Many companies are currently required to appoint a data protection officer. However, the federal government plans to abolish the additional German regulation under which, as a general rule, companies with 20 or more employees who regularly handle personal data are required to appoint a data protection officer. For small and medium-sized businesses, this could eliminate a formal obligation. However, the responsibility for the lawful handling of personal data remains entirely with the company.
When is a data protection officer required today?
For German companies, the requirements are set forth in two sets of regulations: the European General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG).
According to Section 38 of the Federal Data Protection Act (BDSG), a company must generally appoint a data protection officer if it regularly employs at least 20 people who are engaged in the automated processing of personal data. This does not apply only to employees in the IT department. For example, this may also include employees in human resources, sales, accounting, or customer service who regularly work with digital customer data, personnel data, or other personal information.
Regardless of this number of employees, the obligation also applies if the company carries out data processing for which a data protection impact assessment is required. The same applies in particular to the commercial processing of personal data for the purpose of transmission, as well as for market research or opinion polling.
When does the GDPR apply, regardless of a company’s size?
Article 37 of the GDPR contains specific European requirements. According to this provision, a data protection officer must be appointed, in particular, when the company’s core business involves extensive, regular, and systematic monitoring of individuals.
An obligation to appoint a data protection officer may also arise if the core business involves extensive processing of particularly sensitive data. This includes, for example, health data, biometric data, or information about religious beliefs. As a result, even smaller companies may be subject to the European obligation to appoint a data protection officer.
Therefore, it is not just the number of employees and revenue that are decisive, but also the nature, scope, and risk associated with data processing.
Which obligation should be eliminated in the future?
In its “Program for Economic Recovery and Employment” dated July 2, 2026, the governing coalition announced plans to streamline national data protection regulations and reduce the number of corporate data protection officers in small and medium-sized enterprises. In addition, company data protection officers whose appointment is not based on EU requirements are to be eliminated while maintaining the same level of protection. This could particularly affect the purely national provision of Section 38(1) of the Federal Data Protection Act (BDSG), which requires a data protection officer for organizations with 20 or more employees regularly engaged in automated data processing.
However, a specific effective date has not yet been set. As long as the law has not been amended, the existing requirement to place orders remains in effect without change.
Even if the additional German provision were repealed, the directly applicable requirements of Article 37 of the GDPR would remain in effect. Companies that engage in extensive monitoring or whose core activities involve particularly high risks would therefore still be required to appoint a data protection officer.
Fewer formal requirements do not mean less responsibility
The data protection officer advises the company and monitors compliance with data protection regulations. However, company management remains responsible for ensuring that data processing is carried out lawfully.
Even if the obligation to designate a data protection officer is eliminated in the future, companies must continue to assess legal bases, inform data subjects, process requests for access and erasure, implement technical safeguards, and report data breaches where necessary. Nor will the other documentation requirements under the GDPR automatically disappear as a result.
Violations may still result in regulatory action, claims for damages, and substantial fines. Depending on the nature of the violation, the GDPR provides for fines of up to 20 million euros or four percent of global annual revenue.
Data protection remains the responsibility of management
The planned reform could relieve smaller companies in particular of certain personnel-related formal obligations. However, it does not eliminate the need for data protection. Management should therefore first verify whether, in addition to Section 38 of the BDSG, the European requirements of Article 37 of the GDPR are also met. Even without a mandatory appointment requirement, there must be clear internal rules regarding who is responsible for organizing, monitoring, and documenting data protection.
Do only full-time employees count toward the 20-person limit?
No. The key factor is generally how many people regularly process personal data using automated means, not their weekly working hours.
Does the data protection officer have to be a full-time employee?
No. In general, companies may appoint a qualified internal or external data protection officer.
Can the data protection officer be removed from office at this time?
It is not just because of the announced reform. As long as the appointment requirement remains in effect, the legal provisions governing appointment and removal must also be observed.
Who is responsible if a data protection officer is no longer required?
The company remains responsible—in practice, this means, in particular, the management. Data protection tasks can be delegated, but overall corporate responsibility cannot.
Kostenloser Newsletter
Aktuelle Urteile, Praxistipps und neue Folgen aus Marken-, Urheber-, Medien- und Wettbewerbsrecht. Kompakt per E-Mail.
Double-Opt-in. Abmeldung jederzeit über den Link in jeder E-Mail.

