Compliance

CISO vs. DPO: Responsibilities, Legal Requirements, and Dual Roles

Who protects what, when each role is mandatory in Germany, and whether one person should hold both.

Author
Dr. Kilian Schmidt
Date
6.10.2026
Updated on
7.10.2026
CISO vs. DPO: Responsibilities, Legal Requirements, and Dual Roles

Key takeaways

  • The data protection officer (DPO) protects the rights of people whose data is processed. The information security officer protects the confidentiality, integrity, and availability of all company information, from customer data to engineering drawings.
  • Art. 37 GDPR and Section 38(1) of the German Federal Data Protection Act (BDSG) require a DPO, in Germany generally once 20 or more people are constantly engaged in the automated processing of personal data. The federal government has announced that it will propose abolishing this threshold by the end of 2026; as of October 2026, it still applies.
  • Private companies in Germany have no legal obligation to appoint an information security officer. ISO 27001, the German NIS2 implementation act in force since December 6, 2025, and customer requirements still make a named owner for information security unavoidable in practice.
  • No law prohibits one person from being both security officer and DPO. Under the CJEU ruling C-453/21 of February 9, 2023, however, a DPO may not hold tasks that lead them to determine the purposes and means of processing. A security officer who designs measures they must then review as DPO runs straight into that conflict.
  • Both roles can be outsourced, the DPO explicitly under Art. 37(6) GDPR. Accountability stays with management: under Art. 24 GDPR for data protection and under Section 38 of the German BSI Act (BSIG) for implementing and overseeing NIS2 measures.

In sales calls with German mid-sized companies, one question comes up almost every time: What is the difference between a CISO and a DPO, and can we outsource both? The short answer is that the DPO protects people and the security officer protects information. The two work closely together but have different legal bases, different duties, and a different relationship with management. This article helps managing directors and IT leads decide who takes on which role.

A note on terms: German companies call the security role Informationssicherheitsbeauftragter (ISB), literally "information security officer." Many give it a CISO title, although in larger organizations the CISO is usually a more senior executive role. In this article we use "information security officer," or "security officer" for short, for the person who runs the information security management system.

The difference between a CISO and a DPO at a glance

The DPO monitors whether a company complies with the GDPR and does so free from instructions. The security officer builds and runs the information security management system (ISMS) and reports to management on its state. Almost everything else follows from this difference between review and design, including the answer to whether one person can hold both roles.

The DPO role is part of data protection law, which our GDPR guide covers in full. The security officer role comes from the world of management systems and security standards. The following table sets the two side by side.

Information security officer (ISB, often titled CISO) Data protection officer (DPO)
Legal basis No dedicated law for private companies. Derived from ISO/IEC 27001 clause 5.3, BSI IT-Grundschutz ISMS.1.A4, and NIS2 duties under Sections 30 and 38 BSIG Art. 37 to 39 GDPR, Section 38 BDSG
What it protects Confidentiality, integrity, and availability of all information, including information with no personal reference Rights and freedoms of individuals when their data is processed
Core tasks Build and run the ISMS, risk assessments, policies, incident coordination, awareness, reporting to management Inform and advise, monitor GDPR compliance, advise on data protection impact assessments, cooperate with the supervisory authority (Art. 39(1) GDPR)
Mandatory when No legal appointment duty. Expected in practice under ISO 27001, NIS2, and customer requirements Core activities under Art. 37(1) GDPR, or generally 20 or more people in automated processing (Section 38(1) BDSG)
Bound by instructions Yes, acts on behalf of management No, free from instructions when performing their tasks (Art. 38(3) GDPR)
Can be external Yes, explicitly provided for in IT-Grundschutz (ISMS.1.A5) Yes, explicitly under Art. 37(6) GDPR
Typical reporting line Directly to management Directly to the highest management level, required by law

What does the DPO protect?

The DPO represents the perspective of the people affected: employees, applicants, customers, or contacts at suppliers. They review legal bases, the record of processing activities, and retention periods. Under Art. 38(3) GDPR, they receive no instructions in this work and may not be dismissed or penalized for performing their tasks.

What does the information security officer protect?

The security officer thinks in information assets, not people. For a machinery manufacturer, that means CAD data, machine control software, the ERP system, and pricing calculations. A ransomware attack on production is a core concern for the security officer even if not a single personal record leaves the building. The two roles meet in Art. 32 GDPR: the technical and organizational measures that protect personal data are also part of the ISMS.

When is each role mandatory?

For most German mid-sized companies, the DPO is a legal requirement. The security officer is not, but a number of requirements are hard to meet without a named owner.

When is a DPO mandatory?

Art. 37(1) GDPR requires a DPO in three cases: public authorities, organizations whose core activity is large-scale, regular, and systematic monitoring of individuals, and organizations whose core activity is large-scale processing of special categories of data under Art. 9 or Art. 10 GDPR. For a typical industrial company, none of these applies.

In Germany, Section 38(1) BDSG is therefore what decides the question. It requires a DPO where a company generally has at least 20 people constantly engaged in the automated processing of personal data. The count is not total headcount but the people who regularly work with such data on a computer. In a company with 200 employees, sales, purchasing, HR, accounting, and engineering reach 20 quickly. Regardless of headcount, the duty applies whenever a data protection impact assessment under Art. 35 GDPR is required. The German text of Section 38 BDSG is short and worth reading.

The threshold is up for political debate. In the Federal Modernization Agenda of December 4, 2025, the federal government announced it would propose repealing Section 38(1) BDSG by December 31, 2026. To our knowledge, no draft bill exists as of October 2026. Even after a repeal, Art. 37 GDPR would remain, and the GDPR's own obligations do not go away. Supervisory authorities can fine violations of Art. 37 to 39 GDPR up to EUR 10 million or 2 percent of worldwide annual turnover under Art. 83(4) GDPR.

When is an information security officer mandatory, and when is one expected?

Private companies in Germany have no general legal obligation to appoint an information security officer. The new BSIG, in force since December 6, 2025, explicitly requires one only for federal administration bodies (Section 45 BSIG). The ten risk management measures in Section 30(2) BSIG do not name a role. In practice, you still can hardly do without a named owner, for three reasons:

  • NIS2. Under Section 28 BSIG, important entities are companies in covered sectors with at least 50 employees or more than EUR 10 million in both turnover and balance sheet total. Machinery manufacturing is one of those sectors. Section 38 BSIG requires management to implement the measures, oversee their implementation, and attend training regularly. Without someone who runs this day to day, that oversight is hard to deliver. For certain digital providers, such as cloud and managed service providers, Implementing Regulation (EU) 2024/2690, Annex point 1.2.3, also requires at least one person directly accountable to the management bodies for network and information security.
  • ISO 27001. Clause 5.3 requires top management to assign responsibility for the ISMS's conformity and for reporting on its performance. The standard prescribes no job title, but ISO 27001 certification still needs a named person.
  • Customers. Car makers, large corporations, and increasingly mid-sized companies ask for an information security contact in supplier questionnaires. Anyone going through a TISAX assessment must have defined responsibilities for information security.

A common misconception: "Our DPO covers information security." It does not. The DPO checks whether personal data is adequately protected. Whether production is back up 48 hours after an attack, whether engineering data is encrypted, and whether an emergency plan exists are outside their remit. With a DPO and no security officer, only half the topic is covered.

Can one person be both DPO and security officer?

No law prohibits one person from being security officer and DPO at the same time. Art. 38(6) GDPR explicitly allows the DPO to take on other tasks as long as they do not create a conflict of interest. That is exactly where the problem with a dual role lies.

The CJEU set out the test in X-FAB Dresden (C-453/21) on February 9, 2023. A DPO may not be entrusted with tasks or duties that would lead them to determine the purposes and means of processing personal data (para. 44). Whether a conflict exists must be assessed case by case, taking into account all relevant circumstances, in particular the organizational structure (para. 45).

For combining the DPO with the security officer, this means the conflict arises wherever the security officer makes decisions, typically in three situations.

  1. Technical and organizational measures. The security officer designs the measures under Art. 32 GDPR, and the DPO is supposed to monitor whether they are adequate under Art. 39(1)(b) GDPR. In a dual role, someone reviews their own work.
  2. Logging and monitoring. Security wants more data: log files, email filters, endpoint monitoring. Data protection wants as little as necessary, especially for employee data. Whoever holds both roles decides on the means of a processing activity they are then supposed to assess independently.
  3. Security incidents. The security officer wants to contain the incident and restore operations. In parallel, the DPO must assess whether the incident has to be reported to the supervisory authority within 72 hours under Art. 33 GDPR. Under time pressure, the two priorities collide.

For this reason, the Bavarian State Office for Information Security (LSI) advises public authorities against combining the two roles. There is no equally binding statement for companies, but the CJEU's reasoning applies regardless of legal form. A small company without an ISMS can justify a dual role if the security officer has no decision-making authority over processing and the conflict has been weighed and documented. Once an ISMS with real decision-making power is in place, there is a strong case for two people.

A second misconception: "The IT lead can handle it on the side." As DPO, the IT lead is generally ruled out under the X-FAB reasoning, because they decide on the means of processing. As security officer, they are legally permitted but end up auditing the security of their own operations. ISO 27001 requires segregation of conflicting duties in Annex A 5.3, and auditors look closely at exactly that point. Capacity is the other issue: building an ISMS takes months and regularly stalls next to day-to-day IT work.

External CISO and external DPO: what can you outsource, and what stays with management?

Both roles can be filled externally. For the DPO, Art. 37(6) GDPR says so explicitly: the DPO may be a staff member or fulfill the tasks on the basis of a service contract. For the security officer, there is no statutory rule, but no prohibition either. BSI IT-Grundschutz requirement ISMS.1.A5 explicitly provides for an external security officer where the role cannot be filled internally, and specifies what the contract must contain.

The main benefits of an external DPO are available expertise and independence, because no second role inside the company collides with the position. What an external mandate costs and how it compares with an internal appointment are covered in detail there.

An external DPO or security officer takes on the expert role, not the accountability. That holds in both areas of law:

  • Data protection. Under Art. 24 GDPR, the company remains responsible for GDPR compliance. The DPO advises and monitors; they do not decide and are not liable in your place.
  • Information security. Section 38(1) BSIG requires management itself to implement risk management measures and oversee their implementation, and Section 38(2) BSIG ties liability under company law to that duty. The training obligation under Section 38(3) BSIG applies to management personally.

Decisions on risks, budget, and policies stay with management. You also need an internal contact with access to the systems, because an external security officer only sees what they are shown.

Kertos customers often name having a DPO as the most important reason for the external route:

"For me, by far the most important factor is having a DPO and, in the end, being able to show structured, largely complete GDPR documentation that will also stand up to any inspections."

Achim B., Chief Of Staff, Small-Business (50 or fewer emp.), G2 review, September 28, 2026, translated from German

If you outsource both roles, you have two options: two separate providers or one provider with two mandates. The second option saves coordination, as long as the provider assigns the DPO and security officer roles to different people. Otherwise the dual role has simply moved from your org chart to the provider's.

Scenario: a machinery manufacturer with 200 employees

A builder of special-purpose machinery in Baden-Württemberg employs 200 people, around 60 of them in the office and engineering. Two automotive suppliers among its customers require ISO 27001 certification within twelve months, and a third sends an annual questionnaire with more than 80 questions on information security. The IT lead has been the DPO for years, and there is no security officer.

The assessment produces three findings. First, with 200 employees in machinery manufacturing, the company is at least an important entity under Section 28 BSIG and subject to Sections 30 and 38 BSIG. Second, under the X-FAB ruling, the IT lead as DPO is hard to defend: he selects the systems whose data processing he is supposed to review. Third, nobody is in place to lead the ISMS for ISO 27001 certification.

Management chooses the following setup. It outsources the DPO role, and the IT lead is relieved of it while remaining the contact for technical implementation. For the ISMS build, it brings in an external security officer who steers the risk assessment, policies, and audit preparation. Internally, the head of quality management takes on coordination at a quarter of her working time, because she knows management systems and audits from ISO 9001. The managing director receives quarterly reports and completes the training required by Section 38(3) BSIG. The result is three separate roles with no conflict of interest.

Decision guide: which setup fits which company?

The right split depends on three questions: Is a DPO mandatory? Is there pressure from NIS2, ISO 27001, or customers? Does the company have internal capacity and expertise? The following overview maps typical situations.

Situation DPO Security officer Why
Fewer than 20 people in data processing, no NIS2, no customer requirement Not mandatory, a data protection contact is recommended Named internal owner for IT security GDPR obligations apply without a DPO, but the role itself is not required
DPO mandatory, no pressure on information security External Internal, clearly separated from IT management The external DPO resolves the conflict of interest, and the security workload stays manageable
Customers require ISO 27001 or TISAX, little internal security expertise External External for the build, plus internal coordination The build needs experience, and ongoing operation needs someone in-house
Important or essential entity under NIS2 External, or internal without decision-making authority over processing Named, with a direct reporting line to management, internal or external Management must oversee implementation under Section 38 BSIG and needs regular reports to do so
Established security team, in-house data protection lawyers Internal, separate from the security officer Internal The capacity exists, and separate people protect independence

The rule of thumb behind it: a dual role only where the security officer decides nothing, and internal solutions only where someone truly has the time.

How Kertos covers both roles

Kertos offers the external CISO and the external DPO as separate mandates, each with its own service specification. Both roles are performed by certified experts who support your company on the Kertos platform. The platform holds the ISMS, risks, and controls for ISO 27001 certification alongside the record of processing activities, the technical and organizational measures, and data protection impact assessments. Where the two areas overlap, for example in measures under Art. 32 GDPR, the DPO and the security officer work from the same data without one person holding both roles.

Customers particularly value the expert support:

"The support from the data protection officer is practical and shows a real understanding of our business."

Stefan R., Co-Founder, Small-Business (50 or fewer emp.), G2 review, July 23, 2026, translated from German

See our plans and pricing for the combination that fits your company, or book a demo to discuss your setup with us directly.

Frequently asked questions

What is the difference between a CISO and a DPO?

The DPO protects the rights of individuals when their data is processed and monitors GDPR compliance free from instructions. The information security officer, often titled CISO, protects the confidentiality, integrity, and availability of all company information and runs the ISMS on behalf of management. The DPO is governed by Art. 37 to 39 GDPR, while in Germany there is no dedicated law for the security role at private companies.

Can a DPO also be the CISO?

Legally, yes: Art. 38(6) GDPR allows other tasks as long as they create no conflict of interest. Under CJEU ruling C-453/21, however, a DPO may not determine the purposes and means of processing. As soon as the security officer decides on security measures the DPO is supposed to review, a conflict is likely, so two people are advisable once a working ISMS is in place.

Is an information security officer mandatory in Germany?

Private companies in Germany have no legal obligation to appoint one; the BSIG requires it only for federal administration bodies. ISO 27001 does require assigned responsibility for the ISMS, NIS2 obliges management to oversee security measures, and customers specifically ask for a security contact. In practice, most mid-sized companies therefore need one.

When do you need a data protection officer in Germany?

Under Section 38(1) BDSG, generally once 20 or more people are constantly engaged in the automated processing of personal data, regardless of total headcount. If a data protection impact assessment is required, the duty applies regardless of numbers. The federal government plans to abolish the 20-person threshold; as of October 2026, it still applies.

Can you outsource the CISO and DPO roles?

Yes, both roles can be outsourced, the DPO explicitly under Art. 37(6) GDPR and the security officer under established practice and BSI IT-Grundschutz. Accountability stays with management, under Art. 24 GDPR for data protection and under Section 38 BSIG for NIS2 measures. If you give both roles to one provider, make sure they are assigned to different people.

‍

The Founder's Guide about NIS2: Prepare your company Now before

Protect your startup: Discover how NIS2 can impact your business and what you need to consider now. Read the free white paper now!

Ready, your compliance to put on autopilot?
Dr. Kilian Schmidt

Dr. Kilian Schmidt

CEO & Co-Founder at Kertos

Kilian had a strong focus on legal processes from an early age and began his career at Home24 as a Senior Legal Counsel and Data Protection Officer for the Home24 group. After a stint at Freshfields Bruckhaus Deringer, he moved to TIER Mobility, where he expanded the company's legal and public policy departments from one to 65 cities and from 50 to 800 employees. Driven by the lack of technology in the legal field and confirmed by his consulting work at Gorillas Technologies, he decided to found Kertos to develop the next generation of compliance – made in Europe.

About Kertos

Kertos is the modern backbone of the data protection and compliance activities of scaling companies. We enable our customers to implement integrated data protection and information security processes in accordance with GDPR, ISO 27001, TISAX®, SOC2 and many other standards quickly and cheaply through automation.

Ready to simplify GDPR compliance?

CTA Image

📅 Schedule Your 5min Compliance Check

Please enter your business email to continue. We require a company email address to ensure we can best serve your organization.

📞 5min Compliance Check