What does a Data Protection Officer do? Responsibilities, qualifications, and tips for selection

- A Data Protection Officer (DPO) requires expertise in data protection law and practice.
- The requirements for a DPO depend on the size of the company and the risk profile of its data processing activities.
- You can identify a good Data Protection Officer by their voluntary certification (TÜV, DEKRA, IHK).
- Fully qualified lawyers are well-suited for legally complex structures, while IT experts are ideal for technically focused companies.
- An activity report documents the DPO's work and is considered best practice for audit compliance.
Many companies in Germany are required to appoint a data protection officer. The requirements are governed by Article 37 of the General Data Protection Regulation (GDPR) in conjunction with Section 38 of the Federal Data Protection Act (BDSG). But what tasks does a data protection officer perform in your company and what skills do they need for this?
What are the duties of a data protection officer?
Articles 38 and 39 of the GDPR outline the duties of a DPO, which include the following activities, among others.
1. Informing the company
Informing means that the DPO keeps the company updated on its data protection obligations. Professional data protection consulting provides active support in solving specific problems that arise during the implementation of data protection requirements.
➡️ Need professional data protection consulting ? We are happy to help.
2. Monitoring compliance with data protection requirements
The data protection officer monitors compliance with data protection requirements as well as the controller's strategies for protecting personal data within the company. This also includes assigning responsibilities within the company and training employees on data protection topics and to check their level of knowledge.
Important: The practical implementation of data protection regulations is not the responsibility of the DPO themselves, but rather the controller as defined by the GDPR.
3. Advice on Data Protection Impact Assessments (DPIA)
For certain types of data processing, companies must conduct a Data Protection Impact Assessment to provide information about the potential consequences for the protection of personal data that a planned processing activity might have.
In this regard, the Data Protection Officer has a monitoring and advisory role . They specifically oversee the proper execution of the DPIA.
4. Point of contact for supervisory authorities
Sometimes it is necessary for companies to cooperate with supervisory authorities. This involves either responding to inquiries or reporting data breaches. The Data Protection Officer is the primary point of contact for data protection matters and coordinates this cooperation.
5. Point of contact for data subjects
In addition to authorities, data subjects may also have data protection concerns. According to the GDPR, they have the right, for example, to consult the Data Protection Officer regarding any questions related to the processing of their personal data and the exercise of their data subject rights. The DPO is the first point of contact for data subjects.
Other typical tasks of a DPO include the following:
- Monitoring of technical and organizational measures (TOM)
- Verifying that employees are committed to data protection confidentiality
- Reviewing records of processing activities
- Reviewing data processing agreements
- Assisting in the development of a data deletion policy
- Preparing annual activity reports
Regular to-do: What is the data protection officer's activity report?
One of the core tasks of the data protection officer is regular reporting to management in the form of an activity report. It documents the DPO's work over a defined period and provides an overview of the status of data protection within the company.
Benefits: Why is the activity report important?
Data protection officers are not legally requiredcreating a data protection report. However, it is well worth the effort, as both data protection experts and management benefit from the report.
These are the key benefits of the activity report:
- Internal DPOs can use it to account for their activities to management.
- The report can draw the attention of company management to the most important data protection issues within the organization.
- A data protection activity report is an effective tool for promoting compliance with data protection legislation and continuously raising awarenessof data protection among company management.
- The company can use the report to demonstrate to supervisory authorities that data protection activities and measures are being implemented within the company.
- The activity report can motivatethose responsible to comply with data protection requirements.
- An annual report helps company executives and data protection officers meetthe significantly increased accountability and monitoring obligations for data protection compliance.
How often do reports need to be submitted?
Best practice is an annual activity report to the management or the board of directors. In the event of special incidents, such as serious data breaches, ad-hoc reporting should also be provided.
Particularly in group structures with multiple companies, a standardized activity report enables consistent documentation and efficient reporting across all business units.
Expertise: What skills does a DPO need to fulfill their duties?
For a Data Protection Officer to perform their duties efficiently and correctly, expertise is required. According to Article 37(5) of the GDPR, in addition to professional qualifications they also need specialized knowledge in data protection law and practice, as well as specific skills and expertise.
Professional qualifications: How do you become a Data Protection Officer?
In-house Data Protection Officers pursue further training in data protection based on their primary profession, for example through professional development programs from institutions such as TÜV or IHK. Seriöse Ausbildungslehrgänge für Datenschutzbeauftragte haben fachlich hohe Anforderungen und enden regelmäßig mit einer Zertifizierung als Nachweis für die Fachkunde.
Der Inhalt einer datenschutzrechtlichen Weiterbildung umfasst idealerweise
- den gesamten Bereich der datenschutzrechtlichen Vorschriften
- eine Einführung in technische Strukturen vornehmlich im IT-Bereich und
- eine Einführung in organisatorische Standardprozeduren.
Insgesamt muss der Datenschutzbeauftragte in die Lage versetzt werden, die entsprechenden Aufgaben und Anforderungen im Unternehmen übernehmen zu können.
Welches Fachwissen brauchen Datenschutzbeauftragte?
Für die Erfüllung seiner Aufgaben braucht ein Datenschutzbeauftragter umfassendes Fachwissen. Er muss nicht nur die DSGVO und das BDSG-neu kennen, sondern sollte auch fortlaufend über die gesetzlichen Bestimmungen und etwaige Änderungen informiert sein.
Wichtig sind darüber hinaus Kenntnisse über bereichsspezifische Spezialnormen sowie Vereinbarungen mit den Arbeitnehmervertretungen sowie tiefgehende juristische und betriebliche Kenntnisse.
Umfassende IT-Kenntnisse helfen dem Datenschutzbeauftragten, die fachgerechte Verwendung verschiedener Datenverarbeitungsprogramme sicherzustellen. Je besser er die technischen Vorgänge der Datenverarbeitung versteht, desto genauer kann er beurteilen, ob diese den datenschutzrechtlichen Vorgaben genügen.
Fähigkeit zur Erfüllung der Aufgaben
Neben der beruflichen Qualifikation und Fachwissen auf seinem Gebiet muss ein DSB die Fähigkeit zur Erfüllung seiner Aufgaben mitbringen. Hierbei sind drei Punkte besonders wichtig:
- Persönliche Eigenschaften wie soziale Kompetenz, Integrität, Verschwiegenheit und Kommunikationsfähigkeit sind unverzichtbar, um die Informations- und Beratungsaufgaben sowie die Funktion als Ansprechpartner für die Unternehmen wahrzunehmen.
- Entscheidend ist außerdem, dass der Beauftragte seine Pflichten in vollständiger Unabhängigkeit ausüben kann und im Hinblick auf seine Aufgaben nicht in Interessenkonflikte gerät. Dies ist etwa der Fall, wenn dem Datenschutzbeauftragten auch andere Tätigkeiten anvertraut sind, oder er sich selbst kontrollieren müsste.
- Schließlich muss der Beauftragte in der Lage sein, gegenüber der Geschäftsleitung seine Stellung zu wahren und im Zweifel durchzusetzen, insbesondere im Falle von Meinungsverschiedenheiten hinsichtlich der datenschutzrechtlichen Anforderungen an die jeweiligen Verarbeitungsvorgänge.
Nach welchen Kriterien sollten Unternehmen ihren Datenschutzbeauftragten auswählen?
Ausschlaggebend sollten die Erfahrung und die fachliche Eignung des Datenschutzspezialisten sein. Daneben sind Zuverlässigkeit und Durchsetzungsvermögen gefragt. Gerade bei der internen Besetzung der DSB-Position spielt das Thema Interessenskonflikt eine wichtige Rolle: Arbeitet ein Mitarbeiter ständig mit personenbezogenen Daten, so kommt er für die Stelle als interner DSB nicht infrage.
Die notwendige Qualifikation Ihres zukünftigen DSBs sollte sich an der Größe Ihrer Organisation sowie dem Risikoprofil der Datenverarbeitungen orientieren. Je schutzwürdiger die Daten oder je intensiver die Verarbeitungen, desto höher sind die fachlichen Anforderungen. Externe Datenschutzbeauftragte sind hier meist im Vorteil, da sie sich im Alltag hauptsächlich mit Datenschutz befassen und wertvolle Praxis- und Branchenerfahrung mitbringen.
Volljurist oder IT-Experte? Welcher Hintergrund passt zu Ihrem Unternehmen?
Datenschutz in Unternehmen hat viele juristische Elemente. Deshalb bekleiden viele Volljuristen die Position des DSB, nachdem sie sich zusätzliche datenschutzrechtliche Kenntnisse angeeignet haben. Doch Datenschutz in Unternehmen besteht nicht nur aus juristischen Herausforderungen, sondern ist oft mit technischen und organisatorischen Fragen verbunden.
Maßgebend für die Frage, ob Volljuristen oder IT-Experten die bessere Wahl sind, sind deshalb die unternehmensspezifischen Bedürfnisse:
- In Verbundstrukturen ist ein Volljurist als DSB in der Lage, den Überblick über die gesellschaftsrechtliche Komplexität zu behalten.
- Dagegen kann ein DSB mit IT-Expertise vor allem in mittelständischen Unternehmen punkten, die ihre IT-Strukturen und die Verarbeitung von Daten mit verschiedenen digitalen Tools datenschutzrechtlich sauber gestalten möchten.

Checkliste: So wählen Sie den richtigen DSB für Ihre Unternehmensstruktur
Unternehmen sollten sehr genau darauf achten, ob ihr künftiger DSB alle fachlichen und persönlichen Fähigkeiten mitbringt, die für die Stelle notwendig sind. Denn nur so ist sichergestellt, dass Sie die DSGVO sicher einhalten können und das Risiko von Datenschutzverstößen so gering wie möglich bleibt. Letztendlich geht es darum, die Haftungsrisiken für Ihr Unternehmen zu reduzieren.
Die folgende Checkliste bietet Orientierung für die Auswahl eines DSB und fasst die wichtigsten Punkte dieses Artikels zusammen:
Für größere Organisationen ist außerdem relevant, ob der DSB
- Erfahrung mit Konzernstrukturen und mehreren Gesellschaften hat
- standardisierte Reporting-Vorlagen nutzt, etwa für den Tätigkeitsbericht
- über Kenntnisse im Gesellschaftsrecht verfügt
➡️ Im Blog finden Sie eine Entscheidungshilfe für die Frage interner oder externer Datenschutzbeauftragter.
Nächste Schritte: So finden Sie Ihren DSB
Sie wollen prüfen, ob Ihr interner Kandidat qualifiziert ist oder ein externer DSB besser zu Ihrer Unternehmensstruktur passt? Wir beraten Sie gern dazu.
Still have questions? We have the answers.
A DPO informs companies about data protection obligations, monitors GDPR compliance, and advises on data protection impact assessments (DPIAs). They serve as the point of contact for supervisory authorities and data subjects, and review technical and organizational measures, data processing agreements, and records of processing activities. The practical implementation remains the responsibility of the data controller, not the DPO. You can find external Data Protection Officers for your data protection needs at Proliance.
Article 37(5) GDPR requires a DPO to possess expert knowledge of data protection law and practice. This includes comprehensive knowledge of the GDPR and the new BDSG, as well as sector-specific special regulations and IT expertise. The specific requirements depend on the size of the company and the risk profile of the data processing. Personal qualities such as integrity, confidentiality, and communication skills are indispensable – and these are precisely what Proliance's experts provide.
The best choice depends on your company's structure. Legal professionals are ideal for legally complex group structures involving multiple entities, as they can navigate intricate corporate law. IT experts excel in mid-sized companies with extensive digital data processing and complex IT infrastructures. Proliance offers TÜV-/DEKRA-certified experts with a legal background and industry experience in data protection and information security.
Key factors are experience, professional competence, reliability, and assertiveness. Additionally, check their academic background, certifications, professional experience, and industry references. For an internal DPO, it is important that no conflicts of interest exist. For an external DPO, availability should be clearly defined. With Proliance, you get a dedicated contact person who is available Monday to Friday from 9:00 AM to 6:00 PM.
An activity report documents the DPO's work over a defined period and provides an overview of the company's data protection status. Annual reporting to management is considered best practice. Benefits include: demonstrating accountability to management, raising awareness of data protection issues, providing audit evidence for supervisory authorities, and fulfilling enhanced accountability obligations. While not legally mandatory, it is considered best practice. Proliance 360 automatically documents the activity report with an export function.
Reputable DPO certifications, such as those from TÜV or DEKRA, demonstrate expertise as per Article 37(5) GDPR. Training courses should cover data protection regulations, technical IT structures, and standard organizational procedures. Important: Your DPO should undergo regular training, as data protection requirements are constantly changing. Proliance exclusively employs TÜV and DEKRA-certified experts.
Do you have further questions on this topic? Our experts will be happy to advise you free of charge.













