Control function without instructions
In Germany, the tasks and activities of an internal or external data protection officer are governed by Sections 4f and 4g of the Federal Data Protection Act (BDSG). There are also regulations under state law. The data protection officer is responsible for monitoring compliance with the BDSG and other laws (Telemedia Act (TMG) or Telecommunications Act (TKG)). The data protection officer always acts independently and without instructions.
All public authorities, companies and associations must appoint a data protection officer as soon as personal data is processed automatically. 'Automated' is any processing that uses electronic data processing equipment (e.g. PCs) for business processes. Every organization must appoint a data protection officer no later than one month after commencing operations, otherwise it is an administrative offence that can be punished with fines of up to 50,000 euros. The data protection officer either comes 'internally' from the organization or must be appointed 'externally'.
Anyone who cannot fulfill the function of a data protection officer 'from on-board resources' is welcome to use us and our experience 'externally'.