Most SMEs operating in Germany and the EU do not need a full-time internal Data Protection Officer. But most do need reliable GDPR coverage - and the gap between "we have nobody doing this" and "we have a qualified DPO in place" is where the real risk sits. An outsourced DPO solves that gap without the hiring cost, the conflict-of-interest risk, or the single-point-of-failure problem that comes with a lone internal privacy lead. This page covers who legally needs a DPO, what the models actually cost, and what good external DPO services look like in practice.
- A DPO is mandatory under GDPR Art. 37 and, in Germany, from 20 people regularly processing personal data (§ 38 BDSG).
- An external DPO delivers the same legal function without the hiring cost or conflict-of-interest risk.
- Internal DPO ≈ €60,000-90,000/year; external ≈ €150-1,500/month; ETHYX from €299/month.
- The Managing Director stays personally liable - the DPO advises, it does not transfer accountability.
Who Needs a Data Protection Officer?
Is a DPO something every company has to appoint - or just large organisations?
The obligation has two legal sources: Article 37 of the GDPR at EU level, and § 38 BDSG in Germany. Size alone is not the only trigger, the nature of the processing counts as much. Four situations require a formal DPO appointment, and at least one of them applies to most German SMEs:
1. At least 20 people are regularly involved in automated processing of personal data (§ 38 BDSG). This is not just IT staff: HR, sales, marketing and customer support all count when customer, applicant or employee data is a routine part of the role. A 30-person company with a CRM and a newsletter tool typically crosses this threshold.
2. The company runs processing that requires a Data Protection Impact Assessment (§ 38 Abs. 1 S. 2 BDSG). AI-assisted decisions about individuals, behavioural profiling and biometric data all fall here - regardless of headcount.
3. Core activities involve large-scale processing of special category data (Art. 37 GDPR). Health data, biometric data, data revealing racial or ethnic origin, political opinions, or religious beliefs: any company processing these at scale needs a DPO.
4. Large-scale, systematic monitoring of individuals, or the organisation is a public authority (Art. 37 GDPR). Behavioural analytics, tracking-based advertising and automated customer profiling at scale all fall here; public sector bodies need a DPO regardless of size.
In practice, the § 38 BDSG threshold of 20 people is the criterion German SMEs cross most often: it covers almost every company with a CRM, an HR system, a marketing platform, or a support tool.
Not sure whether your company crosses the threshold? → Run a GDPR compliance status check
When Is a DPO Legally Required Under GDPR and Local Law?
What are the exact criteria - in plain language?
A DPO is mandatory in the four situations described above - two triggers from the German BDSG, two from GDPR Article 37. The German BDSG threshold of 20 people regularly involved in automated data processing is the one most often underestimated by SMEs. "Regularly involved" does not mean full-time data work - it means personal data processing is a routine part of the role. Sales reps using a CRM, HR staff processing applications, marketers running email campaigns, customer support agents accessing ticket systems: they all count.
Practical examples for companies operating in Germany:
| Company situation | DPO required? |
|---|---|
| 40 employees, CRM + email marketing in use | ✅ Very likely |
| 15 employees, AI-assisted candidate screening | ✅ Yes (DPIA-triggering processing) |
| 60 employees, SaaS product with customer data | ✅ Yes |
| 25 employees, internal admin only, minimal personal data | ⚠️ Case-by-case assessment needed |
| Any size, processing health or biometric data | ✅ Yes |
What happens if we appoint a DPO voluntarily?
You can - but once appointed, the same legal protections apply. A voluntarily appointed DPO cannot be dismissed without cause, cannot be penalised for doing their job, and must be given the same structural independence as a mandatory one. Appoint voluntarily only after confirming the obligation does not already apply.
Internal vs. External Data Protection Officer
What are the real trade-offs between keeping it in-house and outsourcing?
Both models are legally valid. The question is which one works in practice for a company your size.
| Criterion | Internal DPO | External DPO | ETHYX Model |
|---|---|---|---|
| Hiring / setup effort | High - recruit, qualify, define role | Low - contract and handover | Very low - platform onboarding + DPO in one step |
| Cost predictability | Low - salary, training, sick leave, turnover | High - fixed monthly fee | High - from €299/month, all-inclusive |
| Specialist expertise | Depends on individual | Specialised, kept current | AI Act + GDPR specialist, natively integrated |
| Independence / conflict risk | High risk if DPO has operational role | Structurally independent | Structurally independent |
| Ongoing responsiveness | Limited by capacity, leave, resignation | Contractually defined | Continuous, platform-backed |
| Documentation support | Self-organised | Varies by provider | Guided workflows: ROPA, TOM, DPA, DPIA |
| GDPR + AI Act coordination | Rarely covered | Provider-dependent | Native integration - both handled in one workflow |
When does an internal DPO make sense?
In larger organisations - typically around 250 employees and above - where the volume of data-related decisions justifies a dedicated internal role that can be kept fully separate from operational responsibilities. For most SMEs between 20 and 150 employees, that structural separation is difficult to maintain, and the cost of a qualified internal hire is disproportionate to the actual workload.
How Much Does an External DPO Cost?
Can you give realistic numbers - not a price list, but a real comparison?
Yes. External DPO costs vary by scope, provider type and company complexity. The following are practical market ranges, not regulatory benchmarks:
| Model | Typical monthly cost | What's typically included |
|---|---|---|
| Basic external DPO | €150-500/month | Formal appointment, point of contact, annual check |
| Full-service external DPO | €500-1,500/month | Documentation review, training support, incident handling |
| Internal DPO (full-time hire) | €60,000-90,000/year (≈ €5,000-7,500/month) | Full-time capacity, but conflict risk and single-point-of-failure |
| ETHYX model | From €299/month | External DPO + GDPR platform + EU AI Act compliance |
The internal hire comparison is worth sitting with. A qualified Data Protection Officer commands a market salary of €60,000-90,000 per year in Germany - before training costs, before the risk of that person leaving, and without AI Act coverage typically included. An external DPO engagement at €300-500/month delivers the same legal function at a fraction of that cost, with continuity and specialisation built in.
What is the cost of not having a DPO when one is required?
GDPR fines reach up to €20M or 4% of worldwide annual turnover. Failing to appoint a mandatory DPO is itself a violation - independently sanctionable. Beyond fines, the Managing Director can be personally liable for demonstrably inadequate organisational measures (under German law: §130 OWiG, §43 GmbHG). The cost of coverage is predictable. The cost of non-compliance is not.
What Does a Good External DPO Actually Do?
What am I paying for - in concrete terms?
A qualified external DPO fulfils the legal function defined in GDPR Articles 37-39. In practice, that means:
- Documentation review: Records of Processing Activities (ROPA), privacy notices, TOMs and Data Processing Agreements are reviewed regularly for completeness and accuracy. → ROPA & GDPR documentation guide
- Regulator and data subject contact point: The DPO is the official point of contact for supervisory authorities and for individuals exercising their rights under GDPR.
- Staff training support: Role-specific GDPR training, AI literacy guidance under Article 4 of the EU AI Act, onboarding support for new employees handling personal data.
- Incident management: When a data breach occurs, the DPO coordinates the 72-hour notification obligation to the supervisory authority and supports internal response procedures.
- Audit readiness: Before a regulatory inspection or client due diligence request, the DPO supports documentation preparation and gap closure.
- DPIA oversight: For high-risk processing activities - particularly those involving AI tools - the DPO conducts or reviews the Data Protection Impact Assessment.
What an external DPO does not do: relieve management of responsibility. The DPO advises, reviews and documents. Operational decisions remain with the company - and accountability remains with the Managing Director.
Which Companies Benefit Most from an Outsourced DPO?
Is this really relevant to our type of company?
An outsourced DPO or DPO as a service model is the right fit for:
- Growing SMEs (20-150 employees): The legal obligation often kicks in before a dedicated internal compliance hire is economically justified. An external DPO closes that gap cleanly.
- Digital and SaaS businesses: Extensive use of cloud services, CRM platforms, marketing automation and third-party integrations creates a complex processing landscape that needs continuous monitoring, not a one-time setup.
- Businesses using AI tools: ChatGPT, Microsoft Copilot, HR screening tools, analytics platforms - any company using AI in a professional context has simultaneous GDPR and EU AI Act obligations. A data protection consultant with AI Act expertise covers both. → EU AI Act compliance for SMEs
- B2B companies with enterprise clients: Procurement processes at larger clients increasingly include GDPR documentation checks. A formally appointed DPO is a credible signal - not just a compliance requirement.
- Companies that have already experienced an incident or regulatory contact: After a breach notification or supervisory authority inquiry, a functioning DPO structure needs to be in place quickly and demonstrably.
The ETHYX Model: External DPO Plus Compliance Platform
What makes this different from a standard external DPO service?
Most external DPO providers deliver a person - without a documentation platform, without guided workflows, and without EU AI Act coverage. The result: the legal appointment is in place, but the underlying GDPR documentation remains incomplete. The DPO function exists on paper; the compliance infrastructure does not.
The ETHYX model combines three components at one monthly price:
1. Certified External DPO A qualified, certified Data Protection Officer who takes on the legal function: official regulator contact, incident support, documentation review and sign-off. Not a nominal appointment - a working function.
2. GDPR Compliance Platform Guided workflows for ROPA, Technical and Organisational Measures (TOM), Data Processing Agreements and DPIAs. Pre-structured templates, automatic review triggers, and a continuously updated documentation status - no spreadsheets to maintain manually.
3. EU AI Act Integration AI systems used in the business are inventoried, risk-classified and documented in the same workflow. Deployer obligations under Article 26 of the AI Act are built in, not added as an afterthought.
From €299/month (Expert plan) - replacing what would otherwise be two or three separate service providers.
There is a quieter advantage to having this in place now: enterprise clients and investors increasingly ask for proof of a working privacy setup and a formally appointed DPO before they sign. The companies that can already show it are a step ahead of competitors still assembling theirs.
What the Onboarding Process Looks Like
What happens after I make contact - step by step?
Step 1 - Free assessment call We establish whether a DPO appointment is legally required, which processing activities are in scope, and where the current documentation gaps are. You receive a clear picture of the current state - no sales pressure attached.
Step 2 - Proposal and contract The DPO services agreement sets out the scope, response times, availability, and termination terms. Key provisions that must be in any external DPO contract: confidentiality, the DPO's right to act without instruction from management, access to relevant information and systems, and a handover procedure on termination.
Step 3 - Formal appointment and authority notification The DPO is formally appointed in writing. ETHYX supports you in notifying your DPO to the supervisory authority.
Step 4 - Documentation onboarding A structured review of existing documentation: ROPA, privacy notice, TOMs, DPA agreements. Gaps are identified, prioritised and addressed through the ETHYX platform workflows. → ROPA & GDPR documentation - full guide
Step 5 - Ongoing oversight Quarterly reviews, support for new processing activities, training delivery, incident handling, and continuous platform maintenance. Not a once-a-year check-in - an active ongoing function.
Common Mistakes When Choosing a DPO Provider
What should we watch out for?
- Nominal appointment without substance. A DPO who is formally listed but never reviews documentation, never conducts training and is unreachable during an incident does not fulfil the legal function. The name on a certificate is not compliance.
- No verifiable qualification. A credible external DPO should hold a recognised certification - for example TÜV-certified DPO or an equivalent. Ask for it before signing.
- No SME experience. A data protection consultant who works exclusively with large corporates will apply processes that are disproportionately complex for a 50-person company. Ask specifically for SME client references.
- No EU AI Act competence. The EU AI Act applies in phases - AI literacy obligations are already in force, and deployer obligations for higher-risk systems follow through 2027-2028. Any company using AI tools is building obligations now, so an external DPO without AI Act competence does not cover that part of the risk.
- Unclear response times. A data breach triggers a 72-hour notification window. If your DPO provider takes 48 hours to respond to a message, that is a structural problem - not an edge case.
- No written scope of service. Verbal commitments have no value in a compliance context. Everything material must be in the contract: what is included, what response times apply, what happens on termination.