Although the General Data Protection Regulation (GDPR) came into force in 2018, many companies are unsure whether their data protection measures meet the current legal requirements. One aspect of the GDPR's package of obligations is the appointment of a data protection officer. This article will examine when a company is generally obliged to appoint a data protection officer and what consequences may arise if the person fails to do so.
Which companies usually have to appoint a data protection officer?
According to Article 37 of the GDPR, a data protection officer must be appointed if the core activities of a company consist of processing operations which, due to their nature, scope, and/or purposes, require large-scale, regular, and systematic monitoring of data subjects, or if the core activities of the company consist of large-scale processing of special categories of data pursuant to Article 9 (personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, as well as the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a natural person's sex life or sexual orientation) or personal data relating to criminal convictions and offences pursuant to Article 10. This means that, in particular, companies whose core activities lie in the scoring, headhunting, profiling, market or opinion research, security, and surveillance sectors fall under this category. Social media companies and insurance companies can also be included. Data as defined in Article 9 of the GDPR is primarily processed by medical practices, hospitals, and laboratories. According to Section 38 of the German Federal Data Protection Act (BDSG), non-public bodies must appoint a data protection officer if, as a rule, at least 20 people within the company are regularly engaged in the automated processing of personal data. "Automated processing" refers to any IT-supported data processing. This includes computers, network systems, video surveillance systems, tablets, smartphones, etc. "Regularly" and "regularly" mean that this must be a permanent activity, not just a short-term or temporary one, thus constituting the "normal" professional situation. This typically includes administrative staff, sales representatives, IT personnel, and employees in the human resources and finance departments. Mere access to stored data for the purpose of use is sufficient. It should be noted that the law also stipulates an obligation to appoint a data protection officer under further, more specific conditions, but these would go beyond the scope of this initial overview.
According to Article 37, Paragraph 7 of the GDPR, the contact details of the data protection officer must be published and communicated to the supervisory authority.
What are the consequences if no registration is made in violation of the obligation?
According to Article 83(4) GDPR, infringements of the appointment of a data protection officer may be subject to fines of up to EUR 10.000.000 or, in the case of an undertaking, up to 2% of its total worldwide annual turnover of the preceding financial year, whichever is higher.
The above information is intended only as initial information and to provide an overview of the topic. Depending on the individual case, the obligations and rights may change significantly. If you have any questions or need advice, please feel free to contact us.
Marc Conrad
Lawyer
E-Mail: Conrad@kmbpartner.de
0621 4250890