Switching your data protection officer: costs, notice periods, and handover checklist
Poor availability, high costs, one PDF report per year: there are good reasons to switch your data protection officer (DPO). Legally it is straightforward — as long as termination, handover, and the notification to the supervisory authority happen in the right order. The complete roadmap with checklist.

Table of contents
- Context: when switching pays off
- Who needs a data protection officer at all?
- Terminating an external DPO: contract and notice periods
- Special case internal DPO: the special protection
- What does a data protection officer cost?
- The roadmap: a new DPO in six to eight weeks
- The handover: these records change hands
- Do not forget the notification to the supervisory authority
- How switching works with Dieter
- Conclusion
Context: when switching pays off
In many companies, the data protection officer is a line item that gets purchased once and then never questioned again. Yet quality and price vary considerably across the market. If one or more of the following applies to your current arrangement, a comparison is worth your time:
- Availability: You regularly wait several days for answers, and there is no fixed contact person.
- Purely reactive: Your DPO shows up once a year for the report but never proactively when the legal situation changes.
- Outdated documentation: The record of processing activities and TOMs no longer reflect how your company actually works.
- No training: Your employees have not been trained in over a year, or training costs extra.
- New topics missing: No solid answers on AI tools, cloud services, or the EU AI Act.
- Value for money: You pay an annual flat fee whose main deliverable is a PDF.
The good news: switching an external data protection officer is legally straightforward. It just needs the right sequence so that no gap arises and the documentation changes hands completely.
Who needs a data protection officer at all?
Before you switch, it is worth a quick look at the obligation itself. In Germany, you must appoint a data protection officer if one of the following applies:
- At least 20 people in your company are permanently engaged in the automated processing of personal data (Section 38 BDSG). This counts everyone who regularly works with personal data on a computer, including part-time staff and freelancers.
- You carry out processing operations that require a data protection impact assessment, or you process data commercially for transfer or for market and opinion research. In these cases the obligation applies regardless of headcount.
- Your core activity consists of extensive, regular monitoring of individuals or extensive processing of special categories of data (Art. 37 GDPR).
Terminating an external DPO: contract and notice periods
An external data protection officer works on the basis of a service contract. Unlike an internal DPO, there is no statutory protection against removal: the contract terms and notice periods simply apply. Typical are terms of twelve to 24 months with automatic renewal and notice periods of one to three months to the end of a month or quarter. So check your contract first — otherwise you may end up paying for another year.
The order matters: only terminate once the successor is in place, or plan the notice period as your handover window. Companies subject to the appointment obligation must never be without a data protection officer. An overlap of two to four weeks between the old and new DPO is ideal for an orderly handover.
Special case internal DPO: the special protection
Things are quite different if your current data protection officer is one of your own employees. Where an appointment obligation exists, internal DPOs enjoy strong statutory protection (Section 38(2) in conjunction with Section 6(4) BDSG): removal is only permitted for good cause analogous to Section 626 of the German Civil Code, and the employment relationship enjoys special protection against dismissal during the role and for one year afterwards.
Good cause can include persistent neglect of DPO duties, a conflict of interest, or lack of expertise. Whether the mere wish to switch to an external provider suffices is legally disputed — seek advice before any removal. The consensual route, on the other hand, is unproblematic: many internal DPOs are happy to hand over the role, as it is hard to manage alongside their day job.
What does a data protection officer cost?
Costs depend on the model. For orientation, the typical ranges as cited, among others, by the German professional association of data protection officers (BvD):
| Model | Typical costs | Best suited for |
|---|---|---|
| Internal DPO | A share of working time plus training courses — realistically several thousand euros per year, plus the special protection against dismissal | Larger companies with in-house data protection expertise and capacity |
| External DPO (traditional) | €150–300 per month for small companies, €500–2,000 for larger ones; training and documents often cost extra | Companies that want purely personal support without software |
| External DPO + software (Dieter Premium) | €99 per month, €79 with annual billing — TÜV-certified DPO, documents, trainings, and website scans included | Freelancers and SMEs that want to solve the obligation and its implementation in one |
The switch itself has two cost traps. First, double payment: if the new contract starts before the old one is terminated, you pay for months twice — so clarify the notice period first. Second, hidden setup fees: some providers charge extra for familiarising themselves with your existing documentation. Ask before signing.
The roadmap: a new DPO in six to eight weeks
In practice, an orderly switch takes six to eight weeks from the decision. The four phases:
- 1Week 1 — check the contract and terminate: Look up the term and notice period in your DPO contract, terminate in writing, and announce an orderly handover.
- 2Weeks 1–3 — select the new DPO: Compare qualifications, availability, scope of services, and price. Also clarify: who handles the handover?
- 32–4 weeks in parallel — organise the handover: Transfer documents, access rights, and open matters to the new DPO — ideally with an overlap so no gap arises.
- 4On the effective date — notify and switch over: Report the new DPO to the supervisory authority, update the privacy policy and internal references, inform the team.
If your contract still runs for a while, the plan reverses: select the new DPO first, terminate at the earliest possible date, and use the remaining term as a relaxed handover window.
The handover: these records change hands
The heart of the switch is handing over the documentation. Your previous DPO has likely built up years of records that your company needs for audits, authority inquiries, and day-to-day operations. Schedule a fixed handover meeting and get the handover confirmed in writing. The documents to hand over include:
- Record of processing activities (ROPA)
- Documentation of technical and organisational measures (TOMs)
- Data protection impact assessments
- Overview of all data processing agreements
- Privacy policies and consent texts
- Employee training records
- Deletion concept
- Logs of data breaches and data subject requests
Frequently forgotten: terminating the old DPO’s remote and system access, transferring the data protection mailbox, updating the DPO details in the privacy policy, notifying the supervisory authority, informing the team and relevant service providers — and handing over open matters in documented form, not verbally. Also ask for the reverse confirmation: that the old DPO deletes your company data after the statutory retention period. After all, they themselves received sensitive information.
How switching works with Dieter
The most laborious part of a switch is rarely the termination — it is everything around it: appointment, authority notification, document migration, trainings. With Dieter, exactly that is built-in product mechanics rather than project work:
- Appointment in three guided steps: A short questionnaire generates the ready-made DPO appointment agreement, you confirm it digitally — and a TÜV-certified data protection officer from the Dieter team becomes your fixed contact person.
- Authority notification without searching: Dieter links directly to your federal state’s registration portal — all 16 are on file — and displays all the DPO data you need to enter. The notification is done in minutes.
- Existing documents move with you: Upload the ROPA, data processing agreements, TOMs, and more from your previous DPO per topic area and keep managing them. Whatever is missing or outdated, Dieter creates anew via questionnaire.
- The privacy policy switches automatically: The DPO contact details are central master data. Change them, and all affected documents update — including, via live embedding, the privacy policy directly on your website.
- Trainings with proof: Your employees receive personalised training links, confirmations are documented, and reminders and annual refreshers run automatically.
- Instead of an annual report: a continuously prioritised task list plus a data protection audit report from your DPO — evidence you can present directly if an authority asks.
Conclusion
Switching your data protection officer is easier than most people think: check the contract, secure the successor, hand over in an orderly fashion, update the authority and the privacy policy. The whole process is done in six to eight weeks and often pays for itself within the first year — through lower costs, but above all through support that actually happens in everyday operations. Those who shy away from switching keep paying, year after year, for a PDF.
Author

Sebastian Schenk
Co-Founder & CEO
Lawyer and data protection officer. Drives product vision at simply Legal and ensures Dieter is sound legally and in practice.
This article reflects the position at the date of publication. We update our content when the law changes.
Related articles

Thursday, 10 July 2025
How to create a privacy policy
Every website needs a privacy policy. It fulfils the information obligations under Art. 13 GDPR and explains which data is processed for what purpose and on what legal basis.

Thursday, 11 September 2025
Technical and organisational measures
Technical and organisational measures (TOMs) are the backbone of data protection under the GDPR. They range from technical security safeguards to organisational processes and should be reviewed and adjusted regularly.

Thursday, 23 October 2025
6 answers on the data processing agreement (DPA)
A data processing agreement (DPA) is required under the GDPR as soon as an external service provider processes personal data on your behalf. It defines responsibilities and protects against fines and loss of trust.
