KlarComply
HomeKnowledge › DPO requirements

The Data Protection Officer: when appointment is mandatory — and what the law actually says in 2026

Few data protection questions are asked as often — and answered as wrongly. The answer has two layers: a European one that asks about risk, and a German one that simply counts people. And around that German threshold there has been an announcement since late 2025 that many already treat as law. It is not.

By , Founder of KlarComply · Reviewed on

Infographic: The Data Protection Officer: when is one mandatory? — Two layers, one widespread misconception — status 1 September 2026.
The key points of this article as a graphic — feel free to share or download it.

The EU rule: Art. 37 GDPR asks about risk, not size

Across the EU, appointment is mandatory in only three cases: for public authorities, where the core activity involves large-scale, regular and systematic monitoring of people, and where the core activity involves large-scale processing of special categories of data — health data, for instance. The decisive words are core activity: a trading company keeping a customer database processes data as a means to an end, not as its business model. Under the EU rule, a typical sales, trading or trades SME does not need a Data Protection Officer.

The German add-on: Section 38 BDSG counts people

Germany used its opening clause: companies that constantly employ at least 20 people in the automated processing of personal data must appoint a DPO — regardless of risk. Everyone who regularly works with customer, staff or supplier data on a computer counts, part-time staff included. This matters to any company with staff in Germany; Malta, Austria and the Netherlands have no such extra threshold — there, Art. 37 alone decides.

The repeal is announced — not law

In its Federal Modernisation Agenda of 4 December 2025, the German government pledged to introduce a bill repealing Section 38(1) BDSG by the end of 2026. Pledged is the introduction, not the entry into force — and as of 1 September 2026 no bill exists. Anyone planning today plans with the 20-person threshold. We track changes on our legal status page.

No DPO does not mean no data protection

This is the most common misunderstanding. The appointment duty is one duty among many. Without a DPO, everything else remains: the records of processing activities (Art. 30), data processing agreements (Art. 28), technical and organisational measures (Art. 32) — and the duty to demonstrate all of it (accountability, Art. 5(2)). Trained staff are one of those demonstrations. Whoever needs no DPO must document all the more that the organisation stands anyway.

Internal or external?

Both are permitted. Internally, the person needs expertise and must be free of conflicts of interest — managing directors, heads of IT and heads of HR are regularly ruled out because they would supervise themselves. Externally, many SMEs buy the role as a service. In both cases the appointment is notified to the supervisory authority. There is no state licensing scheme for DPO expertise anywhere in the EU; privately issued qualification certificates are the market standard.

Where to start

The free 2-minute check shows where your company stands across the EU AI Act and data protection. Training with a verifiable record per person, tool inventory and audit file come with the subscription from €49/month — cancel monthly.

Frequently asked questions

Does the German 20-person threshold still apply despite the announced repeal?

Yes. The Modernisation Agenda of 4 December 2025 only pledges a bill by the end of 2026; as of 1 September 2026 no bill exists. Until a law enters into force, Section 38 BDSG applies unchanged to companies with staff in Germany.

If no DPO is required, do the other GDPR duties fall away?

No. Records of processing, data processing agreements, security measures and demonstrable staff awareness apply independently of the appointment duty — and must be demonstrable under Art. 5(2) GDPR.

Where does your company stand?

The free quick check walks through ten points — AI inventory, training status, transparency duties, responsibilities. Two minutes, no sign-up, an honest result and your concrete gaps.

Start the quick check — free
Read on AI literacy obligation → Building an AI inventory → Labelling AI content (Art. 50) → The AI Act for SMEs → Writing an AI policy → AI in hotels → AI in the beauty salon → Appointing an AI lead → ChatGPT at work and the GDPR → Approving AI tools → Finding shadow AI → AI and employee representation → Classifying AI risk → The AI supplier questionnaire → Customer data in an AI tool → Penalties under Article 99 → Trade secrets and AI tools → AI in physiotherapy practices → AI in dental practices → AI in tax and accounting firms → AI in hair salons → AI in advertising agencies → AI for estate agents → AI in car repair shops → AI in trades businesses → AI in law firms → Records of processing → DPA (Art. 28) → Data breach & 72 hours → GDPR staff training → US tools & transfers →
Sources:
Article 37 GDPR — designation of the data protection officer
Section 38 BDSG — data protection officers of private bodies (German)
Reviewed on 1 September 2026 · Reflects the Digital Omnibus · This article is general information and not legal advice.