Unbenanntes Dokument

Data Protection Officer

Intro: What is meant by the appointment of a data protection officer, what function does it have and what must be taken into account when implementing it?

To-Dos: What is the specific procedure for fulfilling the appointment obligation and related duties?

Statements: What have the data protection supervisory authorities published on the subject of appointing a data protection officer?

Appointing a data protection officer in compliance with the law

What is meant by the appointment of a data protection officer, what function does it have and what must be taken into account when implementing it?

If a person is appointed as data protection officer, this means that they must take on legally defined data protection tasks for the appointing company. These tasks are in particular:

  1. Advising the company and its employees on existing data protection obligations
  2. Working towards compliance with data protection regulations, raising awareness and training employees
  3. Advice and review of the data protection impact assessment
  4. Contact point for data protection oversight.

A data protection officer must be appointed in the following cases:
  1. core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale
  2. core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 or personal data relating to criminal convictions and offences referred to in Article 10
  3. processing is carried out by a public authority or body, except for courts acting in their judicial capacity.

The data protection officer can either be an employee of the company (in which case it is referred to as an “internal data protection officer”) or an external expert, i.e. an external data protection officer, is appointed.

When selecting a data protection officer, care must be taken to ensure that he/she has sufficient legal, technical and organizational qualifications. Furthermore, the data protection officer must not have a conflict of interest with other activities that he/she performs in the company. A conflict of interest exists in particular if the person can make decisions regarding the existence or organization of data processing, as is regularly the case with managers. The task of the data protection officer is not to assume organizational responsibility for data processing, but rather to ensure that it is carried out in accordance with the relevant data protection laws.

What is the specific procedure for fulfilling the appointment obligation and related duties?


Determining whether a data protection officer needs to be appointed


Selection of a person sufficiently qualified in data protection who can be appointed as data protection officer


Appointment of the selected person by means of an appointment certificate


Informing the data protection supervisory authority about the appointment of the data protection officer

>> Find out which other data protection obligations have to be considered with respect to European data protection law.

Unbenanntes Dokument

Appoint a cost-effective data protection officer now

Do you need support with the implementation of data protection requirements? about our data protection packages.
Unbenanntes Dokument

We are

familiar with the characteristics of small and large companies

experienced in communicating with data protection authorities

active in data protection for over 10 years.