Data Protection

External Data Protection Officer

 

 

What is an external data protection officer?

The data protection officer is the central point of contact for all data protection matters within a company. The main responsibilities of the data protection officer include Monitoring compliance with applicable data protection regulations, such as in particular the GDPR and the BDSG, and on the other hand with the Consultation from decision-makers, works councils, and employees. Another part of its activities involves Collaboration with regulatory authorities The data protection officer is their primary point of contact within the company.

The data protection officer holds a special position within the company. In the performance of his duties, he is not subject to instructions from management and always reports directly to the highest management level. The controller is obligated to support the data protection officer in his activities by providing him with the necessary resources, information, and authority. The data protection officer may not be dismissed or otherwise disadvantaged as a result of performing his duties.

 

Do I absolutely need an external data protection officer?

Appointing a data protection officer is mandatory according to the GDPR and the BDSG if, in your company, at least 20 employees regularly engaged in the automated processing of personal data are. The requirements for this are low. Thus, they do not necessarily have to be permanent employees. Also, the processing of personal data does not have to be the main task. Even regular access to emails or databases is sufficient.

Regardless of the number of employees, a data protection officer must be appointed, provided that

  • the Core activity Your company's processing of personal data, which is extensiveregular and systematic monitoring of affected persons to make necessary;
  • the Core activity ...your company in processing special categories of data, such as health data, or data on criminal convictions;
  • you carry out processing operations that pose a particularly high risk to data subjects and therefore require prior Data protection impact assessment require according to Art. 35 GDPR.
  • You data business-like for transmission or for purposes of Market or public opinion research

 

What happens if I do not appoint a data protection officer?

If you are required to appoint a data protection officer under the criteria set forth above, the mere failure to do so constitutes an administrative offense. This may result in a fine of €10 million or 2% of your company’s global turnover from the previous year—whichever amount is higher. higher fails – is penalized.

If you are not required to appoint a data protection officer, there are no direct negative consequences for you or your company if you do not do so. However, you should be aware that the extensive regulations and obligations under the GDPR and the BDSG still apply to your company in all other respects. An external data protection officer is a great help in complying with data protection laws and can play a significant role in preventing data breaches and fines. The GDPR provides for fines of up to €20 million or 4% of global annual turnover for certain violations. Here, too, the higher amount applies. Therefore, voluntarily appointing a data protection officer can be beneficial for your company. Such a voluntarily appointed data protection officer may also be dismissed at any time.

 

Who can I appoint as an external data protection officer?

The Data Protection Officer must be selected based on their professional qualifications, expertise in data protection law and practice, and their ability to perform the legally regulated monitoring and advisory tasks. The specific requirements for professional competence will depend on the scope and the need for protection of the data processed by your company. Furthermore, you are free to choose the person who will serve as the Data Protection Officer. You may decide to appoint one of your employees as the internal Data Protection Officer. This could be an employee who works exclusively as a Data Protection Officer, or you can relieve an employee of a portion of their working hours to serve as a Data Protection Officer. However, it is important that this person does not simultaneously perform tasks that lead to a conflict of interest with their role as Data Protection Officer. For example, the head of the marketing or IT department may not simultaneously perform the duties of the Data Protection Officer. Alternatively, you also have the option to appoint an external Data Protection Officer. This could be an individual or even a specialized firm. Which solution is best suited for you will depend on the specific circumstances and needs of your company.

 

Internal or external data protection officer?

The biggest advantage of appointing an internal data protection officer is that the employee in question is already familiar with your company and its workflows, and does not need to familiarize themselves with your way of working and activities. However, this also entails obligations for management that can be costly. For example, it must be ensured that the data protection officer is adequately trained. Their knowledge of data protection law must be kept up-to-date through regular training. Furthermore, the company must provide the internal data protection officer with all resources and work materials, particularly professional literature, that they need to perform their duties.

Another point that should not be overlooked when appointing an internal data protection officer is that the employee gains special protection against dismissal. Should there be professional or personal problems with the internal data protection officer, it can therefore become difficult to dismiss them.

Finally, when appointing an internal data protection officer, the question of liability for consulting errors must also be considered. Since this is an employee of your company, the basic principles of internal damage compensation generally apply. Accordingly, in most cases, your company cannot seek recourse against the internal data protection officer should data protection violations occur due to deficient services, leading to claims.

External data protection officers, on the other hand, work for companies under a service contract. They are responsible for maintaining their current level of knowledge themselves and already have all necessary work materials available. Due to their specialized expertise and practical experience from working for a wide variety of companies, an external data protection officer guarantees the highest level of expertise and the greatest possible protection for your company. This experience allows routine tasks to be carried out based on predictable and manageable cost flat rates for you. Furthermore, they can be replaced with little effort and are comprehensively liable within the scope of the contractual relationship. In addition, an external data protection officer always provides a contact person for particularly complex and extensive cases. Lastly, no valuable employee time is tied up by activities as a data protection officer.

 

What we can do for you

At Kolb, Blickhan & Partner (KBP), we provide a team of lawyers with extensive expertise in data protection law and are among the largest law firms specializing in data protection in the Rhine-Neckar metropolitan region. In the course of our more than ten years of activity in the industry, we have built up an extensive network of partner firms that can also contribute the necessary technical know-how for the implementation of data protection projects. This allows us to carry out data protection projects of any size.

 

We are also happy to advise you on the topic of „Data Protection Officer“.“

  • We review whether you need a data protection officer and what requirements the data processing activities in your company place on the qualifications of such an officer.
  • We provide training for your internal Data Protection Officer.
  • We advise your internal data protection officer on individual questions or when dealing with supervisory authorities.
  • We are happy to carry out projects in cooperation with your internal data protection officer.
  • We check work results for data protection compliance.

 

Kolbcom and KBP – a perfect match

With our partner company, Kolbcom GmbH, we have a trustworthy partner at hand who not only provides simple, innovative, and cost-effective solutions in the area of GDPR compliance, but also, if you wish, also acts as external data protection officer for your company. This means you not only have a data protection officer, but a team of IT specialists and lawyers dedicated to ensuring data protection compliance within your company.

 

A concept that fits your business

Regardless of your company size and budget, we will find the solution approach that suits you together.

From the „Data Protection Package,“ the cost-effective standard solution from Kolbcom GmbH, which enables you to manage data protection within your company yourself by providing all relevant samples, templates, and tables with the help of easy-to-understand explanation videos, to comprehensive and individual consulting for your company and the provision of a Data Protection Officer, to negotiating works agreements with your Works Council, and conducting formal proceedings to defend or enforce legal claims by our lawyers – we are here for you!

Here you go Data Protection Package

 

 
Get in touch