Many business owners are aware of the obligation to appoint a data protection officer. The appointment on this topic However, it often raises questions such as „Do I need a data protection officer?“, „Who is actually eligible to be one?“ and so on.
A topic for everyone
And even if you already employ a data protection officer or are one yourself, it is still worth reading on. As a data controller, you simply cannot avoid this issue, particularly at a time when internal business processes are being adapted to comply with the requirements of the EU General Data Protection Regulation (GDPR).
Under current legislation, where are data protection officers deployed?
The obligation to appoint a data protection officer in writing no later than one month after commencing business operations arises from the Federal Data Protection Act (BDSG, Section 4f) and applies whenever personal data is processed either automatically – that is, using data processing equipment such as a PC – or non-automatically, i.e. manually. This is likely to apply to all organisations in the first instance, which is why the Act sets out a number of exceptions to the obligation to appoint a data protection officer.
What does a data protection officer actually do?
Now that it has been established when a data protection officer must be appointed, we must clarify what duties they are required to perform. This brings us to the scope of the data protection officer’s responsibilities, which will in future be determined by the GDPR. There is no catch-all clause here for national regulations – as there is for the obligation to appoint a data protection officer – so the scope of their responsibilities will change somewhat compared with the current legal situation.
In principle, however, the company remains responsible for compliance with data protection regulations, whilst the data protection officer can „only“ work towards ensuring compliance. As has been the case to date, this is to be achieved primarily by providing information and advice to the company and to staff involved in data processing regarding existing data protection obligations. In summary, this results in the following range of duties:
- Providing information and advice to the company and to staff involved in data processing regarding existing data protection obligations (legislation, case law, etc.)
- Monitoring compliance with data protection regulations and organisational policies on the protection of personal data
- Raising awareness and training staff
- Monitoring and advice on carrying out a data protection impact assessment
- Cooperation with and acting as a point of contact for data protection authorities
- Contact person for those affected
What is the role of the Data Protection Officer?
It is only reasonably possible to fulfil these duties if the data protection officer can act independently of the body being supervised. He must therefore not be bound by instructions with regard to the fulfilment of his duties and must not be dismissed or disadvantaged on account of his activities as a data protection officer. This has been the case to date and will remain so. It is, however, questionable whether the advantages currently provided for under the law – in the form of special protection against dismissal for the Data Protection Officer pursuant to Section 4f(3) of the Federal Data Protection Act (BDSG) – will continue to apply. The GDPR makes no provision on this matter, and the aforementioned catch-all clause does not apply here either. [I assume, however, that case law will uphold the special protection against dismissal, on the basis of an argument such as „protection of the position must be maintained under employment law“ or similar.] In any case, the fact remains that the data protection officer will report directly to the highest level of management and that the role entails obligations of secrecy and confidentiality. How this is to be reconciled with increased cooperation with the data protection authorities remains to be seen.
Who can be appointed as a data protection officer?
It is up to the company’s management to decide who will ultimately hold the post of Data Protection Officer. However, before Mr F. is transferred from the XY department and retrained, it is important to bear in mind that the GDPR sets out a number of basic requirements which the Data Protection Officer must fulfil. In addition to technical, legal and organisational knowledge, personal qualities (e.g. a willingness to undertake further training, conflict-resolution skills, etc.) must also be taken into account when selecting the Data Protection Officer. Whether an in-house employee or an external service provider is ultimately appointed as the data protection officer, however, is irrelevant.
Conclusion
Whether under the new or the old legal framework, the company is responsible for complying with data protection requirements, whilst the data protection officer works to ensure that this obligation is effectively met. His or her appointment is therefore, and remains, a legal requirement, meaning that every company will, as a matter of course, have to deal with this issue.
Company managers must first determine whether there is, in fact, an obligation to appoint a data protection officer in the case in question. If the answer is yes, the second question arises: who should do the job? Whether the person is internal or external is, in principle, irrelevant. As mentioned, only two things are crucial. Firstly, there must be no conflicts of interest that would preclude suitability for the role. And secondly, the appointment of the data protection officer – whether internal or external – must not be a mere token gesture. Furthermore, from the company’s perspective, simply appointing a data protection officer is not enough, as there are also further obligations to cooperate and provide support. And if this set of issues is not addressed at all, or is dealt with too laxly, there is a risk of (even higher in future) fines at the end of the day.
Further links
- With our Opti.Tax.Doku software, we can help you process your data. Here You can find further information here.
- Still not sure exactly how the GDPR works? You can watch an explanatory video here.
-
Find further information and the full article at https://diercks-digital-recht.de






