What skills must a Data Protection Officer (DPO) have?
A few years ago, the General Data Protection Regulation (GDPR) came into force. In the course of this law, many new regulations were introduced, including those requiring the appointment of a data protection officer (DPO) by the company.
This provision is intended to ensure that the controller or processor maintains a high standard of quality in the protection of personal data.
A company has the choice of an internal or external data protection officer to name.
The internal DPO is selected and appointed by management.
What are the tasks of a data protection officer under the GDPR?
You are surely familiar with the term „data protection officer“ (DPO), or at least have heard of it. But what functions and responsibilities come with this role within a company’s Data protection Goes hand in hand? Does your own company even need a data protection officer?
In this article, we provide information on when you need a data protection officer and what obligations and tasks a (company) data protection officer has under GDPR has.
When is a data protection officer required?
Art. 37 of the GDPR specifies the conditions under which the Responsible persons or the data processor is required to appoint a data protection officer. The German legislature has established this requirement in § 38 Federal Data Protection Act (BDSG) (new version).
For example, a data protection officer must always be appointed if at least 20 people in your company are constantly working with automated data processing. Processing of personal data are employed, i.e. you have at least 20 employees who come into contact with personal data.
If you have not yet considered the requirements for appointing a data protection officer, we strongly advise you to assess whether this is necessary.
Tasks of company data protection officers according to GDPR and BDSG in the company
The data protection officer is the person responsible for data protection. He or she must ensure the protection of personal data by complying with relevant data protection regulations.
However, this does not mean that the data protection officer must handle all aspects of data protection within the organization on his or her own. He or she is authorized to delegate tasks and to monitor compliance with data protection regulations. What is crucial is that he or she assumes responsibility for ensuring compliance with data protection regulations.
The data protection officer does not have to be an employee of the company. It is possible to appoint both an internal company data protection officer and an external data protection officer from an expert service provider. The tasks of external data protection officers according to GDPR and BDSG do not differ.
Article 39 of the GDPR defines in more detail exactly what the responsibilities of a (company) data protection officer entail:
- The Data Protection Officer monitors compliance with data protection regulations, in particular those of the GDPR and the BDSG.
He creates and maintains the Processing directory, investigates and resolves the causes of data protection incidents and conducts data protection audits. - The Data Protection Officer advises the controller/processor on all matters related to data protection and assists in implementing data protection requirements.
For example, he develops guidelines, provides advice on data protection impact assessments, and monitors their implementation in accordance with Article 35 of the GDPR. - The data protection officer is the point of contact for all issues relating to both the employer and the employees or the data protection officer. Works Council. External parties such as customers, contractual partners or suppliers can also contact the data protection officer with questions.
- The data protection officer also raises awareness about data protection. For example, he or she is involved in employee training sessions to teach employees how to properly handle personal data in their day-to-day work.
- The data protection officer also works with the supervisory authorities. He serves as the point of contact for the supervisory authorities regarding all data protection matters.
The scope of a data protection officer’s responsibilities is therefore wide-ranging and has expanded since the introduction of the GDPR. He or she should therefore possess the necessary professional qualifications to fulfill his or her duties and responsibilities as a data protection officer competently and knowledgeably.
The data protection officer is not bound by instructions in the performance of his or her duties. However, he or she also does not have the authority to issue instructions. This means that, when it comes to implementing his or her recommendations, the Responsible persons or the data processor. Effective cooperation between the data protection officer and management is therefore crucial for effective data protection within the organization.
Responsibilities Regarding Protection Against Unfair Dismissal
As a designated data protection officer (DSB), the employee is protected against termination, which is justified only in cases of gross misconduct. The Responsible persons also ensures that it provides the DSB with all the necessary resources to carry out its duties.
Election of the data protection officer
When deciding between an in-house or external data protection officer, it is important to consider that an external data protection officer has no bias toward the company itself and therefore remains neutral, which means that no conflicts of interest can arise in the performance of their duties as a data protection officer.
In addition, there are many other advantages that make hiring an external data protection officer a good choice. We’ve listed these advantages in our blog post ‘What Are the Costs of an External Data Protection Officer?,’ where we take a closer look at the costs of an external data protection officer, among other things.
Required expertise
According to GDPR only those who have the "required expertise" should be appointed as DPOs. If the required expertise cannot be fulfilled, the supervisory authorities are entitled to dismiss the DPO.
An external data protection officer typically already possesses the required qualifications. The responsibilities of an external data protection officer are no different from those of an internal data protection officer. Often, an External Data Security Officer However, thanks to their extensive experience, they are better able to ensure the necessary expertise than an in-house DPO.
It is crucial that a DPO possess the necessary expertise. In particular, a basic understanding of data protection law and data protection practices, IT security as well as soft skills in order to be able to GDPR to fulfill the prescribed tasks and duties of a data protection officer.
This includes advising those responsible on data protection issues and supporting the implementation of measures that implement data protection requirements. The DPO is the contact person for the employer, the employees, the Works Council and external parties, such as contractual partners, customers and suppliers. He is also the primary contact for inquiries from and to the responsible supervisory authorities.
The data protection officer should also be involved in employee training measures. The aim is to involve the Processing employees involved in the processing of personal data about general data protection requirements in order to ensure data protection here as well.
The central task of the DPO is to advise the person responsible on the implementation and realization of measures that ensure the set compliant Processing of personal data. It should be noted here that the DPO only has an advisory role and is not responsible for the actual implementation.
Responsible persons In this context, it is important to ensure that the implementation of data protection-compliant processes is not a one-time project, but rather requires ongoing refinement. If there is no plan in place for establishing such processes as part of a data protection organization, the DPO should be involved in developing one.
The compilation of the record of processing activities can serve as a first point of reference for such an organization.
Such a directory helps organize processes that comply with data protection regulations and provides a readily accessible source for obtaining the necessary information about data processing activities.
In the course of establishing data protection-compliant processes, the implementation of data protection-friendly default settings should always be taken into account (privacy by design/default). This, in conjunction with regular data protection audits and risk assessments, is a good way to be able to act in a data protection-compliant manner in the future and avoid legal risks due to a lack of compliance with data protection regulations. GDPR to minimize.





