Data protection officer (DPO)

Data protection glossary · 1 minute read

The data protection officer monitors compliance with data protection rules within an organisation and is the point of contact for the supervisory authority and data subjects.

When is a data protection officer mandatory?

In Germany, designation is mandatory once 20 or more persons regularly process personal data by automated means. The role can be filled internally or assigned to an external data protection officer, who is formally appointed and is personally liable.

Irrespective of headcount, the obligation applies, among other cases, where the core activities consist of large-scale processing of special categories of personal data or large-scale regular monitoring, or where processing is subject to a data protection impact assessment.

Tasks and position

The data protection officer advises management and staff, monitors compliance with data protection law, provides training, advises on data protection impact assessments and cooperates with the supervisory authority.

The DPO does not receive any instructions regarding the performance of their tasks and must not be penalised for performing them. Their contact details must be published and communicated to the supervisory authority.

Art. 37 GDPR
Obligation to designate, qualifications and publication of contact details.
Arts. 38 and 39 GDPR
Position and tasks of the data protection officer.
Section 38 BDSG
Obligation to designate a DPO, as a rule from 20 persons, and special protection against dismissal.

Last updated: September 2026

Questions about this topic?

Dr. Georg Schröder, LL.M. · Managing Director, Lawyer, Data Protection Officer

Book a consultation

In 20 minutes you will know where you stand.

We clarify where action is needed on data protection, AI and information security - and what you should do next.