Key takeaways
- The data protection officer (DPO) protects the rights of people whose data is processed. The information security officer protects the confidentiality, integrity, and availability of all company information, from customer data to engineering drawings.
- Art. 37 GDPR and Section 38(1) of the German Federal Data Protection Act (BDSG) require a DPO, in Germany generally once 20 or more people are constantly engaged in the automated processing of personal data. The federal government has announced that it will propose abolishing this threshold by the end of 2026; as of October 2026, it still applies.
- Private companies in Germany have no legal obligation to appoint an information security officer. ISO 27001, the German NIS2 implementation act in force since December 6, 2025, and customer requirements still make a named owner for information security unavoidable in practice.
- No law prohibits one person from being both security officer and DPO. Under the CJEU ruling C-453/21 of February 9, 2023, however, a DPO may not hold tasks that lead them to determine the purposes and means of processing. A security officer who designs measures they must then review as DPO runs straight into that conflict.
- Both roles can be outsourced, the DPO explicitly under Art. 37(6) GDPR. Accountability stays with management: under Art. 24 GDPR for data protection and under Section 38 of the German BSI Act (BSIG) for implementing and overseeing NIS2 measures.
In sales calls with German mid-sized companies, one question comes up almost every time: What is the difference between a CISO and a DPO, and can we outsource both? The short answer is that the DPO protects people and the security officer protects information. The two work closely together but have different legal bases, different duties, and a different relationship with management. This article helps managing directors and IT leads decide who takes on which role.
A note on terms: German companies call the security role Informationssicherheitsbeauftragter (ISB), literally "information security officer." Many give it a CISO title, although in larger organizations the CISO is usually a more senior executive role. In this article we use "information security officer," or "security officer" for short, for the person who runs the information security management system.
The difference between a CISO and a DPO at a glance
The DPO monitors whether a company complies with the GDPR and does so free from instructions. The security officer builds and runs the information security management system (ISMS) and reports to management on its state. Almost everything else follows from this difference between review and design, including the answer to whether one person can hold both roles.
The DPO role is part of data protection law, which our GDPR guide covers in full. The security officer role comes from the world of management systems and security standards. The following table sets the two side by side.
What does the DPO protect?
The DPO represents the perspective of the people affected: employees, applicants, customers, or contacts at suppliers. They review legal bases, the record of processing activities, and retention periods. Under Art. 38(3) GDPR, they receive no instructions in this work and may not be dismissed or penalized for performing their tasks.
What does the information security officer protect?
The security officer thinks in information assets, not people. For a machinery manufacturer, that means CAD data, machine control software, the ERP system, and pricing calculations. A ransomware attack on production is a core concern for the security officer even if not a single personal record leaves the building. The two roles meet in Art. 32 GDPR: the technical and organizational measures that protect personal data are also part of the ISMS.
When is each role mandatory?
For most German mid-sized companies, the DPO is a legal requirement. The security officer is not, but a number of requirements are hard to meet without a named owner.
When is a DPO mandatory?
Art. 37(1) GDPR requires a DPO in three cases: public authorities, organizations whose core activity is large-scale, regular, and systematic monitoring of individuals, and organizations whose core activity is large-scale processing of special categories of data under Art. 9 or Art. 10 GDPR. For a typical industrial company, none of these applies.
In Germany, Section 38(1) BDSG is therefore what decides the question. It requires a DPO where a company generally has at least 20 people constantly engaged in the automated processing of personal data. The count is not total headcount but the people who regularly work with such data on a computer. In a company with 200 employees, sales, purchasing, HR, accounting, and engineering reach 20 quickly. Regardless of headcount, the duty applies whenever a data protection impact assessment under Art. 35 GDPR is required. The German text of Section 38 BDSG is short and worth reading.
The threshold is up for political debate. In the Federal Modernization Agenda of December 4, 2025, the federal government announced it would propose repealing Section 38(1) BDSG by December 31, 2026. To our knowledge, no draft bill exists as of October 2026. Even after a repeal, Art. 37 GDPR would remain, and the GDPR's own obligations do not go away. Supervisory authorities can fine violations of Art. 37 to 39 GDPR up to EUR 10 million or 2 percent of worldwide annual turnover under Art. 83(4) GDPR.
When is an information security officer mandatory, and when is one expected?
Private companies in Germany have no general legal obligation to appoint an information security officer. The new BSIG, in force since December 6, 2025, explicitly requires one only for federal administration bodies (Section 45 BSIG). The ten risk management measures in Section 30(2) BSIG do not name a role. In practice, you still can hardly do without a named owner, for three reasons:
- NIS2. Under Section 28 BSIG, important entities are companies in covered sectors with at least 50 employees or more than EUR 10 million in both turnover and balance sheet total. Machinery manufacturing is one of those sectors. Section 38 BSIG requires management to implement the measures, oversee their implementation, and attend training regularly. Without someone who runs this day to day, that oversight is hard to deliver. For certain digital providers, such as cloud and managed service providers, Implementing Regulation (EU) 2024/2690, Annex point 1.2.3, also requires at least one person directly accountable to the management bodies for network and information security.
- ISO 27001. Clause 5.3 requires top management to assign responsibility for the ISMS's conformity and for reporting on its performance. The standard prescribes no job title, but ISO 27001 certification still needs a named person.
- Customers. Car makers, large corporations, and increasingly mid-sized companies ask for an information security contact in supplier questionnaires. Anyone going through a TISAX assessment must have defined responsibilities for information security.
A common misconception: "Our DPO covers information security." It does not. The DPO checks whether personal data is adequately protected. Whether production is back up 48 hours after an attack, whether engineering data is encrypted, and whether an emergency plan exists are outside their remit. With a DPO and no security officer, only half the topic is covered.
Can one person be both DPO and security officer?
No law prohibits one person from being security officer and DPO at the same time. Art. 38(6) GDPR explicitly allows the DPO to take on other tasks as long as they do not create a conflict of interest. That is exactly where the problem with a dual role lies.
The CJEU set out the test in X-FAB Dresden (C-453/21) on February 9, 2023. A DPO may not be entrusted with tasks or duties that would lead them to determine the purposes and means of processing personal data (para. 44). Whether a conflict exists must be assessed case by case, taking into account all relevant circumstances, in particular the organizational structure (para. 45).
For combining the DPO with the security officer, this means the conflict arises wherever the security officer makes decisions, typically in three situations.
- Technical and organizational measures. The security officer designs the measures under Art. 32 GDPR, and the DPO is supposed to monitor whether they are adequate under Art. 39(1)(b) GDPR. In a dual role, someone reviews their own work.
- Logging and monitoring. Security wants more data: log files, email filters, endpoint monitoring. Data protection wants as little as necessary, especially for employee data. Whoever holds both roles decides on the means of a processing activity they are then supposed to assess independently.
- Security incidents. The security officer wants to contain the incident and restore operations. In parallel, the DPO must assess whether the incident has to be reported to the supervisory authority within 72 hours under Art. 33 GDPR. Under time pressure, the two priorities collide.
For this reason, the Bavarian State Office for Information Security (LSI) advises public authorities against combining the two roles. There is no equally binding statement for companies, but the CJEU's reasoning applies regardless of legal form. A small company without an ISMS can justify a dual role if the security officer has no decision-making authority over processing and the conflict has been weighed and documented. Once an ISMS with real decision-making power is in place, there is a strong case for two people.
A second misconception: "The IT lead can handle it on the side." As DPO, the IT lead is generally ruled out under the X-FAB reasoning, because they decide on the means of processing. As security officer, they are legally permitted but end up auditing the security of their own operations. ISO 27001 requires segregation of conflicting duties in Annex A 5.3, and auditors look closely at exactly that point. Capacity is the other issue: building an ISMS takes months and regularly stalls next to day-to-day IT work.
External CISO and external DPO: what can you outsource, and what stays with management?
Both roles can be filled externally. For the DPO, Art. 37(6) GDPR says so explicitly: the DPO may be a staff member or fulfill the tasks on the basis of a service contract. For the security officer, there is no statutory rule, but no prohibition either. BSI IT-Grundschutz requirement ISMS.1.A5 explicitly provides for an external security officer where the role cannot be filled internally, and specifies what the contract must contain.
The main benefits of an external DPO are available expertise and independence, because no second role inside the company collides with the position. What an external mandate costs and how it compares with an internal appointment are covered in detail there.
An external DPO or security officer takes on the expert role, not the accountability. That holds in both areas of law:
- Data protection. Under Art. 24 GDPR, the company remains responsible for GDPR compliance. The DPO advises and monitors; they do not decide and are not liable in your place.
- Information security. Section 38(1) BSIG requires management itself to implement risk management measures and oversee their implementation, and Section 38(2) BSIG ties liability under company law to that duty. The training obligation under Section 38(3) BSIG applies to management personally.
Decisions on risks, budget, and policies stay with management. You also need an internal contact with access to the systems, because an external security officer only sees what they are shown.
Kertos customers often name having a DPO as the most important reason for the external route:
If you outsource both roles, you have two options: two separate providers or one provider with two mandates. The second option saves coordination, as long as the provider assigns the DPO and security officer roles to different people. Otherwise the dual role has simply moved from your org chart to the provider's.
Scenario: a machinery manufacturer with 200 employees
A builder of special-purpose machinery in Baden-Württemberg employs 200 people, around 60 of them in the office and engineering. Two automotive suppliers among its customers require ISO 27001 certification within twelve months, and a third sends an annual questionnaire with more than 80 questions on information security. The IT lead has been the DPO for years, and there is no security officer.
The assessment produces three findings. First, with 200 employees in machinery manufacturing, the company is at least an important entity under Section 28 BSIG and subject to Sections 30 and 38 BSIG. Second, under the X-FAB ruling, the IT lead as DPO is hard to defend: he selects the systems whose data processing he is supposed to review. Third, nobody is in place to lead the ISMS for ISO 27001 certification.
Management chooses the following setup. It outsources the DPO role, and the IT lead is relieved of it while remaining the contact for technical implementation. For the ISMS build, it brings in an external security officer who steers the risk assessment, policies, and audit preparation. Internally, the head of quality management takes on coordination at a quarter of her working time, because she knows management systems and audits from ISO 9001. The managing director receives quarterly reports and completes the training required by Section 38(3) BSIG. The result is three separate roles with no conflict of interest.
Decision guide: which setup fits which company?
The right split depends on three questions: Is a DPO mandatory? Is there pressure from NIS2, ISO 27001, or customers? Does the company have internal capacity and expertise? The following overview maps typical situations.
The rule of thumb behind it: a dual role only where the security officer decides nothing, and internal solutions only where someone truly has the time.
How Kertos covers both roles
Kertos offers the external CISO and the external DPO as separate mandates, each with its own service specification. Both roles are performed by certified experts who support your company on the Kertos platform. The platform holds the ISMS, risks, and controls for ISO 27001 certification alongside the record of processing activities, the technical and organizational measures, and data protection impact assessments. Where the two areas overlap, for example in measures under Art. 32 GDPR, the DPO and the security officer work from the same data without one person holding both roles.
Customers particularly value the expert support:
See our plans and pricing for the combination that fits your company, or book a demo to discuss your setup with us directly.
Frequently asked questions
What is the difference between a CISO and a DPO?
The DPO protects the rights of individuals when their data is processed and monitors GDPR compliance free from instructions. The information security officer, often titled CISO, protects the confidentiality, integrity, and availability of all company information and runs the ISMS on behalf of management. The DPO is governed by Art. 37 to 39 GDPR, while in Germany there is no dedicated law for the security role at private companies.
Can a DPO also be the CISO?
Legally, yes: Art. 38(6) GDPR allows other tasks as long as they create no conflict of interest. Under CJEU ruling C-453/21, however, a DPO may not determine the purposes and means of processing. As soon as the security officer decides on security measures the DPO is supposed to review, a conflict is likely, so two people are advisable once a working ISMS is in place.
Is an information security officer mandatory in Germany?
Private companies in Germany have no legal obligation to appoint one; the BSIG requires it only for federal administration bodies. ISO 27001 does require assigned responsibility for the ISMS, NIS2 obliges management to oversee security measures, and customers specifically ask for a security contact. In practice, most mid-sized companies therefore need one.
When do you need a data protection officer in Germany?
Under Section 38(1) BDSG, generally once 20 or more people are constantly engaged in the automated processing of personal data, regardless of total headcount. If a data protection impact assessment is required, the duty applies regardless of numbers. The federal government plans to abolish the 20-person threshold; as of October 2026, it still applies.
Can you outsource the CISO and DPO roles?
Yes, both roles can be outsourced, the DPO explicitly under Art. 37(6) GDPR and the security officer under established practice and BSI IT-Grundschutz. Accountability stays with management, under Art. 24 GDPR for data protection and under Section 38 BSIG for NIS2 measures. If you give both roles to one provider, make sure they are assigned to different people.





