"Do we need a Data Protection Officer?" is a question most SMEs answer too late, and usually with the wrong assumption that DPOs are only for large companies. Size isn't the trigger - the nature and scale of your processing is, and in Germany an additional headcount rule catches most SMEs. This guide gives you the criteria in plain language and a quick decision table. To compare models and costs once you've confirmed the obligation, see the external DPO pillar.
- Under GDPR Art. 37: large-scale systematic monitoring, large-scale special-category data, or a public authority.
- Under German § 38 BDSG: 20+ people regularly engaged in automated processing - or DPIA-triggering processing, regardless of size.
- Either trigger is enough; the German one is the most commonly underestimated.
When Is a DPO Mandatory?
What are the exact criteria?
A DPO is mandatory in any of these situations:
- GDPR Art. 37 - large-scale systematic monitoring of individuals (behavioural analytics, tracking-based advertising, automated profiling at scale).
- GDPR Art. 37 - large-scale special-category data (health, biometric, racial/ethnic origin, political or religious data).
- GDPR Art. 37 - public authority or body (regardless of size).
- German § 38 BDSG - 20+ people regularly engaged in automated processing of personal data.
- German § 38 BDSG - DPIA-triggering processing, regardless of headcount (e.g. AI-assisted decisions about people).
"Regularly engaged" doesn't mean full-time data work - it means handling personal data is a routine part of the role. Sales using a CRM, HR processing applications, marketing running campaigns: they all count.
Quick Decision Table
Does this apply to my company?
| Situation | DPO required? |
|---|---|
| 40 employees, CRM + email marketing | ✅ Very likely |
| 15 employees, AI-assisted candidate screening | ✅ Yes (DPIA-triggering) |
| 60 employees, SaaS with customer data | ✅ Yes |
| 25 employees, internal admin only, minimal data | ⚠️ Case-by-case |
| Any size, processing health or biometric data | ✅ Yes |
What If We Appoint Voluntarily?
Are there strings attached?
Yes. Once appointed, a voluntary DPO has the same legal protections as a mandatory one: they can't be dismissed without cause, can't be penalised for doing the job, and must have the same structural independence (Art. 38). Appoint voluntarily only after confirming the obligation doesn't already apply - otherwise you take on the duties without intending to.
not sure where you land? ETHYX confirms the obligation in a free assessment and, where you need one, provides the certified external DPO to fill it.