When must a company appoint a data protection officer?
Private bodies must appoint a data protection officer where they permanently employ at least twenty persons on the automated processing of personal data. The duty also applies where a data protection impact assessment is required under the Regulation or where data are processed commercially for transfer.
Source
- Source
- Federal Data Protection Act, section 38
- Acts
- Federal Data Protection Act
- Area
- Personal data
- Checked
- 2026-09-21
Questions
Ready-made pack
GDPR incident pack
total 98.75 € (about 107 USD)
The basis for what you just read, ready for the file.
What you need once a personal data breach has happened: the notification articles, the risk profile and a ready evidence chain.
Evidence chain, hash and read date per row. One-time purchase, delivered instantly.
Next step
Three ways to put the register to work in your own practice.
Start with your task
Litigation
Find support in a judgment
Search guiding decisions, see what became final and follow changes in the law.
In-house, deals
Map the rules in a transaction
Move from theme to act and on to the article that carries the duty.
Compliance
Assess the risk in a process
Risk scoring per legal area, with the sources behind every score.