Article 38 GDPR

From GDPRhub
Article 38 - Position of the data protection officer
Chapter 10: Delegated and implementing acts

Legal Text


Article 38 - Position of the data protection officer

1. The controller and the processor shall ensure that the data protection officer is involved, properly and in a timely manner, in all issues which relate to the protection of personal data.

2. The controller and processor shall support the data protection officer in performing the tasks referred to in Article 39 by providing resources necessary to carry out those tasks and access to personal data and processing operations, and to maintain his or her expert knowledge.

3. The controller and processor shall ensure that the data protection officer does not receive any instructions regarding the exercise of those tasks. He or she shall not be dismissed or penalised by the controller or the processor for performing his tasks. The data protection officer shall directly report to the highest management level of the controller or the processor.

4. Data subjects may contact the data protection officer with regard to all issues related to processing of their personal data and to the exercise of their rights under this Regulation.

5. The data protection officer shall be bound by secrecy or confidentiality concerning the performance of his or her tasks, in accordance with Union or Member State law.

6. The data protection officer may fulfil other tasks and duties. The controller or processor shall ensure that any such tasks and duties do not result in a conflict of interests.

Relevant Recitals

Recital 97: Data Protection Officer
Where the processing is carried out by a public authority, except for courts or independent judicial authorities when acting in their judicial capacity, where, in the private sector, processing is carried out by a controller whose core activities consist of processing operations that require regular and systematic monitoring of the data subjects on a large scale, or where the core activities of the controller or the processor consist of processing on a large scale of special categories of personal data and data relating to criminal convictions and offences, a person with expert knowledge of data protection law and practices should assist the controller or processor to monitor internal compliance with this Regulation. In the private sector, the core activities of a controller relate to its primary activities and do not relate to the processing of personal data as ancillary activities. The necessary level of expert knowledge should be determined in particular according to the data processing operations carried out and the protection required for the personal data processed by the controller or the processor. Such data protection officers, whether or not they are an employee of the controller, should be in a position to perform their duties and tasks in an independent manner.

Commentary

Article 38 GDPR sets out the position of the data protection officer (DPO) within an organisation. This provision is therefore closely connected to the other provisions governing the role of the DPO, i.e., Article 37 GDPR (designation of the data protection officer) and Article 39 GDPR (tasks of the data protection officer). In particular, Article 38 GDPR outlines that the position of the DPO has to be structured in an organisation in order to be able to fulfil its role. The requirements set out in this provision apply to mandatory DPOs (Article 37(1) GDPR) as well as to DPOs appointed voluntarily by a controller or processor (Article 37(4) GDPR).[1]

Article 38(1) GDPR provides for the controller's and processor's obligation to ensure the DPO's timely and proper involvement in any data protection issues.

Article 38(2) GDPR states that controllers and processors are required to support the DPO in the execution of their tasks by providing necessary resources.

Article 38(3) GDPR highlights the independent nature of the DPO's role, ensuring they are free from any influence or retaliation from the controller in matters pertaining to their office.

Article 38(4) GDPR ensures that data subjects have the right to contact the DPO regarding any issues concerning the processing of their personal data and the exercise of their data protection rights.

Finally, Article 38(5) and (6) GDPR impose an obligation of confidentiality on the DPO and address rules concerning potential conflicts of interest.

EDPB, EDPS and WP29 Guidelines:

  • WP29, 'Guidelines on Data Protection Officers (“DPOs”)', WP 243 rev.01, 5 April 2017 (available here), and
  • EDPS, ‘Supervisory Guidance - Role of the Data Protection Officers in EU institutions, bodies, offices and agencies’, 18 December 2025 (available here).

(1) DPO's involvement in any data protection issues

Article 38(1) GDPR obliges the controller and the processor to ensure that the DPO is involved, properly and in a timely manner, in all issues which relate to the protection of personal data.

The controller and the processor

The addressee of this is provision is the controller or processor who appoints a DPO. It is irrelevant whether the controller or processor was obliged required to appoint a DPO or they were appointed voluntarily.[2] However, the controller or processor's obligation to involve the DPO in all data protection issues corresponds with an internal right of the DPO to demand such involvement.[3]

DPO involvement in data protection issues

Core of this provisions is the required involvement of the DPO whenever an issue relates to the protection of personal data. However, this does not mean that the DPO has to be involved in every processing step (i.e. every time the controller processes personal data), rather this should be considered as the DPO's involvement in the processing activities on a procedural level.[4] For example, this could be the design and development of a product, as well as the creation of a new service or modification of an existing one by adding new features.[5] While the appropriate involvement of the DPO in any processing operation can vary based on the respective complexity and risk, this should not be used as an excuse to avoid involving the DPO at all.[6]

In any case the DPO has to be involved proactively by the controller or processor; it is not sufficient that the DPO has the option to request the necessary information.[7]

DPOs should also be regularly involved in management meetings, and opinions of the DPO should be given due weight. In case management disagrees with the DPO’s opinions, the Article 29 Working Party (WP29) recommends documenting the reasons for not following the DPO’s position.[8] Indeed, this best practice seems also necessary to comply with the principle of accountability (Articles 5(2) and 24 GDPR).

Regarding the question, what should be considered an adequate involvement of the DPO, reference can be made to the DPO's tasks set out in Article 39 GDPR.[9] This means that the involvement of the DPO must enable them to fulfill their tasks; e.g. the DPO must be in a position to inform and advice the controller or processor on data protection issues and to monitor compliance with data protection regulation.[10] In particular, the DPO's task to monitor the controller's or processor's compliance with data protection regulation requires that the DPO is made aware of all processing operations and is able to request all necessary information from the involved departments and employees.[11]

However, it should be pointed out that the DPO does not make any management decisions regarding the controller's or processor's processing operations (in particular, regarding the purposes and means of the processing) and the controller or processor remains responsible for the compliance with data protection regulation.[12] Therefore, despite their involvement in management decisions, the DPO cannot be held personally liable for the non-compliance of the organisation, as liability always stays with the controller.[13]

In a timely manner

According to Article 38(1) GDPR, the DPO must be involved in a timely manner in all issues which relate to the protection of personal data. In this context, "in timely manner" means the earliest possible stage, ideally the design stage of processing operations. In any case, the DPO shall be involved at a stage when fundamental decisions can still be taken.[14] The early involvement of the DPO is also an important factor in complying with the privacy by design principle set out in Article 25 GDPR.[15]

In any case, the DPO should be provided with sufficient time to appropriately asses any processing operation; it should not be expected from the DPO to provide any ad-hoc assessments.[16] Neither would it be compliant to only present the DPO with already final decisions without giving him the option to influence the outcome.[17]

Among others, the early involvement is necessary in order to adequately conduct a Data Protection Impact Assessment (DPIA).[18]

"It is crucial that the DPO, or his/her team, is involved from the earliest stage possible in all issues relating to data protection. In relation to data protection impact assessments, the GDPR explicitly provides for the early involvement of the DPO and specifies that the controller shall seek the advice of the DPO when carrying out such impact assessments. Ensuring that the DPO is informed and consulted at the outset will facilitate compliance with the GDPR, promote a privacy by design approach and should therefore be standard procedure within the organisation’s governance. In addition, it is important that the DPO be seen as a discussion partner within the organisation and that he or she be part of the relevant working groups dealing with data processing activities within the organisation."

WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 13 (footnotes omitted).


(2) Necessary resources

Article 38(2) GDPR obliges the controller or processor to support the DPO in performing their tasks (see Article 39 GDPR) by (i) providing resources necessary to carry out those tasks and (ii) access to personal data and processing operations, and (iii) to maintain their expert knowledge.

The controller and the processor

Just as Article 38(1) GDPR, this provision is addressed to the controller or processor who designated a DPO. See above for more information.

Support the DPO in performing their tasks

Under Article 38(2) GDPR, the DPO must be provided with all necessary resources to carry out their tasks, including access to personal data and processing operations and the possibility to maintain the expert knowledge which is necessary to perform their tasks.

Providing necessary resources

Regarding the necessary resources the DPO should be provided with, the WP29 suggests considering certain elements:

  • The active support of the DPO by senior management.
  • Sufficient time for the DPO to fulfil their responsibilities set out in Article 39 GDPR; in particular in case a DPO is employed only on a part-time basis and/or also has different duties in the organisation, as conflicting priorities could hinder their effectiveness. To address this, the person filling the DPO's role should dedicate an appropriate and sufficient amount of their time to this role.
  • Adequate financial resources, infrastructure such as premises, facilities and equipment, and supportive staff where appropriate.
  • Communication of the designation of the DPO to the organisation's staff in order to ensure that their existence and function are known within the organisation.
  • Access to other services, such as Human Resources, legal, IT, security, etc., allowing the DPOs to receive support, input and information from those other services as well.
  • Access to technical, and personnel resources. It is also essential to communicate the existence and contact details of the DPO to all staff members of the controller or processor to ensure accessibility.[19]

"In general, the more complex and/or sensitive the processing operations, the more resources must be given to the DPO. The data protection function must be effective and sufficiently well-resourced in relation to the data processing being carried out."

WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 14.

In particular, the DPO must be provided with the basic information about the IT infrastructure of the controller or processor as well as with information about the processing operations which should not be limited to the information in the record of processing activities under Article 30 GDPR.[20]

While all this is true for internal as well as for external DPOs,[21] external DPOs will generally allocate the necessary resources of time, personal and facilities themselves while the controller or processor only provides the required financial resources. However, the external DPO still needs all required access to and information about the processing operation as well as it needs to be involved in data protection issues in accordance with Article 38(1) GDPR.[22]

Including access to personal data and processing operations

The authority to access personal data and processing operations mentioned in the GDPR entails for example that the DPO must be allowed to enter all premises where personal data is or may be processed, including on the premises of data processors.[23] The DPO should similarly be provided with the necessary access rights in the controller's or processor's IT-system to fulfil its tasks.[24]

Maintain expert knowledge

It should be recalled that in accordance with Article 37(5) GDPR, the DPO should already have expert knowledge of data protection law when being appointed to this role. During the time of the appointment, the DPO should be provided with continuous training, allowing them to to stay up to date with regard to developments within the field of data protection.[25]

Expert knowledge can be maintained through the institution of updating courses to keep the DPO and their team informed about data protection developments and related disciplines. Alternatively, the DPO must be put in the condition to autonomously catch up with the relevant updates, being the workload no justification to postpone or ignore such an obligation.

(3) Independence, no retaliation, direct communication with management

According to Article 38(3) GDPR, the DPO’s independence in the organisation must be guaranteed by the controller or processor. In particular, the DPO may not receive any instructions from either of them regarding their tasks, and may not be dismissed or sanctioned for performing these tasks. This extends to the personnel working under the DPO, which should only receive substantive directions from the DPO and not from the controller or processor.[26]

The controller and the processor

Just as Article 38(1) and (2) GDPR, this provision is addressed to the controller or processor who designated a DPO. See above for more information regarding the addressee.

Independence (no instructions)

The first part of Article 38(3) GDPR stipulates that the DPO must not receive any instructions from the controller or processor regarding the exercise of their tasks as DPO; in other words, it grants the DPO the right to carry out their duties with an adequate level of autonomy and independence.

In essence, the DPO is empowered to perform their responsibilities without being subject to direct instructions or interference from the controller or processor. As DPOs fulfil their responsibilities under Article 39 GDPR, they must not receive any instructions on how to handle a matter, such as specifying the desired outcome, guiding the investigation of a complaint, or determining whether to consult the supervisory authority. Additionally, they should not be directed to adopt a particular perspective on issues related to data protection law, including a specific interpretation of the law. This provision ensures the DPO's independence and prevents any undue influence that could compromise their objective and impartial role in safeguarding data protection rights.[27]

"This means that, in fulfilling their tasks under Article 39, DPOs must not be instructed how to deal with a matter, for example, what result should be achieved, how to investigate a complaint or whether to consult the supervisory authority. Furthermore, they must not be instructed to take a certain view of an issue related to data protection law, for example, a particular interpretation of the law.


The autonomy of DPOs does not, however, mean that they have decision-making powers extending beyond their tasks pursuant to Article 39.


The controller or processor remains responsible for compliance with data protection law and must be able to demonstrate compliance."

WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 15.

"[T]he objective of ensuring the functional independence of the DPO, as it follows from the second sentence of Article 38(3) of the GDPR, is also apparent from the first and third sentences of that provision, which require that that DPO is not to receive any instructions regarding the exercise of those tasks and is to report directly to the highest level of management of the controller or processor, and from Article 38(5), which provides that, with regard to that exercise, that DPO is to be bound by secrecy or confidentiality [...]"

CJEU - C-453/21 - X-Fab Dresden GmbH & Co. KG, margin number 26 with further reference.


No dismissal or penalties

Article 38(3) requires that DPOs should "not be dismissed or penalised by the controller or the processor for performing [their] tasks." This measure strengthens the autonomy of the DPO by shielding them from possible retaliations by the employer, controller, or processor. In particular, it should enable the DPO to ask uncomfortable questions and provide unfavourable assessments concerning processing operations of the controller or processor.[28] Thus, the DPO's functional independence should be further strengthened by this provision.[29]

While the terms ‘dismissed’, ‘penalised’ and ‘for performing [their] tasks’ are not defined in the GDPR, it means that that DPO must be protected against any decision terminating his or her duties, by which they would be placed at a disadvantage or which would constitute a penalty.[30] It should be noted that this provision only prohibits the dismissal of the DPO or penalties in case they are connected to the exercise of the DPO's functions.

"Penalties are only prohibited under the GDPR if they are imposed as a result of the DPO carrying out his or her duties as a DPO. For example, a DPO may consider that a particular processing is likely to result in a high risk and advise the controller or the processor to carry out a data protection impact assessment but the controller or the processor does not agree with the DPO’s assessment. In such a situation, the DPO cannot be dismissed for providing this advice."

WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 15.


However, just like any other employee or contractor under applicable national contract, labour, and criminal law, a DPO could still be legitimately dismissed for reasons unrelated to the performance of their DPO tasks. For example, grounds for dismissal might include theft, physical, psychological, or sexual harassment, or other forms of gross misconduct.[31] The burden of proof to show that that the reasons for a penalty or dismissal do not lie in the performance of the DPO's task lies with the controller or processor.[32]

In particular, the fact that the DPO must not be dismissed for performing their task does not mean that they cannot be dismissed at all. While the GDPR does not specify specify how and when a DPO can be dismissed or replaced by another person, the contract with the DPO (i.e. the appointment) can be limited in time but should last long enough to enable the DPO to work effectively rather than only cover an onboarding period.[33] Also, it should be pointed out that the DPO can be dismissed in case they no longer fulfil the requirements of a DPO or in case they fail to fulfil their tasks as a DPO.[34]

Penalties (i.e. sanctions) against the DPO can take various forms, both direct and indirect. These may include the absence or delay of promotions, hindrance in career advancement, or denial of benefits that other employees receive. Regarding penalties or sanctions related to the exercise of the DPO’s functions, a broad interpretation must be followed. For example, the DPO shall not suffer disadvantages in the form of threats, absence or delay of promotion, or denial from benefits which other employees receive. In other words, it is not necessary for these penalties to be actually implemented; even a mere threat is sufficient as long as they are used to penalize the DPO based on their DPO activities.[35]

It should be noted that this protection of the DPO is applicable for internal as well as for external DPOs.[36]

"[T]he second sentence of Article 38(3) of the GDPR applies without distinction both to the DPO who is a member of the staff of the controller or processor and to the person who fulfils the tasks on the basis of a service contract concluded with the latter, in accordance with Article 37(6) of the GDPR, with the result that the second sentence of Article 38(3) is intended to apply to relationships between a DPO and a controller or processor, irrespective of the nature of the relationship between that DPO and the latter [...]"

CJEU - C-453/21 - X-Fab Dresden GmbH & Co. KG, margin number 23 with further references.


While each Member State generally is free to lay down more protective specific provisions regarding the dismissal of the DPO, such a provision must not undermine the GDPR; e.g. by preventing the dismissal of a DPO who no longer possesses the professional qualities required to perform their task in Accordance with Article 37(5) GDPR, or who does not fulfil those tasks in accordance with the provisions of that regulation.[37]

"[I]ncreased protection for the DPO which would prevent the dismissal of the DPO in the event that he or she is not, or is no longer, in a position to carry out his or her tasks in an independent manner on account of there being a conflict of interests would undermine the achievement of that objective."

CJEU - C-453/21 - X-Fab Dresden GmbH & Co. KG, margin number 34.


Direct communication with management

If the controller or processor takes decisions that are not in line with the GDPR and contradict the advice given by the DPO, the DPO should have the opportunity to express their dissenting opinion to the highest management level and decision-makers. Article 38(3) GDPR facilitates this process by stating that the DPO "shall directly report to the highest management level of the controller or the processor." This direct reporting ensures that senior management, such as the board of directors, is informed of the DPO's advice and recommendations, as it is part of the DPO's role to inform and advise the controller or processor. Another example of direct reporting is the preparation of an annual report detailing the DPO's activities, which is submitted to the highest management level.[38]

For example: A controller's DPO is integrated in the controller's legal department and only reports internally to the department head which in turn report to the highest management level. Such a structure would be incompatible with the requirements of Article 28(3) GDPR. Not just because the DPO must be able to directly report to the highest management level, but also such a structure would likely lack the necessary independence of the DPO.[39]


(4) DPO as contact point for data subjects

Article 38(4) GDPR grants data subjects the right to contact the DPO on any issues related to (i) the processing of their personal data and (ii) the exercise of their rights under the GDPR. Obviously, this is limited to issues relating to the processing operations of the controller or processor.[40] It should be recalled that under Article 13(1)(b) and 14(1)(b) GDPR, the controller is obliged to inform data subjects about the contact details of the data protection officer; and under Article 37(7) GDPR the controller or processor has to publish the DPO's contact details.[41]

Regarding the first aspect (i.e. the option to contact the DPO on issues relating to the processing of their personal data), the possibility of contacting the DPO implies their capability to conduct internal investigations to verify the existence of violations, if necessary, and report such findings to top management. Furthermore, the DPO should inform the data subject about the results of their investigation.[42]

Concerning the exercise of data subject rights, it is worth noting that the DPO is not directly responsible for executing these rights. Instead, their role is to inform the data subject about the specific rights they possess, particularly in relation to the data subject's specific case. Nonetheless, the obligation to ensure the proper exercise of each right ultimately remains the responsibility of the controller.[43]

The DPO must be directly reachable by the data subject. If the communication is directed to another recipient, it should be forwarded "unopened" to the DPO or a member of their team. This reinforces the notion that the contact details provided in accordance with Article 37(7) GDPR should enable direct communication with the DPO, possibly even through encrypted means.[44]

(5) Confidentiality

Article 38(5) GDPR stipulates that the DPO is bound by secrecy or confidentiality concerning the performance of their tasks, in accordance with Union or Member State law.

The phrasing of this provision is not entirely precise. Firstly, the distinction between "secrecy" and "confidentiality" is not entirely clear, as both terms involve containing information within a special relationship, withholding it from others.[45] More importantly, the provision does not clarify the exact scope of the confidentiality obligation and whether it is simply a referral to any European or national law that regulates such secrecy or confidentiality or whether it is supposed to set out a separate confidentiality obligation applicable even in the absence of such a provision in European or Member State law.[46]

However, this provision should be understood as establishing a (separate) confidentiality obligation of the DPO.[47] The reference to European and Member State law can be considered as the option to further regulate and limit the confidentiality requirements (in particular, at the national level), as well as the legal consequences of breaching these requirements.[48]

For instance, in the case of Article 39(1)(b) GDPR (monitoring the controller's compliance with the rules), confidentiality should protect the data subject, who is the passive subject of potential violations committed by the controller. Thus, the DPO shall be bound by secrecy or confidentiality regarding all elements of the request, including the data subject's identity.[49] Similarly, this provision is supposed to protect any confidential information of the controller such as business secrets and is a requirement for the DPO's capability to access all relevant information in connection with the controller's or processor's processing operations.[50]

[T]he obligation of secrecy/confidentiality does not prohibit the DPO from contacting and seeking advice from the supervisory authority. Article 39(1)(e) provides that the DPO can consult the supervisory authority on any other matter, where appropriate.

WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 18.


(6) Conflict of interests

Tightly connected to the independence requirement is Article 38(6) GDPR which emphasises that while the DPO may fulfil other tasks and duties, these should not result in a conflict of interests. Therefore, the DPO must not be in positions which result in determining the purposes and means of the processing operations of the organisation which appointed the DPO.[51]

"As a rule of thumb, conflicting positions within the organisation may include senior management positions (such as chief executive, chief operating, chief financial, chief medical officer, head of marketing department, head of Human Resources or head of IT departments) but also other roles lower down in the organisational structure if such positions or roles lead to the determination of purposes and means of processing. In addition, a conflict of interests may also arise for example if an external DPO is asked to represent the controller or processor before the Courts in cases involving data protection issues."

WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 16.


Similarly, a possible indicator of a conflict of interest is could be an (unusually high) economic interest in the economic success of the organisation they are working for (e.g. a co-owner of a partnership but not a negligible shareholder in a publicly traded company).[52] The same is generally true for family members of the organisation's owner.[53]

"[T]he GDPR does not establish that there is a fundamental incompatibility between, on the one hand, the performance of DPO’s duties and, on the other hand, the performance of other duties within the controller or processor. Article 38(6) of that regulation specifically provides that the DPO may be entrusted with performing tasks and duties other than those for which it is responsible under Article 39 of the GDPR.


[...] the controller or its processor must ensure that those other tasks and duties do not give rise to a ‘conflict of interests’. In the light of the meaning of those words in everyday language, it must be held that, in accordance with the objective pursued by Article 38(6) of the GDPR, the DPO cannot be entrusted with performing tasks or duties which could impair the execution of the functions performed by the DPO.


[...] that provision is, in essence, intended [...] to preserve the functional independence of the DPO and, consequently, to ensure the effectiveness of the provisions of the GDPR.


[...] according to Article 39(1)(b) of the GDPR, the task of the DPO is, inter alia, to monitor compliance with the GDPR, other provisions of EU law or of the law of the Member States on data protection and the policies of the controller or processor in relation to the protection of personal data, including the assignment of responsibilities, awareness-raising and training of staff involved in processing operations, and the related audits.


It follows, in particular, that a DPO cannot be entrusted with tasks or duties which would result in him or her determining the objectives and methods of processing personal data on the part of the controller or its processor. Under EU law or the law of the Member States on data protection, the review of those objectives and methods must be carried out independently by the DPO.


The determination of the existence of a conflict of interests, within the meaning of Article 38(6) of the GDPR, must be carried out, case by case, on the basis of an assessment of all the relevant circumstances, in particular the organisational structure of the controller or its processor and in the light of all the applicable rules, including any policies of the controller or its processor."

CJEU - C-453/21 - X-Fab Dresden GmbH & Co. KG, margin number 39 et seqq.


Decisions

→ You can find all related decisions in Category:Article 38 GDPR

References

  1. Berg, Herbort, in Kühling, Buchner, DS-GVO BDSG, Article 38 GDPR, margin number 1 (C.H. Beck 2024, 4th Edition).
  2. WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 5 et seq. (available here); see also Commentary on Article 37(1) GDPR.
  3. Berg, Herbort, in Kühling, Buchner, DS-GVO BDSG, Article 38 GDPR, margin number 12 (C.H. Beck 2024, 4th Edition).
  4. Compare Drewes, in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 38 GDPR, margin numbers 8 (NOMOS 2025, 2nd Edition).
  5. Berg, Herbort, in Kühling, Buchner, DS-GVO BDSG, Article 38 GDPR, margin number 13 (C.H. Beck 2024, 4th Edition).
  6. Heberlein, in Ehmann, Selmayr, DS-GVO, Article 38 GDPR, margin number 7 (C.H. Beck 2024, 3rd Edition).
  7. Heberlein, in Ehmann, Selmayr, DS-GVO, Article 38 GDPR, margin number 7 (C.H. Beck 2024, 3rd Edition).
  8. WP29, ‘Guidelines on Data Protection Officers (‘DPOs’)’, 16/EN WP 243 rev.01, 5 April 2017, p. 14 (available here).
  9. Berg, Herbort, in Kühling, Buchner, DS-GVO BDSG, Article 38 GDPR, margin number 15 (C.H. Beck 2024, 4th Edition).
  10. See Article 39(1)(a) and (b) GDPR.
  11. Berg, Herbort, in Kühling, Buchner, DS-GVO BDSG, Article 38 GDPR, margin number 16 et seq. (C.H. Beck 2024, 4th Edition).
  12. Compare WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 15 (available here).
  13. Alvarez Rigaudias, Spina, in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 38 GDPR, p. 707 (Oxford University Press 2020).
  14. Berg, Herbort, in Kühling, Buchner, DS-GVO BDSG, Article 38 GDPR, margin number 14 (C.H. Beck 2024, 4th Edition).
  15. See Commentary on Article 25 GDPR.
  16. Heberlein, in Ehmann, Selmayr, DS-GVO, Article 38 GDPR, margin number 8 (C.H. Beck 2024, 3rd Edition).
  17. Drewes, in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 38 GDPR, margin numbers 12 (NOMOS 2025, 2nd Edition).
  18. WP29, ‘Guidelines on Data Protection Officers (‘DPOs’)’, 16/EN WP 243 rev.01, 5 April 2017, p. 13 (available here).
  19. WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 14 (available here).
  20. Drewes, in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 38 GDPR, margin numbers 21 et seq. (NOMOS 2025, 2nd Edition).
  21. See Commentary on Article 37(6) GDPR for the distinction between internal and external DPO.
  22. Berg, Herbort, in Kühling, Buchner, DS-GVO BDSG, Article 38 GDPR, margin number 21 et seq. (C.H. Beck 2024, 4th Edition).
  23. Berg, Herbort, in Kühling, Buchner, DS-GVO BDSG, Article 38 GDPR, margin number 19 (C.H. Beck 2024, 4th Edition); see also Heberlein, in Ehmann, Selmayr, DS-GVO, Article 38 GDPR, margin number 12 (C.H. Beck 2024, 3rd Edition).
  24. Drewes, in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 38 GDPR, margin numbers 29 (NOMOS 2025, 2nd Edition).
  25. WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 14 (available here).
  26. Berg, Herbort, in Kühling, Buchner, DS-GVO BDSG, Article 38 GDPR, margin number 26 (C.H. Beck 2024, 4th Edition).
  27. WP29, ‘Guidelines on Data Protection Officers (‘DPOs’)’, 16/EN WP 243 rev.01, 5 April 2017, p. 15 (available here).
  28. Berg, Herbort, in Kühling, Buchner, DS-GVO BDSG, Article 38 GDPR, margin number 28 (C.H. Beck 2024, 4th Edition).
  29. CJEU, Case C-453/21, X-FAB Dresden GmbH & Co. KG, 9 February 2023, margin number 27 (available here).
  30. CJEU, Case C-453/21, X-FAB Dresden GmbH & Co. KG, 9 February 2023, margin number 21 with further reference (available here).
  31. WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 15 (available here).
  32. Berg, Herbort, in Kühling, Buchner, DS-GVO BDSG, Article 38 GDPR, margin number 30 et seq. (C.H. Beck 2024, 4th Edition).
  33. WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 16 (available here): Berg, Herbort, in Kühling, Buchner, DS-GVO BDSG, Article 38 GDPR, margin number 29 (C.H. Beck 2024, 4th Edition).
  34. Heberlein, in Ehmann, Selmayr, DS-GVO, Article 38 GDPR, margin number 17 (C.H. Beck 2024, 3rd Edition).
  35. WP29, ‘Guidelines on Data Protection Officers (‘DPOs’)’, 16/EN WP 243 rev.01, 5 April 2017, pp. 15-16 (available here).
  36. Berg, Herbort, in Kühling, Buchner, DS-GVO BDSG, Article 38 GDPR, margin number 28 (C.H. Beck 2024, 4th Edition).
  37. CJEU, Case C-453/21, X-FAB Dresden GmbH & Co. KG, 9 February 2023, margin number 31 et seq. (available here).
  38. WP29, ‘Guidelines on Data Protection Officers (‘DPOs’)’, 16/EN WP 243 rev.01, 5 April 2017, p. 15 (available here).
  39. Heberlein, in Ehmann, Selmayr, DS-GVO, Article 38 GDPR, margin number 19 (C.H. Beck 2024, 3rd Edition).
  40. Berg, Herbort, in Kühling, Buchner, DS-GVO BDSG, Article 38 GDPR, margin number 34 (C.H. Beck 2024, 4th Edition).
  41. See Commentary on Article 13(1)(b) GDPR for more information.
  42. Heberlein, in Ehmann, Selmayr, DS-GVO, Article 38 GDPR, margin number 21 (C.H. Beck 2024, 3rd Edition).
  43. Heberlein, in Ehmann, Selmayr, DS-GVO, Article 38 GDPR, margin number 21 (C.H. Beck 2024, 3rd Edition).
  44. Berg, Herbort, in Kühling, Buchner, DS-GVO BDSG, Article 38 GDPR, margin number 35 (C.H. Beck 2024, 4th Edition).
  45. Behr, H. (2006). Special Section: Secrecy and Confidentiality in Groups. Group Analysis, 39(3), 356–365.
  46. See Berg, Herbort, in Kühling, Buchner, DS-GVO BDSG, Article 38 GDPR, margin number 38 (C.H. Beck 2024, 4th Edition).
  47. CJEU, Case C-453/21, X-FAB Dresden GmbH & Co. KG, 9 February 2023, margin number 26 (available here); Berg, Herbort, in Kühling, Buchner, DS-GVO BDSG, Article 38 GDPR, margin number 38 (C.H. Beck 2024, 4th Edition); Drewes, in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 38 GDPR, margin numbers 54 (NOMOS 2025, 2nd Edition).
  48. Compare Berg, Herbort, in Kühling, Buchner, DS-GVO BDSG, Article 38 GDPR, margin number 38 (C.H. Beck 2024, 4th Edition).
  49. Compare Berg, Herbort, in Kühling, Buchner, DS-GVO BDSG, Article 38 GDPR, margin number 38b (C.H. Beck 2024, 4th Edition).
  50. Heberlein, in Ehmann, Selmayr, DS-GVO, Article 38 GDPR, margin number 23 (C.H. Beck 2024, 3rd Edition).
  51. WP29, Guidelines on Data Protection Officers (“DPOs”)”, WP 243 rev.01, 5 April 2017, p. 16 (available here).
  52. Berg, Herbort, in Kühling, Buchner, DS-GVO BDSG, Article 38 GDPR, margin number 41 (C.H. Beck 2024, 4th Edition).
  53. Berg, Herbort, in Kühling, Buchner, DS-GVO BDSG, Article 38 GDPR, margin number 41 (C.H. Beck 2024, 4th Edition).