Services
External data protection officer
As the external data protection officer you appoint, we take on the responsibility that comes with the role under Art. 37 GDPR and § 38 BDSG. Whether a duty to appoint applies is not decided by headcount alone. Even without a duty, a voluntary appointment is often worthwhile, since it creates responsibilities and procedures that work when it matters.
When the duty to appoint applies
Twenty staff
must be constantly engaged in the automated processing of personal data (§ 38 (1) sentence 1 BDSG).
Special categories
of personal data or data on criminal convictions must be the core activity of the processing (Art. 37 (1)(c) GDPR).
Systematic monitoring
of individuals must be the core activity, in extensive and regular form (Art. 37 (1)(b) GDPR).
Transfer as a business
Data are processed commercially for transfer or for market and opinion research. § 38 (1) sentence 2 BDSG.
Self-assessment
Do we need a data protection officer?
von 6
Why a voluntary appointment is often worthwhile
A duty follows from the statute, a benefit from the situation. Where data protection questions arise, an appointment above all creates structure, in that it produces a named responsibility, a known route and someone who already understands your setup.
A notification under Art. 33 GDPR is due within 72 hours, and that period runs at the weekend as well. What has to happen in those hours is set out under Something has happened.
Frequently asked questions
How many staff before we need a data protection officer?
Under § 38 (1) BDSG, from twenty people who are constantly engaged in the automated processing of personal data. Headcount is only one of four triggers, and the other three apply regardless.
What does the appointment cost?
That depends on the size of your organisation and the extent of the processing. We give you the figure in the initial consultation, before any contract exists.
Can we appoint someone internally?
You can. An internal appointment ties up working time, creates special protection against dismissal and regularly produces conflicts of interest, for instance in IT management or in HR.
Related pages
Data protection and security incidents
A personal data breach leaves 72 hours for investigation, defence and notification. When a duty to notify arises and which duties run alongside it.
Record of processing activities
Art. 30 GDPR requires a record. What belongs in it, how far the entries have to go and what its upkeep in the organisation depends on.
The supervisory authority is asking
What sets the tone and scope of the reply, what the underlying reason says about the procedure, and why a complaint rarely ends in a fine.
Get in touch!
Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!
Contact usAlternatively you can request a call back.