately have to seek assistance anyway, an external data protection officer possesses the necessary experience to act quickly and effectively. They can consult with colleagues who also have experience in other areas. Depending on the number of hours allocated to the employee serving as the internal data protection officer, the size of the company, and the tasks to be performed, there are different frameworks for an external DPO mandate.
At 2B Advice GmbH, the number of hours in the work packages we offer is adjusted based on the size of the company. As a result, our clients include not only large and medium-sized companies but also small businesses.
Please feel free to contact our sales department so that we can provide you with a quote tailored to your needs.
Similar articles from our blog: Data Protection Impact Assessment (DPIA): What Needs to Be Done? Read here





