Data Protection Officer

In an increasingly digital world, protecting personal data is more important than ever. Whether appointed voluntarily or required by law, an external data protection officer as defined by Art. 37 GDPR will help your company meet GDPR requirements and ensure legally compliant and efficient data processing. With their expertise, they protect your company from legal risks and ensure that your data protection strategies are implemented in a future-proof and practical manner.

What is an external data protection officer?

An external data protection officer is a specialized expert who helps companies and organizations implement and comply with data protection regulations.
The data protection officer analyzes existing data protection processes, identifies potential risks and weaknesses, and develops tailor-made solutions to efficiently meet legal requirements. They also ensure that employees are trained and kept up to date with the latest developments in data protection law. By working with an external data protection officer, companies can ensure that their data protection strategies are both legally compliant and practice-oriented without having to build internal resources.

Advantages of an external data protection officer

Working with an external data protection consultant offers companies numerous advantages. They benefit from the expertise of a specialized professional who is always familiar with the latest legal developments in data protection. This enables efficient and legally compliant implementation of data protection requirements without tying up internal resources. An external consultant also brings an objective perspective to the company, identifies potential risks and weaknesses, and develops tailor-made solutions that strengthen the data protection strategy in the long term. Additionally, the consultant ensures compliance with all legal requirements, such as those of the GDPR, protecting the company from legal and financial risks like high fines. Ultimately, with the support of an external data protection officer, companies can optimize their data protection processes and ensure compliance without setting up an internal department.

Unlike an internal data protection officer, an external consultant brings an objective perspective to your company or organization. Additionally, unlike the appointment of an internal employee, they are not subject to the special protection against dismissal under Section 6 (4) Federal Data Protection Act (BDSG) in conjunction with Section 626 German Civil Code (BGB).

Our services as an external data protection officer

  • Monitoring of data protection obligations
    We support you with the introduction of a data protection management system including all relevant components such as the list of processing activities, deletion concept, data protection declarations and internal guidelines.
  • Analysis and optimization of your processes
    We are pleased to review your existing processes and develop customized solutions to ensure your compliance.
  • Training and sensitization of your
    Data protection affects all areas of a company. We ensure that both company management and employees are familiar with data protection issues.
  • Advice on data protection impact assessments
    We are happy to advise you in connection with the implementation of threshold analyses and data protection impact assessments in accordance with Art. 35 GDPR.
  • Advice on third country transfers
    In our networked world, third country transfers are not the exception, but the rule. In order to bring these into compliance with data protection law, appropriate safeguards must be in place. We will be happy to advise you on the selection of the appropriate guarantees and how these can best be implemented within the company or in the third country.
  • Contact for authorities and affected parties
    Whether requests for information or audits - we represent your interests competently and efficiently.
  • Regular audits and monitoring
    We continuously monitor your data protection measures and ensure that you are always up to date.

Contact persons

Bernhard Veeck

Bernhard Veeck

Attorney at Law | Partner

LL.M. (Media Law) | Adjunct Professor at Frankfurt University of Applied Sciences | Data Protection Officer (TÜV)

Olga Stepanova

Olga Stepanova

Attorney at Law | Partner

LL.M. (Berkeley) | CIPP/E | Certified Specialist for Intellectual Property Law | Certified Specialist for IT Law | Data Protection Officer (TÜV)

FAQ: Data Protection Officer

Under the German special rule in Section 38(1) BDSG (German Federal Data Protection Act), a company must generally appoint a data protection officer if at least 20 persons are normally permanently engaged in the automated processing of personal data. Irrespective of this number of persons, an obligation may arise under Article 37 GDPR if the core activity consists in the large-scale processing of sensitive data, such as health data, or in the regular and systematic monitoring of individuals. Processing operations subject to a data protection impact assessment may also make an appointment necessary. The decisive factor is therefore not only the size of the company but, above all, which data are processed, to what extent and for what purpose. In cases of doubt, the obligation should be assessed and documented on a case-by-case basis.

An internal data protection officer is an employee of the company and naturally has good knowledge of its internal processes. However, he or she must not have conflicts of interest with other duties. A conflict of interest exists in particular where the head of IT is appointed as data protection officer at the same time, because in that management role he or she decides on the technical means and, in some cases, the purposes of data processing, meaning that the necessary independent supervisory function would not be ensured. The position regarding protection against dismissal requires differentiation: the special protection against dismissal under Section 6(4) BDSG in conjunction with Section 38(2) BDSG applies only where the appointment is legally mandatory. There is no such protection where the appointment is voluntary, so the general employment-law rules apply to termination. An external data protection officer is engaged on a contractual basis, often brings broader experience from different sectors and avoids internal conflicts of interest from the outset. Employment-law protection against dismissal does not apply to him or her; however, the removal from office is also subject to the restrictions in Article 38(3) GDPR, so removal on account of the performance of the officer’s duties is not permissible. The choice therefore usually depends on the size of the company, its budget and the expertise available.

The core duties under Article 39 GDPR include monitoring compliance with data protection requirements, advising management and employees, and co-operating with the supervisory authority as a point of contact. The officer also participates in data protection impact assessments. It is important that these duties are performed independently of instructions and without a conflict of interest.

As a rule, it is not the data protection officer who is liable but the company as controller, because the officer has an advisory and supervisory, not a decision-making, function. Personal liability may arise only in cases of gross breach of duty within the officer’s own area of responsibility, for example in the event of complete inaction; the principles of employee liability apply to an internal data protection officer, while contractual liability provisions apply to an external officer. The actual responsibility under data protection law remains with management.

No, this is generally not permissible because management itself decides on the lawfulness of data processing and the data protection officer is intended to monitor those decisions independently. This dual role would create a clear conflict of interest within the meaning of Article 38(6) GDPR. For the same reason, other management functions with decision-making authority over data processing are generally incompatible with the role.