AVANTCORE Rechtsanwälte
Menu

Data Protection Officer only required from 20 employees onwards?

The GDPR and the new Federal Data Protection Act (BDSG) have been in force since May 2018. Repeatedly, voices have been raised that the data protection regulations, in particular, overtax smaller companies. The legislature has now made improvements: soon a data protection officer will only need to be appointed from a company size of at least 20 employees.


Long before the data protection regulations that have been in effect since May 2018 came into force, many voices were raised that smaller companies in particular would be overwhelmed by these regulations. A central point of contention in this regard was the issue of the data protection officer.

According to the BDSG, such an officer had to be appointed if a company "as a rule employed at least ten persons permanently with the automated processing of personal data". However, this threshold is reached very quickly in practice, since part-time employees are also fully counted and the mere use of an email program already constitutes automated processing of personal data.

Data Protection Officer only required from 20 employees onwards?

The Bundestag decided on 27.06.2019, among other things, that in future a data protection officer will only need to be appointed from a company size of 20 employees. This is intended to provide significant relief, particularly for small companies, since the appointment of a data protection officer entails non-negligible costs.

However, companies with fewer than 20 employees may still be obliged to appoint a data protection officer, namely when they are already obliged to do so under the GDPR. For instance, companies that process special categories of personal data (e.g. concerning race, ethnic origin, political opinion, religious beliefs, trade union membership, health or sexual life) or companies whose core activity consists in the processing of personal data are required to appoint a data protection officer, regardless of their size.

No relief for companies

However, it may be doubted whether the promised relief will actually materialize through this amendment to the law. The amendment to the BDSG does not mean that the requirements of the GDPR and the BDSG only need to be complied with from a company size of 20 employees. Rather, these obligations continue to apply unchanged and also for small and very small enterprises. In this respect, in most cases, even without an obligation to appoint a data protection officer, it would be sensible and possibly also more cost-effective to obtain competent support from a data protection officer.

Conclusion

The fact that a data protection officer will in future only need to be appointed from a company size of at least 20 employees does not, contrary to the claims made by the political class, actually result in any real relief for small companies. For this to happen, the legal obligations arising from the GDPR/BDSG would have had to be reduced, which, however, the law does not do. The same data protection regulations continue to apply, the compliance with which small companies alone will not be able to manage without external help. In this respect, they will also continue to depend on competent support.

Last updated
04 October 2019
Author
Christopher A. Wolf, MBA

This is a translation of the German original. In case of discrepancies, the German version prevails.

All news
Data Protection Officer only required from 20 | AVANTCORE