Key Takeaways
Headcount isn't the only trigger: Article 37 GDPR and § 38(1) sentence 2 BDSG make a DPO mandatory at any size for large-scale monitoring, special-category data, or DPIA-level processing.
Your CEO, IT lead and HR head are disqualified: Article 38(6) GDPR bars anyone who decides how personal data is processed — most SMBs go external for €150–350 a month.
Skipping it costs up to €10 million or 2% of turnover: failure to appoint a required DPO is a fineable offence under Article 83(4) GDPR.
The basics matter more than the title: records of processing, access control, device encryption and clean offboarding are what clients actually check, and deeploi automates that layer.
Most founders and office managers don't wake up thinking about data protection officers. The question usually lands on your desk because a client sent a security questionnaire, or your lawyer mentioned it in passing, or you just hired your twentieth employee and someone on LinkedIn said that number matters. It does, but the details are more nuanced than most summaries suggest.
Two legal frameworks determine whether your company must appoint a DPO: GDPR Article 37 at the European level, and the stricter German BDSG §38 for companies operating in Germany. Both are worth understanding, even if you only fall under one. And a heads-up: §38(1) BDSG is under active legislative discussion, so the threshold described below may shift in 2026. The underlying obligations, however, will not.
When is a Data Protection Officer legally required?
Under GDPR Article 37, a DPO is mandatory in three situations:
If your organization is a public authority.
If your core activities involve regular and systematic monitoring of individuals on a large scale (think adtech, location tracking, or behavioural profiling).
If your core activities involve large-scale processing of special-category data such as health records, biometric data, or information about religious beliefs. The key word is "core activities." If data processing supports but isn't central to your business model, the GDPR trigger alone may not apply.
German law goes further. Under §38(1) BDSG, you must appoint a DPO if at least 20 persons are constantly engaged in automated processing of personal data. "Persons" here is broader than your headcount: working students, interns, part-timers, and freelancers working under your instruction all count. And "automated processing" includes anyone who uses email, a CRM, an HR tool, or a shared spreadsheet with personal data. In practice, most companies with 20 people on the payroll are well over the line, not teetering on its edge. The count applies per legal entity, and there is no grace period once you cross it.
To self-assess, answer this: do you have 20 or more people (broadly defined) working with personal data in digital tools? If yes, you need a DPO under German law. If no, check whether your core business involves large-scale monitoring or special-category data. If it does, GDPR Article 37 applies regardless of size. For companies managing GDPR IT compliance without a dedicated team, this is the first box to tick.
Also check § 38(1) sentence 2 BDSG: a DPO is mandatory regardless of headcount if your processing requires a DPIA under Article 35, or if you process personal data commercially for transfer, anonymized transfer, or market and opinion research.
Internal vs. external DPO: which option fits an SMB?
An internal DPO is an existing employee who takes on the role alongside (or instead of) their other duties. The upside is that they already know your systems and culture. The downside is cost, training, and a strict independence requirement that trips up many small companies.
Under Article 38(6) GDPR, a DPO may not hold any position that leads them to determine the purposes and means of data processing. In practice, this disqualifies the managing director, the Head of HR, and the Head of IT, because all three routinely make decisions about how and why personal data is processed. The European Court of Justice confirmed this principle in its 2023 ruling in C-453/21 (X-FAB). A junior IT employee without decision-making authority is not automatically excluded, but appointing someone so close to operational IT decisions is rarely advisable.
An external DPO, typically a specialized consultant or law firm, avoids the conflict-of-interest problem entirely. External appointments also tend to bring broader expertise across industries and regulatory updates. For SMBs, external DPOs typically cost between €150 and €350 per month at 20-50 employees, and €350 to €800 at 50-250, depending on complexity – usually well below the cost of training and partially freeing up an internal hire. Companies navigating questions around EU data residency and GDPR will find an external DPO especially helpful for vendor due diligence.
What does a DPO actually do, and what happens without one?
Day to day, a DPO monitors your organization's compliance with data protection law, advises on Data Protection Impact Assessments (DPIAs), trains staff who handle personal data, and serves as the point of contact for your supervisory authority. They review processing activities, flag risks, and help answer data subject requests within the legally required timeframe.
Critically, the DPO is not personally liable for your company's compliance failures. Responsibility stays with the controller, meaning the company itself and its management. Under Article 38(3) and Article 39 GDPR, the DPO advises and monitors but does not bear the legal consequences of decisions made by leadership.
Those consequences are real. Failing to appoint a required DPO falls under Article 83(4) GDPR, which allows fines of up to €10 million or 2% of global annual turnover, whichever is higher. This is explicitly the lower tier; it is not the €20 million / 4% ceiling that applies to unlawful processing. Beyond fines, German managing directors face personal liability under §43 GmbHG and §130 OWiG if they fail to establish proper organizational safeguards. And then there's the deal-cycle damage: a missing DPO or incomplete records of processing can stall a partnership, a funding round, or an enterprise sales contract. Companies already thinking about NIS2 compliance requirements will recognize this pattern.
What every SMB should have in place, with or without a DPO
Whether or not you're legally required to appoint a DPO, the GDPR's operational obligations still apply to every company that processes personal data. Here's what should be in place:
Records of processing activities (Art. 30 GDPR): document what personal data you collect, why, where it's stored, who has access, and when it's deleted.
Technical and organizational measures (TOMs): encryption, access controls, secure configurations, and backup procedures, documented and reviewable.
Access management: role-based permissions so employees only reach the data they actually need. Review these quarterly.
Device management: enforce disk encryption, OS updates, and endpoint protection across every laptop and phone that touches company data. Centralised cybersecurity for business devices makes this manageable at scale.
Offboarding hygiene: revoke accounts, recover devices, and wipe data on the day someone leaves, not weeks later. A delayed offboarding is one of the most common sources of data incidents in SMBs.
Employee awareness: brief your team on phishing, password hygiene, and how to handle data subject requests. One annual session is a start; regular reminders are better.
These aren't theoretical requirements. They're the controls that auditors, clients, and supervisory authorities actually look for. Platforms like deeploi help SMBs automate the IT layer underneath these obligations, from device encryption enforcement to IT security and compliance policies, so the people responsible for compliance don't have to become IT experts. If your team uses AI tools like ChatGPT on company devices, device-level controls become even more important.
Conclusion
The DPO question is really a data protection maturity question. If you've got the operational basics right (documented processing, access controls, device security, clean offboarding), deciding whether to appoint an internal or external DPO becomes a straightforward next step rather than a panic move. Even if §38(1) BDSG is reformed and the threshold changes, the checklist above holds either way, because the GDPR obligations underneath it aren't going anywhere. Get the foundations in place first, then make the appointment with confidence.
FAQ
Can a small company below the BDSG threshold ignore data protection entirely?
Absolutely not. All GDPR obligations apply regardless of company size. The DPO is just one piece. More importantly, §38(1) sentence 2 BDSG requires a DPO regardless of headcount when processing triggers a mandatory DPIA under Article 35, or when personal data is processed commercially for transfer, anonymized transfer, or market and opinion research. Concrete examples: video surveillance of public areas, tracking-heavy marketing, processing health data, or using HR analytics tools that profile employee behavior.
Who in our team is allowed to be the DPO?
Anyone who can act independently and doesn't determine the purposes or means of data processing. This rules out the CEO, managing director, Head of IT, and Head of HR in most SMBs. A compliance-oriented employee without operational data-processing authority could qualify, but they'll need training and protected time. For most small companies, an external appointment is simpler and safer.
How do I spot security gaps in our IT before someone else does?
Supervisory authorities rarely audit SMBs proactively. What actually surfaces gaps is an ex-employee complaint, a data subject request you can't answer in time, a breach you have to report within 72 hours, or a client's security questionnaire mid-deal. To stay ahead, run regular access reviews, keep an up-to-date asset inventory, and use automated device monitoring to catch unpatched systems or missing encryption. The deeploi platform gives growing teams a single view of device health, access status, and security posture without requiring a dedicated IT department.
This article is for general information only and does not constitute legal advice. Data protection obligations depend on the specifics of your organization and its processing activities, and the legal position described here reflects the status as of August 2026. For a binding assessment of your situation, please consult a qualified lawyer or data protection officer.
_%2520Does%2520Your%2520SMB%2520Need%2520One_%2520(1).png)









