Few data protection questions are asked as often — and answered as wrongly. The answer has two layers: a European one that asks about risk, and a German one that simply counts people. And around that German threshold there has been an announcement since late 2025 that many already treat as law. It is not.
By Patrick de Kathen, Founder of KlarComply · Reviewed on
Across the EU, appointment is mandatory in only three cases: for public authorities, where the core activity involves large-scale, regular and systematic monitoring of people, and where the core activity involves large-scale processing of special categories of data — health data, for instance. The decisive words are core activity: a trading company keeping a customer database processes data as a means to an end, not as its business model. Under the EU rule, a typical sales, trading or trades SME does not need a Data Protection Officer.
Germany used its opening clause: companies that constantly employ at least 20 people in the automated processing of personal data must appoint a DPO — regardless of risk. Everyone who regularly works with customer, staff or supplier data on a computer counts, part-time staff included. This matters to any company with staff in Germany; Malta, Austria and the Netherlands have no such extra threshold — there, Art. 37 alone decides.
In its Federal Modernisation Agenda of 4 December 2025, the German government pledged to introduce a bill repealing Section 38(1) BDSG by the end of 2026. Pledged is the introduction, not the entry into force — and as of 1 September 2026 no bill exists. Anyone planning today plans with the 20-person threshold. We track changes on our legal status page.
This is the most common misunderstanding. The appointment duty is one duty among many. Without a DPO, everything else remains: the records of processing activities (Art. 30), data processing agreements (Art. 28), technical and organisational measures (Art. 32) — and the duty to demonstrate all of it (accountability, Art. 5(2)). Trained staff are one of those demonstrations. Whoever needs no DPO must document all the more that the organisation stands anyway.
Both are permitted. Internally, the person needs expertise and must be free of conflicts of interest — managing directors, heads of IT and heads of HR are regularly ruled out because they would supervise themselves. Externally, many SMEs buy the role as a service. In both cases the appointment is notified to the supervisory authority. There is no state licensing scheme for DPO expertise anywhere in the EU; privately issued qualification certificates are the market standard.
The free 2-minute check shows where your company stands across the EU AI Act and data protection. Training with a verifiable record per person, tool inventory and audit file come with the subscription from €49/month — cancel monthly.
Yes. The Modernisation Agenda of 4 December 2025 only pledges a bill by the end of 2026; as of 1 September 2026 no bill exists. Until a law enters into force, Section 38 BDSG applies unchanged to companies with staff in Germany.
No. Records of processing, data processing agreements, security measures and demonstrable staff awareness apply independently of the appointment duty — and must be demonstrable under Art. 5(2) GDPR.
The free quick check walks through ten points — AI inventory, training status, transparency duties, responsibilities. Two minutes, no sign-up, an honest result and your concrete gaps.
Start the quick check — free