Legal obligation

Data Protection Officer appointment threshold

Data Protection Officer appointment threshold — legal obligation, Germany. It binds private-sector organisations that generally employ at least 20 people continuously engaged in the automated processing of personal data.

Jurisdiction
Germany
Record class
Legal obligation
Instrument
Reporting
Last verified

Where this applies

This record is scoped to Germany. Scope is part of the claim: a rule that binds one part of a country does not bind the whole of it, and this library states the scope its sources state.

Instrument

Bundesdatenschutzgesetz (BDSG), §38

Who it binds

Private-sector organisations that generally employ at least 20 people continuously engaged in the automated processing of personal data

What it requires

BDSG §38: an organisation must appoint a Data Protection Officer "soweit sie in der Regel mindestens 20 Personen ständig mit der automatisierten Verarbeitung personenbezogener Daten beschäftigen." This 20-person threshold is a German-specific addition on top of GDPR, which does not itself set a headcount threshold for this duty. Supervision is split under BDSG §40: the 16 Länder data-protection authorities cover the private sector, while the Federal Commissioner for Data Protection and Freedom of Information (BfDI) covers federal public bodies, social security carriers, and telecom/postal providers.

Route to the authority

Last verified:

Related records and requirements

This page is for information only; it is not legal advice, and it does not establish whether this record applies to your business. Verify current status through the official source above.

Cite this page

Attributing this record helps other researchers verify it independently.

"Data Protection Officer appointment threshold." Certifidex, FutureTechnologies. Last verified 21 August 2026. https://certifidex.com/countries/de/bdsg-dpo-threshold

All Germany records →