When do I need a data protection officer?
Data protection has a reputation for being hard to follow. On this one question, that is not true.
In Germany there are exactly seven reasons why a company must appoint a data protection officer. If none of them applies, there is no obligation. A single one is enough to create it.
And here is where it gets complicated.
Four of these seven reasons come from German law. Those are the ones the federal government intends to repeal. The announced date is the end of 2026.
Nothing has been decided so far. Until a law takes effect, all seven reasons apply unchanged.
When is one required, and when not?
Many business owners believe the number of employees decides the matter. That is not correct.
A trade business with 30 employees may be free of the obligation. An office with two people may be subject to it. What matters is what the company does with data.
So it is worth looking at all seven reasons. One of them is enough for the obligation to apply.
The seven reasons
1. The controller is a public authority.
The controller is whoever decides what happens to the data. Here it means every public authority and public body. Courts are exempt as far as they act in a judicial capacity.
This applies, for example, to municipal administrations, schools and universities.
2. The core activity consists of monitoring people on a large scale and systematically.
Core activity means the actual business, not the administration that runs alongside it. The monitoring has to be regular and planned.
This applies, for example, to credit reference agencies, detective agencies and providers of targeted advertising.
3. The core activity is processing specially protected data on a large scale.
Specially protected data includes health data as well as biometric and genetic data. It also covers religion, trade union membership and a person’s sex life.
This applies, for example, to hospitals, genetic laboratories and counselling centres.
4. At least 20 people are constantly occupied with automated data processing.
Automated processing means any work with data on a computer. Part-time staff and temporary helpers count in full. What counts is the person, not the position.
This applies, for example, to a planning office with 22 screen workstations.
5. A processing operation requires a data protection impact assessment.
A data protection impact assessment is a risk review carried out in advance. It becomes necessary when a processing operation is likely to put those affected at serious risk.
This applies, for example, to blanket video surveillance of a shopping centre.
6. Data is processed on a commercial basis in order to pass it on.
Commercial basis means lasting and set up to be repeated. Whether a profit is made does not matter.
This applies, for example, to address brokers.
7. Data is processed for market research or opinion research.
Here, too, the number of employees is irrelevant. The obligation depends solely on the purpose of the processing.
This applies, for example, to opinion research institutes.
What does this mean for you?
Work through the seven reasons one by one. If one applies, you have to appoint a data protection officer. If none applies, you do not.
Three of the seven reasons come from European data protection law. Those remain, whatever Germany decides. The other four come from German law and are up for repeal.
For your company, nothing changes today. As long as no new law applies, all seven reasons stand.
The last relaxation here raised the threshold from ten to twenty people. Thomas Kranig was president of the Bavarian data protection authority at the time. His verdict was blunt.
The German original speaks of a favour that harms the person receiving it.
The reasoning is simple. The duties under data protection law do not disappear when the duty to appoint someone does. It is just that nobody inside the company takes care of them any more.
Fortunately, there is no ban on appointing one
Working without expertise usually costs more in the end. Mistakes surface late, and liability falls on the management.
Nobody has to do without a data protection officer merely because there is no obligation. A voluntary appointment is possible at any time. It brings order to the processes and gives staff and customers one place to turn to.
There is only one thing to keep in mind. Anyone who appoints voluntarily has to follow the same rules as a company under an obligation.
This does not have to be expensive. For small companies, the task is available for modest money as well.
An external data protection officer only charges for the time actually needed. That keeps the effort small and the expertise close at hand.