Protection against dismissal for data protection officers

Last updated:
23.02.2026
Internal data protection officers benefit from special protection against dismissal, which presents many employers with legal challenges. This article explains when termination is possible, how it differs from removal from office, and what alternatives are available.
Protection against dismissal for data protection officers
Key Takeaways
  • Internal data protection officers are entitled to special protection against dismissal, which was confirmed by the ECJ in 2022.
  • The dismissal of a data protection officer is only permitted if there is a valid reason.
  • This protection against dismissal remains in effect for up to one year after the internal DPO role has ended.
  • Removing an individual from the position is also subject to specific requirements and requires a valid reason.
  • Different rules apply to external data protection officers, which is why appointing one can minimize employment law risks.

Why do data protection officers have special protection against dismissal?

The role of the data protection officer is of fundamental importance to every company. They are responsible for protecting personal data and implementing GDPR requirements to shield their employer from costly fines in the event of violations.

Companies are free to decide whether to assign these tasks to an internal or external data protection officer. An internally appointed company data protection officer is also an employee of the company.  

To ensure they can perform their work independently and neutrally, they are afforded special protection against dismissal or removal from their role, both in their capacity as a DPO and as an employee. If companies could dismiss a DPO at any time without a valid reason, their independence would no longer be guaranteed.

ECJ ruling: Protection against dismissal is compliant with EU law

In June 2022, the European Court of Justice (ECJ) reinforced the protection against dismissal for internal data protection officers. An employee tasked with data protection had filed a lawsuit against her dismissal, which her employer had justified by citing company restructuring. She was successful at all levels of the court.

The ECJ clarified that the German regulation regarding the special protection against dismissal for an internal data protection officer does not conflict with the GDPR and is therefore compliant with EU law. For employers, this means that dismissing a data protection officer is significantly more complex than for other employees.  

What is the difference between removal from a role and dismissal?

When companies face the decision of whether their data protection officer can continue to fulfill their duties, the terms removal and dismissal often arise. These are two distinct legal processes.

| Removal | Termination | | :--- | :--- | | Ends the role as Data Protection Officer | Ends the entire employment relationship | | The employment relationship continues | Subject to stricter requirements than a removal | | The employee can continue working in their original position | Ordinary termination is excluded for mandatorily appointed DPOs |

What legal foundations apply to the protection of DPOs against dismissal?

The protection against dismissal and removal for data protection officers is based on several concurrent laws:

  • General Data Protection Regulation (GDPR): According to Art. 38 (3) GDPR, a data protection officer may not be dismissed or penalized by the controller for performing their tasks.
  • Federal Data Protection Act (BDSG): Section 6 (4) of the BDSG prohibits public bodies, such as authorities, from removing a DPO unless there are facts that justify extraordinary termination. Section 38 (2) of the BDSG clarifies that this regulation also applies to non-public bodies, such as companies.
  • German Civil Code (BGB): Section 626 of the BGB defines extraordinary termination for good cause. This applies when the continuation of the employment relationship is no longer reasonable.

When is the removal or dismissal of a data protection officer permissible?

Whether a removal or dismissal is permissible depends first on whether the data protection officer was appointed based on a legal obligation or voluntarily. According to Section 38 (2) sentence 2 of the BDSG, a voluntarily appointed data protection officer can be removed from their function at any time. The protection against dismissal for the employment relationship remains in effect.

If the DPO was appointed due to a legal obligation, there must be a good cause under Section 626 of the BGB for both removal and dismissal. The following table shows what these reasons might be.

| Reason | Practical example | | :--- | :--- | | Lack of expertise | The DPO no longer has (or never had) the required qualification | | Conflict of interest | The DPO simultaneously serves as managing director, board member, or IT manager | | Serious intentional breach of duty | Betrayal of trade or business secrets | | Irrecoverable loss of trust | The relationship of trust between employer and DPO has been permanently destroyed | | Complete closure of the business | The business ceases operations entirely; Important: according to the CJEU, a corporate restructuring or organizational changes generally do not constitute grounds for dismissal |

Even if there is a valid reason for termination, employers must first consider less severe measures, such as removal from the position. Termination is generally only an option if the employment relationship itself can no longer be continued.

Breakdown of the admissibility of removing a Data Protection Officer

Special case: Removal at the request of the supervisory authority

Under Section 40 (6) sentence 2 of the German Federal Data Protection Act (BDSG), the data protection supervisory authority may also demand the removal of a DPO if they fail to perform their duties properly. In practice, however, this time-consuming procedure is rarely used.

A pitfall for employers: Post-termination protection

One aspect that employers often overlook regarding the protection against dismissal for their Data Protection Officer is that this protection continues for one year after the DPO role ends. During this year, the former DPO cannot be dismissed through ordinary termination. Extraordinary termination is only possible for a compelling reason. This applies regardless of whether the DPO role ended through removal or by other means.

Please note: In the event of a business transfer, the post-termination protection expires with respect to both the transferee and the transferor.

What applies to fixed-term employment contracts or DPO appointments?

If an internal Data Protection Officer has a fixed-term employment contract, both the DPO role and the protection against dismissal end when the employment contract expires.  

It is also possible to limit only the appointment as Data Protection Officer to a specific period. The employment relationship remains unaffected by this. However, employers should ensure that the duration of the fixed term is reasonable: a period that is too short could negatively impact the DPO's independence and the continuity of data protection efforts.

What protection against dismissal applies to external Data Protection Officers?

The strict dismissal protection regulations for Data Protection Officers pose challenges for many companies. A sensible alternative is to appoint an external Data Protection Officer.

Advantages of an external DPO:

✅ Protection against dismissal: Does not apply, allowing for flexible contract terms

✅ Neutrality: No conflicts of interest arising from internal positions

✅ Expertise: Specialized experts with up-to-date know-how

✅ Effort: No need to arrange for holiday cover or professional development

✅ Predictability: Transparent contract terms instead of long-term personnel commitments

An external data protection officer provides not only legal flexibility but also the necessary expertise and independence – without the labor law complexities of an internal DPO.

Conclusion: Creating legal certainty for employers

A data protection officer is an indispensable asset for corporate compliance. The extensive legal requirements of the GDPR alone make this clear. The special protection against dismissal is certainly sensible: it guarantees that the DPO can act independently without having to fear consequences.

However, for companies that want to maintain flexibility, an external DPO is often the better choice. This allows you to avoid labor law pitfalls and switch providers easily if needed.

Proliance's external data protection officers support you with:

  • Industry-specific expertise tailored to small and medium-sized enterprises
  • Modern compliance tools that automate processes
  • Up-to-date expertise to ensure your data protection remains legally compliant
  • Maximum flexibility without the hurdles of special protection against dismissal
Frequently Asked Questions

Still have questions? We have the answers.

When is the termination of an internal data protection officer permissible?

The termination of a mandatory internal data protection officer is only permissible for just cause, as defined by Section 626 of the German Civil Code (BGB). Valid reasons include a lack of professional expertise, serious breaches of duty, conflicts of interest, or an irretrievable loss of trust. Ordinary termination is not allowed. According to the ECJ, restructurings alone are not sufficient grounds for termination. Proliance offers external data protection officers, eliminating the employment law hurdles associated with terminating internal staff.

What is the difference between the revocation of a Data Protection Officer's appointment and the termination of their employment?

Revocation only terminates the DPO function; the employment relationship remains intact. The employee continues to work in their original position. Termination of employment, however, ends the entire employment relationship and is subject to stricter requirements. For legally mandated DPOs, ordinary termination is not possible. Proliance avoids this complexity by providing flexible external Data Protection Officers.

How long does protection against dismissal apply to Data Protection Officers after their DPO role ends?

Protection against dismissal extends for one year after the DPO's term of office ends. During this year, ordinary termination is not possible; only extraordinary termination for good cause. This applies regardless of how the DPO's function concluded. External data protection officers from Proliance offer maximum flexibility without post-termination protection against dismissal.

Do you have further questions on this topic? Our experts will be happy to advise you free of charge.

If you're looking for a partner to support you on your journey to data protection and information security, feel free to contact our team of experienced experts.
60+ Expertinnen und Experten
Book a consultation
Topics
Editorial
Sabrina Schaub
Freelance Editor
Leveraging her content expertise, Sabrina supports the Proliance team in communicating complex topics clearly. As a freelance writer, she understands the data privacy requirements across different sectors and translates even complex information into content tailored to specific target audiences.
Zum Autorenprofil
Zum Expertenprofil
About Proliance
Proliance stands for Professional Compliance for businesses. We are a digitally driven Legal Tech company based in Munich, established in 2017 and now with over 90 privacy enthusiasts. Our more than 2,500 clients include start-ups, medium-sized businesses, and corporate groups from almost all industries.
About us
Latest Articles

Topics you might be interested in