Data Protection Officer: When Companies Need a DPO

From 20 employees who are regularly involved in the automated processing of personal data, companies must appoint a data protection officer and report this appointment to the competent supervisory authority.
In short: A data protection officer (DPO) monitors compliance with the GDPR within a company. Appointment becomes mandatory as soon as, as a rule, at least 20 people are constantly employed in automated data processing, or independently of that number in certain cases involving data protection impact assessments or data transfers. If a company fails to appoint a DPO despite being required to, fines of up to €10 million or 2% of annual turnover are possible.
Who is affected by the obligation to appoint a data protection officer?
This affects companies in which, under Section 38 BDSG (Bundesdatenschutzgesetz, Federal Data Protection Act) in conjunction with Article 37 GDPR, as a rule at least 20 people are constantly employed in the automated processing of personal data. What matters exclusively is this headcount tied to data processing, not the total number of employees and not the company's revenue. A small company with many employees in customer service or accounting who work with databases or CRM systems daily can therefore reach the threshold faster than expected. Independently of this number, the obligation also applies if the business requires certain data protection impact assessments or has certain data transfer cases. Anyone unsure whether their company belongs to this group should systematically record internal data processing and document the headcount tied to data.
What tasks does the data protection officer take on?
The data protection officer is the central point of contact for data protection questions within the company: they monitor whether personal data is processed lawfully, advise management and employees on new processing operations, and also serve as a contact point for data subjects and for the supervisory authority. This dual role, advising internally while being reachable externally, is why the contact details must be published and the appointment reported.
What exactly do you need to do?
Once it is clear that the obligation applies, the path to appointing a data protection officer runs through the following steps:
- Check whether the threshold of 20 people with automated data processing has been reached.
- Decide: internal or external data protection officer.
- Qualify the DPO professionally, or engage a service provider with proven expertise.
- Publish the DPO's contact details on the website.
- Report the appointment to the competent supervisory authority.
When deciding between an internal and an external solution, it is worth taking a close look at potential conflicts of interest: an external data protection officer sits outside the company hierarchy and thereby avoids liability questions that can arise with an internal appointment within the same business. Already at the selection stage, it is worth checking relevant training or certifications, so that the professional qualification can be proven if a dispute arises.
By when, and how often, does the obligation apply?
The obligation to appoint arises as soon as one of the stated conditions is met for the first time. This is not a one-off deadline that you check off once: as long as the threshold of 20 people with automated data processing is reached, or a corresponding data protection impact assessment or transfer case exists, an appointed data protection officer must be available at all times. This also applies if the position needs to be refilled in the meantime, for example because an internal DPO leaves the company. Companies should therefore regularly review the relevant headcount to recognize a newly arising obligation in good time, especially during growth phases, when the threshold can be crossed unnoticed.
What are the consequences of violating the appointment obligation?
If a data protection officer is not appointed despite the existing obligation, fines of up to €10 million or 2% of annual turnover are possible. This scale makes clear that the appointment is not a mere formality but is taken seriously by supervisory authorities. A tool such as Company Audit gives an overview of exactly which obligations apply to your company.
The key points at a glance:
| Aspect | Rule |
|---|---|
| Threshold | as a rule, at least 20 people with automated data processing |
| Special cases | certain data protection impact assessment or data transfer cases |
| Legal basis | Section 38 BDSG · Article 37 GDPR |
| Fine range for violations | up to €10 million or 2% of annual turnover |
Frequently asked questions
The following answers go into more detail on the most important individual questions about the appointment obligation.
Does every company have to appoint a data protection officer?
No. The obligation only arises once, as a rule, at least 20 people are constantly employed in the automated processing of personal data, or, independently of that, certain data protection impact assessment or data transfer cases exist.
Is an internal or external data protection officer more sensible?
Both are permitted. An external data protection officer avoids conflicts of interest and liability questions that can arise with an internal appointment within the same business.
Does the obligation also apply below 20 employees?
Not formally required, but even below this threshold, a data protection officer can make sense if the company processes particularly sensitive data.
Where must the data protection officer's contact details be published?
The contact details must be published on the company's website so that data subjects and the supervisory authority can reach the data protection officer.
Who must the appointment of the data protection officer be reported to?
The appointment must be reported to the competent supervisory authority, in addition to publishing the contact details on the company's own website.
Source: Section 38 BDSG · Article 37 GDPR. This article is general information and does not replace individual legal advice. As of: July 2026.
Share this article
Stay up to date
Get the latest articles, insights and industry updates straight to your inbox.
Decide for yourself what Google shows you
Google lets you choose which sources appear more prominently in your search results: in Top Stories and in AI answers. Two clicks, and you see the sites you trust.
Add provimedia.de to my preferred sourcesRelated articles
More articles you might find interesting.
Recapitulative Statement (ZM), OSS, and Intrastat in EU Trade
ZM due by the 25th of the following month, OSS filed quarterly, Intrastat from the threshold: EU reporting obligations explained compactly.
Ensuring Product Safety Under the GPSR
The GPSR and Germany's ProdSG require every seller of non-food products to carry out a risk analysis, appoint an EU responsible person, and provide warning notices, even for tiny quantities.
Product Liability: When Manufacturers Are Liable Without Fault
Manufacturers are liable without fault for defective products: product liability insurance protects against claims that could threaten a company's existence.
Ihre Unternehmerpflichten im Griff
Company Audit erstellt Ihnen in wenigen Minuten eine individuelle Pflichtenliste – mit Fristen-Kalender, Erinnerungen und KI-Assistent. Für Selbständige und KMU.