Datenschutzbeauftragter: When German Law Requires a Data Protection Officer

Datenschutzbeauftragter is one of the most searched terms in German data protection law, and the reason is that the German rule is not the same as the European one. The DSGVO requires an appointment in a defined and fairly narrow set of situations. Germany then adds a national rule in § 38 BDSG that catches many more organisations than the DSGVO alone would.
Almost every short summary of that national rule stops at a single number, twenty people. The number is real, but it is only the first half of the sentence it comes from. § 38 Abs. 1 BDSG contains a second trigger that has nothing to do with headcount at all, and an organisation of three people can fall squarely inside it.
This page sets out both limbs of § 38 BDSG in the order the statute uses them, the DSGVO grounds that apply whatever the headcount, the separate rule for public bodies in § 5 BDSG, the difference between an internal and an external appointment, the protection the role carries under § 6 BDSG, and, just as important, what the role is not.
Information last verified on 20 July 2026. This page provides general legal information and does not constitute legal advice in an individual case.
Two layers of law, not one
The appointment duty in Germany sits on two floors. The upper floor is the DSGVO, which applies directly across the EU and names its own grounds for appointing a data protection officer. The lower floor is national: § 38 BDSG, headed Datenschutzbeauftragte nichtöffentlicher Stellen, which deals with private sector controllers and processors.
The relationship between the two is stated in the first three words of § 38 Abs. 1 BDSG. The German duty applies ergänzend, in addition to, Art. 37 Abs. 1 lit. b and lit. c DSGVO. It does not replace the European grounds and it does not soften them. It adds a further, distinctly German reason to appoint.
That structure is the single most useful thing to understand about this topic. An organisation that is comfortably below the German threshold can still be caught by the DSGVO grounds, and an organisation that is nowhere near the DSGVO grounds can still be caught by § 38 BDSG. The two are checked separately, not against each other.
This page explains the structure. Whether a particular organisation falls inside it is a question about that organisation's actual processing activities, and answering that question for a named business is individual legal advice, which is a regulated activity in Germany and not something this page performs.
The first limb of § 38 BDSG: twenty people
The first sentence of § 38 Abs. 1 BDSG requires the controller and the processor to appoint a Datenschutzbeauftragter where they employ, as a rule, at least 20 persons constantly with the automated processing of personal data. In German: in der Regel mindestens 20 Personen ständig mit der automatisierten Verarbeitung personenbezogener Daten beschäftigen.
Every word in that phrase narrows or widens the count, and three of them do most of the work.
The statute counts Personen, persons, not positions and not full time equivalents. Four people each working a quarter of a week are four persons for this purpose, not one. Working students, part time staff and marginally employed staff are persons.
The processing must be automatisiert, automated. Handling personal data on a computer counts. Purely manual handling of paper files does not fall within this limb.
And the engagement must be ständig and in der Regel, constant and as a rule. This filters out the person who touches a customer record once a quarter, and it means a temporary seasonal spike does not by itself create a permanent duty. It does not filter out someone who processes personal data as a routine part of the job even if that is a small share of their working time.
What the phrase does not do is limit itself to people whose job title mentions data. Anyone who regularly works with personal data in a system counts, which in a modern office is usually a much larger group than a first pass suggests: sales staff in a CRM, HR, accounting, dispatch, support, marketing, and management.
The second limb: the trigger that ignores headcount
The second sentence of § 38 Abs. 1 BDSG is the part that most short explanations omit, and omitting it is the single most common error in circulation on this topic.
It provides that where the controller or processor carries out processing which is subject to a Datenschutz-Folgenabschätzung under Art. 35 DSGVO, or processes personal data commercially for the purpose of transfer, of anonymised transfer, or for the purposes of market or opinion research, they must appoint a Datenschutzbeauftragter irrespective of the number of persons engaged in the processing.
The words unabhängig von der Anzahl are in the statute itself. There is no small business carve out inside this limb. A three person company can be obliged to appoint, and a sole trader with two assistants can be obliged to appoint.
The commercial transfer category deserves particular attention because it is broader than it sounds. It is not aimed only at credit reference agencies. It describes a business model in which personal data are processed geschäftsmäßig, on a commercial and repeated basis, for the purpose of passing them on. Address trading, list broking, data brokerage and commercial lead generation sit inside that description by design. Market and opinion research is named separately and needs no further analysis: a research institute is caught however small it is.
The Datenschutz-Folgenabschätzung route is the other half. Where a planned processing operation triggers the obligation to carry out an impact assessment, the appointment duty follows automatically. The German supervisory authorities publish lists of processing operations for which an impact assessment is mandatory, which is where that assessment is normally anchored in practice.
A worked example of both limbs
Take a fictional logistics firm in Nordrhein-Westfalen with 34 employees. Fourteen of them work daily in the dispatch and customer systems, three in HR, two in accounting. That is 19 persons regularly and permanently engaged in automated processing of personal data. On the first limb alone, the firm sits one person below the threshold, and hiring one more person into any of those functions would cross it. That is how tight the count can be, and it is why the count is done on actual roles rather than on the total payroll.
Now change one fact and leave the headcount alone. Suppose the same firm also sells its customer contact list to a marketing partner as a regular side revenue line. That is processing personal data commercially for the purpose of transfer, and the second limb of § 38 Abs. 1 BDSG applies unabhängig von der Anzahl. The 19 versus 20 arithmetic becomes irrelevant, and the appointment duty exists even if the firm had three employees rather than 34.
The example shows why the twenty person figure, quoted on its own, is misleading. It is a floor for one route into the duty, not a floor for the duty as a whole.
The grounds that come from the DSGVO itself
Because § 38 Abs. 1 BDSG operates in addition to Art. 37 Abs. 1 lit. b and lit. c DSGVO, those two European grounds apply in Germany whatever the German headcount says. Both turn on the controller's or processor's Kerntätigkeit, its core activity, rather than on an ancillary function.
The first of the two concerns core activities consisting of processing operations that require regular and systematic monitoring of data subjects on a large scale. The second concerns core activities consisting of processing on a large scale of special categories of personal data, or of personal data relating to criminal convictions and offences. The operative wording is in Art. 37 DSGVO itself and should be read there, because the terms large scale and core activity carry more weight than a paraphrase can convey.
The practical point is the interaction. An organisation whose core business is tracking behaviour across users, or whose core business handles health data at scale, is on the DSGVO ground regardless of whether 20 people are involved. Conversely, an ordinary trading company with no such core activity is off the DSGVO ground entirely and is assessed only against § 38 BDSG.
Public bodies appoint regardless
For the public sector the question is much simpler. § 5 Abs. 1 BDSG requires public bodies to appoint a Datenschutzbeauftragter, and it says the same applies to public bodies under § 2 Abs. 5 BDSG that participate in competition. There is no threshold, no de minimis rule and no exception for a small authority.
§ 5 Abs. 2 BDSG allows several public bodies to appoint one joint Datenschutzbeauftragter, taking account of their organisational structure and size. That is the mechanism small municipalities and their associated bodies usually use.
§ 5 Abs. 5 BDSG then requires the public body to publish the contact details of its Datenschutzbeauftragter and to communicate them to the BfDI. Publication and notification are two separate duties, and satisfying one does not satisfy the other.
Internal or external
The role can be filled from inside or from outside. § 5 Abs. 4 BDSG puts it plainly for public bodies: the Datenschutzbeauftragter may be an employee of the body, or may perform the tasks on the basis of a service contract. The DSGVO permits the same for private controllers, and an external appointment on a service contract is common practice across the German private sector, particularly in smaller organisations.
The trade off is structural rather than legal. An internal appointee knows the systems, the people and the informal workarounds that never appear in a written process, and is available continuously. An internal appointee also carries the protections described in the next section, which is a real and lasting commitment for the employer.
An external appointee is easier to replace, brings comparison across many organisations, and has no line management relationship to be compromised by. An external appointee also needs to be given access and information deliberately, because nothing reaches them by osmosis.
One constraint applies either way. The role cannot sit with someone who determines the purposes and means of the processing they are supposed to monitor, because that person would be reviewing their own decisions. That is why the head of IT, the head of HR, the managing director and the head of marketing are the classic problem candidates for an internal appointment.
Independence, and the protection against removal
The position of the Datenschutzbeauftragter is protected, and in Germany the protection is unusually strong. For public bodies the rules are set out in § 6 BDSG. § 6 Abs. 3 BDSG provides that the Datenschutzbeauftragter receives no instructions regarding the exercise of the tasks, reports directly to the highest management level, and may not be removed or disadvantaged for performing them.
For the private sector § 38 Abs. 2 BDSG applies a deliberately selected subset of § 6 BDSG: § 6 Abs. 4, § 6 Abs. 5 Satz 2 and § 6 Abs. 6, and § 6 Abs. 4 only where the appointment is mandatory. The independence duties themselves are not in that list because they already apply directly from the DSGVO, so nothing is lost by their absence.
§ 6 Abs. 4 BDSG is the provision that gives the German role its distinctive weight. Removal from the role is permissible only in analogous application of § 626 BGB, the provision on extraordinary termination for good cause. Termination of the employment relationship is inadmissible unless facts exist that would justify termination for good cause without notice. And after the role ends, termination of the employment relationship remains inadmissible for one further year on the same condition.
That trailing year is the part employers most often miss. Ending someone's tenure as Datenschutzbeauftragter does not restore ordinary dismissal rules the next day.
Note the conditional in § 38 Abs. 2 BDSG. § 6 Abs. 4 BDSG applies only where the appointment was mandatory. A purely voluntary appointment made by an organisation that was under no duty does not attract that protection through this route.
Two further protections travel with the private sector role. § 6 Abs. 5 Satz 2 BDSG obliges the Datenschutzbeauftragter to secrecy about the identity of a data subject who has sought advice, and about circumstances allowing that person to be identified, unless released by them. § 6 Abs. 6 BDSG extends a professional right to refuse to give evidence, together with a prohibition on seizure of the corresponding files, where the organisation's leadership or an employee would hold that right.
Expertise, conflicts of interest, and removal by the authority
Expertise is not a formality. § 5 Abs. 3 BDSG requires appointment on the basis of professional qualification and in particular of expert knowledge of data protection law and practice, and of the ability to perform the tasks in § 7 BDSG.
The enforcement edge is in § 40 Abs. 6 BDSG. The supervisory authority may require the removal of the Datenschutzbeauftragter where that person does not possess the expertise necessary to perform the tasks, or where, in the case of Art. 38 Abs. 6 DSGVO, a serious conflict of interest exists. § 40 governs the Land authorities supervising the private sector, so this is a live private sector power and not a public sector curiosity.
The same subsection also obliges the supervisory authorities to advise and support Datenschutzbeauftragte with regard to their typical needs, which is why the Land authorities run advice lines and publish practice guidance aimed at the role rather than at the organisation.
What the tasks actually are
§ 7 BDSG lists the tasks for public bodies, and it is the clearest statutory statement of the role in German law. It covers informing and advising the body and its processing staff about their obligations, monitoring compliance including the allocation of responsibilities, awareness raising, staff training and the associated audits, advising on and monitoring the impact assessment, cooperating with the supervisory authority, and acting as its point of contact.
§ 7 Abs. 2 BDSG permits the Datenschutzbeauftragter to carry out other tasks and duties, and requires the body to ensure that such tasks do not give rise to a conflict of interest. § 7 Abs. 3 BDSG requires the role to be performed with due regard to the risk associated with the processing operations, taking account of their nature, scope, circumstances and purposes. In other words the workload is risk led, not uniform.
For private sector controllers the equivalent task catalogue comes from the DSGVO rather than from § 7 BDSG, but the shape of the job is the same.
What the Datenschutzbeauftragter is not
The most consequential misunderstanding about this role is that appointing someone transfers the compliance obligation to them. It does not. The controller remains the controller, and the accountability for lawful processing stays with the organisation and its management.
The Datenschutzbeauftragter informs, advises, monitors and cooperates with the authority. The verbs in § 7 BDSG are Unterrichtung, Beratung, Überwachung and Zusammenarbeit. None of them is deciding.
So the role is not the person who signs off legal risk for the business. A Datenschutzbeauftragter can record that a planned processing operation raises a serious problem, and management can proceed anyway; what management cannot do is claim afterwards that the risk had been signed off, or dismiss the person for having said so.
The role is also not a substitute for the Betriebsrat. Employee data processing is governed by § 26 BDSG, which permits processing necessary for the employment relationship and, for detecting criminal offences, only on documented factual indications and subject to a proportionality test. § 26 BDSG remains on the books, but the EuGH held on 30 March 2023 in C-34/21 that a national general clause of this kind does not qualify as a more specific rule under Art. 88 Abs. 1 DSGVO. A replacement Beschäftigtendatengesetz has been discussed for years without being enacted: the last draft lapsed with the previous coalition and the project does not appear in the current coalition agreement, so it is not law and should not be treated as imminent. The practical consequences for monitoring at work are covered at workplace surveillance.
Finally, the role is not a lawyer for the organisation and does not represent it. Nor is it a service desk for individuals, although § 6 Abs. 5 BDSG expressly allows data subjects to consult the Datenschutzbeauftragter about the processing of their data and the exercise of their rights, under the confidentiality duty described above. The practical route for an individual whose request is refused is set out at the right of access, and the regulator route at German data protection supervisory authorities.
Notifying the authority
An appointment that nobody outside the organisation knows about is only half done. The contact details of the Datenschutzbeauftragter have to be published and communicated to the competent supervisory authority. § 5 Abs. 5 BDSG states both duties expressly for public bodies, with the communication going to the BfDI.
In the private sector the communication goes to the Landesdatenschutzbehörde of the Land where the controller is established, and every Land authority operates a notification channel for exactly this purpose. The Bayerisches Landesamt für Datenschutzaufsicht, for example, runs an online service for reporting a Datenschutzbeauftragter alongside its breach reporting and complaint services.
The contact details need to be genuinely reachable. A shared functional mailbox that nobody monitors defeats the point of the requirement, since the same address is the one a data subject or the authority will use.
What happens if nobody is appointed
Here a widely repeated error needs correcting, because it changes the whole picture of the risk.
§ 43 BDSG is often presented as the German data protection fine provision. It is not. § 43 Abs. 1 BDSG creates exactly two offences, and both concern § 30 BDSG: failing to handle an Auskunftsverlangen correctly under § 30 Abs. 1 BDSG, and failing to inform a consumer correctly, completely or in time under § 30 Abs. 2 Satz 1 BDSG. § 30 BDSG itself is about consumer credit and the treatment of information requests from lenders in other member states. § 43 Abs. 2 BDSG caps the fine at fifty thousand Euro, and § 43 Abs. 3 BDSG provides that no fines are imposed on authorities and other public bodies.
That is a narrow national provision about credit information handling. It is not the appointment duty, it is not a general data protection penalty, and it is not the DSGVO fine regime. Any source that quotes 50.000 Euro as the penalty for failing to appoint a Datenschutzbeauftragter has merged two unrelated provisions.
The DSGVO fines are separate and are set out in Art. 83 DSGVO, which contains two distinct tiers, one in Art. 83 Abs. 4 DSGVO and a higher one in Art. 83 Abs. 5 DSGVO. Which tier applies depends on which obligation was breached, and the allocation is made by those two paragraphs themselves. They are not a single headline figure and should not be quoted as one.
In practice the more immediate consequence of a missing or unsuitable appointment is administrative rather than financial. Supervisory authorities notice the gap when something else brings the organisation to their attention, typically a complaint or a breach notification, and § 40 Abs. 4 and § 40 Abs. 5 BDSG give them information and access powers to look further. § 40 Abs. 6 BDSG then supplies the removal power where the appointee is unsuitable.
For how the authorities are organised, which one is competent and how a complaint is handled, see German data protection supervisory authorities. For the wider set of German data protection topics see the data privacy overview, the rules on supplier contracts at data processing agreements, and the general guide at Germany.
Frequently asked questions
Frequently Asked Questions
When does a German company have to appoint a Datenschutzbeauftragter?
§ 38 Abs. 1 BDSG sets two independent routes. The first applies where at least 20 persons are, as a rule, constantly engaged in the automated processing of personal data. The second applies irrespective of headcount where the processing is subject to a Datenschutz-Folgenabschätzung under Art. 35 DSGVO, or where personal data are processed commercially for transfer, anonymised transfer, or market or opinion research. The grounds in Art. 37 Abs. 1 lit. b and lit. c DSGVO apply in addition.
Does the 20 person threshold count full time equivalents?
The statute counts Personen, persons. Part time staff, working students and marginally employed staff are persons for this purpose. What narrows the count is the requirement that the engagement in automated processing of personal data be constant and, as a rule, regular.
Can a company with fewer than 20 employees be required to appoint one?
Yes, through the second sentence of § 38 Abs. 1 BDSG, which applies unabhängig von der Anzahl, irrespective of the number of persons involved. Commercial processing for the purpose of transfer, anonymised transfer, or market or opinion research triggers it, as does processing subject to a Datenschutz-Folgenabschätzung.
What is the difference between an internal and an external Datenschutzbeauftragter?
An internal appointee is an employee of the organisation. An external appointee performs the tasks on the basis of a service contract, which § 5 Abs. 4 BDSG states expressly for public bodies and which is common practice in the private sector. The legal tasks are identical; the practical difference is access and familiarity on one side, replaceability and independence on the other.
Can a Datenschutzbeauftragter be dismissed?
Where the appointment is mandatory, § 38 Abs. 2 BDSG applies § 6 Abs. 4 BDSG. Removal from the role is possible only in analogous application of § 626 BGB, termination of the employment relationship is inadmissible absent facts justifying extraordinary termination, and that protection continues for one year after the role ends.
Can the managing director or the head of IT take the role?
Those positions determine the purposes and means of processing, so appointing them creates the conflict of interest the role is designed to avoid. Under § 40 Abs. 6 BDSG the supervisory authority may demand removal where a serious conflict of interest exists within the meaning of Art. 38 Abs. 6 DSGVO, or where the appointee lacks the necessary expertise.
Is the Datenschutzbeauftragter liable if the company breaches data protection law?
The controller remains responsible for lawful processing. The tasks in § 7 BDSG are informing, advising, monitoring and cooperating with the supervisory authority, not deciding. Appointing someone does not move the organisation's accountability onto them.
What is the fine for failing to appoint a Datenschutzbeauftragter?
Not the 50.000 Euro figure that circulates. That figure comes from § 43 Abs. 2 BDSG, which applies only to the two offences in § 43 Abs. 1 BDSG concerning the handling of requests and consumer notification under § 30 BDSG, and § 43 Abs. 3 BDSG excludes fines against public bodies. Fines for data protection breaches generally come from Art. 83 DSGVO, which sets two distinct tiers in Art. 83 Abs. 4 and Art. 83 Abs. 5 DSGVO.
Sources and References
- § 38 BDSG, Datenschutzbeauftragte nichtöffentlicher Stellen(gesetze-im-internet.de).gov
- § 5 BDSG, Benennung der oder des Datenschutzbeauftragten öffentlicher Stellen(gesetze-im-internet.de).gov
- § 6 BDSG, Stellung der oder des Datenschutzbeauftragten(gesetze-im-internet.de).gov
- § 7 BDSG, Aufgaben der oder des Datenschutzbeauftragten(gesetze-im-internet.de).gov
- § 40 BDSG, Aufsichtsbehörden der Länder, einschließlich der Befugnis zur Abberufung nach § 40 Abs. 6(gesetze-im-internet.de).gov
- § 43 BDSG, Bußgeldvorschriften des Bundesdatenschutzgesetzes(gesetze-im-internet.de).gov
- § 30 BDSG, Verbraucherkredite und die Behandlung von Auskunftsverlangen(gesetze-im-internet.de).gov
- § 26 BDSG, Datenverarbeitung für Zwecke des Beschäftigungsverhältnisses(gesetze-im-internet.de).gov
- § 2 BDSG, Begriffsbestimmungen, insbesondere öffentliche und nichtöffentliche Stellen(gesetze-im-internet.de).gov
- § 626 BGB, Fristlose Kündigung aus wichtigem Grund(gesetze-im-internet.de).gov
- BfDI, Beschwerde über Datenschutzverstöße bei den Aufsichtsbehörden, mit der Aufteilung der Zuständigkeiten(bfdi.bund.de).gov
- BfDI, Anschriften und Links der Landesdatenschutzbehörden(bfdi.bund.de).gov
- Bayerisches Landesamt für Datenschutzaufsicht, Online-Services für nichtöffentliche Stellen, einschließlich der Meldung einer Datenschutzbeauftragten oder eines Datenschutzbeauftragten(lda.bayern.de).gov