EnglishDeutsch
Germany flag

Germany

Datenschutzbeauftragter: When German Law Requires a Data Protection Officer

By Recording Law Editorial Team22 min read
Datenschutzbeauftragter: When German Law Requires a Data Protection Officer

Frequently Asked Questions

When does a German company have to appoint a Datenschutzbeauftragter?

§ 38 Abs. 1 BDSG sets two independent routes. The first applies where at least 20 persons are, as a rule, constantly engaged in the automated processing of personal data. The second applies irrespective of headcount where the processing is subject to a Datenschutz-Folgenabschätzung under Art. 35 DSGVO, or where personal data are processed commercially for transfer, anonymised transfer, or market or opinion research. The grounds in Art. 37 Abs. 1 lit. b and lit. c DSGVO apply in addition.

Does the 20 person threshold count full time equivalents?

The statute counts Personen, persons. Part time staff, working students and marginally employed staff are persons for this purpose. What narrows the count is the requirement that the engagement in automated processing of personal data be constant and, as a rule, regular.

Can a company with fewer than 20 employees be required to appoint one?

Yes, through the second sentence of § 38 Abs. 1 BDSG, which applies unabhängig von der Anzahl, irrespective of the number of persons involved. Commercial processing for the purpose of transfer, anonymised transfer, or market or opinion research triggers it, as does processing subject to a Datenschutz-Folgenabschätzung.

What is the difference between an internal and an external Datenschutzbeauftragter?

An internal appointee is an employee of the organisation. An external appointee performs the tasks on the basis of a service contract, which § 5 Abs. 4 BDSG states expressly for public bodies and which is common practice in the private sector. The legal tasks are identical; the practical difference is access and familiarity on one side, replaceability and independence on the other.

Can a Datenschutzbeauftragter be dismissed?

Where the appointment is mandatory, § 38 Abs. 2 BDSG applies § 6 Abs. 4 BDSG. Removal from the role is possible only in analogous application of § 626 BGB, termination of the employment relationship is inadmissible absent facts justifying extraordinary termination, and that protection continues for one year after the role ends.

Can the managing director or the head of IT take the role?

Those positions determine the purposes and means of processing, so appointing them creates the conflict of interest the role is designed to avoid. Under § 40 Abs. 6 BDSG the supervisory authority may demand removal where a serious conflict of interest exists within the meaning of Art. 38 Abs. 6 DSGVO, or where the appointee lacks the necessary expertise.

Is the Datenschutzbeauftragter liable if the company breaches data protection law?

The controller remains responsible for lawful processing. The tasks in § 7 BDSG are informing, advising, monitoring and cooperating with the supervisory authority, not deciding. Appointing someone does not move the organisation's accountability onto them.

What is the fine for failing to appoint a Datenschutzbeauftragter?

Not the 50.000 Euro figure that circulates. That figure comes from § 43 Abs. 2 BDSG, which applies only to the two offences in § 43 Abs. 1 BDSG concerning the handling of requests and consumer notification under § 30 BDSG, and § 43 Abs. 3 BDSG excludes fines against public bodies. Fines for data protection breaches generally come from Art. 83 DSGVO, which sets two distinct tiers in Art. 83 Abs. 4 and Art. 83 Abs. 5 DSGVO.

Sources and References

  1. § 38 BDSG, Datenschutzbeauftragte nichtöffentlicher Stellen(gesetze-im-internet.de).gov
  2. § 5 BDSG, Benennung der oder des Datenschutzbeauftragten öffentlicher Stellen(gesetze-im-internet.de).gov
  3. § 6 BDSG, Stellung der oder des Datenschutzbeauftragten(gesetze-im-internet.de).gov
  4. § 7 BDSG, Aufgaben der oder des Datenschutzbeauftragten(gesetze-im-internet.de).gov
  5. § 40 BDSG, Aufsichtsbehörden der Länder, einschließlich der Befugnis zur Abberufung nach § 40 Abs. 6(gesetze-im-internet.de).gov
  6. § 43 BDSG, Bußgeldvorschriften des Bundesdatenschutzgesetzes(gesetze-im-internet.de).gov
  7. § 30 BDSG, Verbraucherkredite und die Behandlung von Auskunftsverlangen(gesetze-im-internet.de).gov
  8. § 26 BDSG, Datenverarbeitung für Zwecke des Beschäftigungsverhältnisses(gesetze-im-internet.de).gov
  9. § 2 BDSG, Begriffsbestimmungen, insbesondere öffentliche und nichtöffentliche Stellen(gesetze-im-internet.de).gov
  10. § 626 BGB, Fristlose Kündigung aus wichtigem Grund(gesetze-im-internet.de).gov
  11. BfDI, Beschwerde über Datenschutzverstöße bei den Aufsichtsbehörden, mit der Aufteilung der Zuständigkeiten(bfdi.bund.de).gov
  12. BfDI, Anschriften und Links der Landesdatenschutzbehörden(bfdi.bund.de).gov
  13. Bayerisches Landesamt für Datenschutzaufsicht, Online-Services für nichtöffentliche Stellen, einschließlich der Meldung einer Datenschutzbeauftragten oder eines Datenschutzbeauftragten(lda.bayern.de).gov
Share: