Switching your data protection officer: costs, notice periods, termination letter template and handover checklist
Poor availability, high costs, one PDF report per year: there are good reasons to switch your data protection officer. Legally it is straightforward, as long as termination, handover and the notification to the supervisory authority happen in the right order. The complete roadmap with a termination letter template, a handover checklist and the mistakes that happen most often when switching.

Table of contents
- Context: when switching pays off
- Who needs a data protection officer at all?
- Terminating an external DPO: contract and notice periods
- Special case internal DPO: the special protection
- What does a data protection officer cost?
- The roadmap: a new DPO in six to eight weeks
- The handover: these records change hands
- Do not forget the notification to the supervisory authority
- The most common mistakes when switching
- How switching works with Dieter
- Conclusion
Context: when switching pays off
In many companies, the data protection officer is a line item that gets purchased once and then not questioned again for years. Yet quality and price vary considerably across the market. If one or more of the following points apply to your current arrangement, a comparison is worth your time:
- Availability: You regularly wait several days for answers to your questions, and there is no fixed contact person.
- Purely reactive: Your DPO gets in touch once a year for the report, but never on their own initiative when the legal situation changes.
- Outdated documentation: The record of processing activities and TOM no longer reflect how your company works today.
- No training: Your employees have not been trained in over a year, or training costs extra.
- New topics missing: On AI tools, cloud services or the EU AI Act, you get no reliable answer.
- Value for money: You pay an annual flat fee whose main deliverable is essentially a PDF.
The good news: switching an external data protection officer is legally straightforward. It only needs a clean sequence so that no gap arises and the documentation changes hands completely.
Who needs a data protection officer at all?
Before you switch, it is worth taking a quick look at the obligation itself. In Germany, you must designate a data protection officer if one of the following cases applies:
- At least 20 people in your company are permanently engaged in the automated processing of personal data (§ 38 of the German Federal Data Protection Act, BDSG). This counts everyone who regularly works with personal data on a computer, including part-time staff and freelancers.
- You carry out processing operations that require a data protection impact assessment (DPIA), or you process data on a commercial basis for the purpose of transfer or for market and opinion research. In that case the obligation applies regardless of headcount.
- Your core activity consists of the extensive, regular monitoring of individuals or the extensive processing of particularly sensitive data (Art. 37 GDPR).
Whether the obligation applies to you is clarified by the obligation check on the external data protection officer page. Which supervisory authority is responsible for you depends on the German federal state in which your company is based.
Terminating an external DPO: contract and notice periods
An external data protection officer works on the basis of a service contract. Unlike an internal DPO, there is no statutory protection against removal: the terms and notice periods set out in the contract simply apply. Terms of twelve to 24 months with automatic renewal and notice periods of one to three months to the end of a month or quarter are common. So check your contract first, otherwise you may well end up paying for another year.
The order matters: only terminate once the successor is in place, or plan the notice period as your handover window. Companies subject to the designation obligation must never be without a data protection officer at any point. An overlap of two to four weeks between the old and the new DPO is ideal for handling the handover in an orderly way.
Send the termination by email with a read receipt and additionally by post or in whatever form the contract prescribes. Some contracts require the written form with a signature.
Special case internal DPO: the special protection
Things are quite different if your current data protection officer is one of your own employees. Where a designation obligation exists, internal DPOs enjoy strong statutory protection (§ 38(2) in conjunction with § 6(4) BDSG): removal is only permitted for good cause in accordance with § 626 of the German Civil Code (BGB), and the employment relationship enjoys special protection against dismissal during the role and for one year afterwards.
Good cause can include, for instance, a persistent breach of DPO duties, a conflict of interest or a lack of expertise. Whether the mere wish to switch to an external provider in future is enough is legally disputed; you should seek advice before any removal. The consensual route, on the other hand, is unproblematic: many internal DPOs are happy to give up the role, because it is hard to manage alongside their day-to-day work.
What does a data protection officer cost?
The costs depend on the model. For orientation, here are the typical ranges as cited, among others, by the German professional association of data protection officers (BvD):
| Model | Typical costs | Suitable for |
|---|---|---|
| Internal DPO | A share of working time plus further training, realistically several thousand euros per year, plus the special protection against dismissal | Larger companies with in-house data protection expertise and enough capacity |
| External DPO (traditional) | €150 to €300 per month for small companies, €500 to €2,000 for larger ones; training and documents often only at an extra charge | Companies that want purely personal support without software |
| External DPO + software (Dieter Premium) | €99 per month, €79 with annual billing; TÜV-certified DPO, documents, training and website scans included | Self-employed people and SMEs that want to solve the obligation and its implementation in one go |
The switch itself has two cost traps. First, double payment: anyone who starts the new contract before the old one has been terminated pays for months twice. So clarify the notice period first. Second, hidden setup costs: some providers charge extra for familiarising themselves with your existing documentation. Ask about this before signing the contract.
The roadmap: a new DPO in six to eight weeks
In practice, an orderly switch takes six to eight weeks, counted from the decision. The four phases:
If your contract still runs for longer, the plan reverses: select the new DPO first, give notice at the earliest possible date and use the remaining term as a relaxed handover window.
The handover: these records change hands
The heart of the switch is the handover of the documentation. Your previous DPO has most likely built up records over years that your company needs for audits, enquiries from the authorities and day-to-day operations. Schedule a fixed handover date and have the handover confirmed in writing:
- Verzeichnis der Verarbeitungstätigkeiten (VVT)
- Dokumentation der TOMs
- Datenschutz-Folgenabschätzungen
- Übersicht aller AV-Verträge
- Datenschutzerklärungen und Einwilligungstexte
- Schulungsnachweise der Mitarbeitenden
- Löschkonzept
- Protokolle zu Datenpannen und Betroffenenanfragen
- Remote- und Systemzugänge des alten DSB beenden
- Datenschutz-Postfach (z. B. datenschutz@…) übertragen
- DSB-Angaben in der Datenschutzerklärung aktualisieren
- Meldung an die Aufsichtsbehörde (Art. 37 Abs. 7 DSGVO)
- Team und relevante Dienstleister informieren
- Offene Vorgänge dokumentiert übergeben, nicht mündlich
Two points deserve particular attention. First, access rights: external DPOs often have remote access, a dedicated data protection mailbox or accounts in your systems. Terminate or transfer all of them. Second, the reverse direction: have the old DPO confirm that they will delete your company data after the statutory retention period. After all, they themselves were a recipient of sensitive information.
The most common mistakes when switching
- Terminating without a successor. A gap arises between the end of the contract and the new designation. Where a designation obligation exists, that is a violation, and experience shows that this is exactly when the data subject request comes in.
- Missing the notice period. The contract renews for another year, and you pay two DPOs in parallel. Read the contract before you decide.
- Verbal handover. Without a handover record, the training records or the correspondence with the authority will be missing later, and nobody can say where they went.
- Access rights left open. The old DPO still has access to the data protection mailbox months after the contract ended.
- Forgetting the notification. The supervisory authority still has the old DPO on file, and letters from the authority go nowhere.
- Privacy policy not updated. The website still names the old contact person. A violation of Art. 37(7) GDPR that every visitor can spot.
How switching works with Dieter
The most laborious part of a switch is rarely the termination itself but everything around it: designation, notification to the authority, moving documents, training. With Dieter, exactly that is not project work but built-in product mechanics:
- Designation in three guided steps: A short questionnaire generates the ready-made agreement on the designation of the data protection officer, you confirm it digitally, and a TÜV-certified data protection officer from the Dieter team becomes your fixed contact person.
- Notification to the authority without searching: Dieter links directly to the notification portal of your federal state, all 16 are on file, and shows you all the DPO details you need to enter, ready to go. The notification is done in a few minutes.
- Existing documents move with you: You upload the record of processing activities, data processing agreements, TOM and the like from your previous DPO by topic area and keep managing them. Whatever is missing or outdated, Dieter creates anew via questionnaire.
- The privacy policy switches automatically with you: The DPO contact details are central master data. If you change them, all affected documents update, and via live embedding so does the privacy policy directly on your website.
- Training including records: Your employees receive personalised training links, confirmations are documented, and reminders and annual refreshers run automatically.
- Instead of an annual report: a continuously prioritised task list plus a data protection audit report from your DPO. Evidence you can present directly if an authority asks.
Conclusion
Switching your data protection officer is easier than most people think: check the contract, secure the successor, hand over in an orderly way, update the authority and the privacy policy. The whole process is done in six to eight weeks and often pays for itself within the first year, through lower costs, but above all through support that actually happens in everyday operations. Those who shy away from switching otherwise keep paying, year after year, for a PDF.
Author

Sebastian Schenk
Co-Founder & CEO
Lawyer and data protection officer. Drives product vision at simply Legal and ensures Dieter is sound legally and in practice.
Sources and further reading
- Art. 37 GDPR: Designation of the data protection officer (full text)
- § 38 BDSG: Data protection officers of private bodies (full text, in German)
- § 6 BDSG: Protection of the DPO against removal and dismissal (full text, in German)
- Dr. Datenschutz: Will the obligation to designate a DPO fall by the end of 2026? (June 2026, in German)
- BvD: External data protection officer, cost overview (in German)
- DSN Group: €51,000 fine against Facebook for failure to notify the DPO (in German)
- LfDI Hessen: Data protection officer only required from 20 persons (in German)
Frequently asked questions
How long is the notice period for an external data protection officer?
There is no statutory notice period. The service contract applies; one to three months to the end of a month or quarter is common, with terms of twelve to 24 months and automatic renewal. Check the renewal clause especially carefully, it is the most common cost trap.
May I be without a data protection officer temporarily during the switch?
Not if a designation obligation exists. In that case the new DPO must be designated before the old one leaves. Plan an overlap of two to four weeks. Companies without a designation obligation are free to decide, but must continue to meet all other GDPR obligations.
Do I have to notify the supervisory authority of the switch?
Yes. Art. 37(7) GDPR obliges you to communicate the contact details of the data protection officer to the supervisory authority. When switching, you notify the new DPO via the online form of your federal state; this replaces the old notification. In addition, the contact details in the privacy policy must be updated.
Can I simply remove my internal data protection officer and designate an external one?
Where a designation obligation exists, only for good cause (§ 38(2) in conjunction with § 6(4) BDSG). Whether the mere wish for an external provider is enough is disputed. The safe route is for the internal DPO to give up the role by mutual agreement, recorded in writing.
Which records does the old data protection officer have to hand over to me?
Everything they kept for your company: the record of processing activities, TOM documentation, data processing agreements, training records, activity reports, documentation of data subject requests and data breaches, and the correspondence with the supervisory authority. The records belong to you, not to the DPO. Have the handover and the later deletion of their copies confirmed.
What does switching to Dieter cost?
Dieter Premium with a TÜV-certified external data protection officer costs €99 per month or €79 with annual billing. If your current DPO contract is still running, Dieter is free of charge until it ends, so that you do not pay twice. There are no setup costs.
This article reflects the position at the date of publication. We update our content when the law changes.
Related articles

Thursday, 10 July 2025
How to create a privacy policy: mandatory information, examples and common mistakes
Every website needs a privacy policy, because even loading a page processes personal data. This guide shows which information Art. 13 GDPR requires, how to describe services such as analytics, newsletters or Google Fonts correctly, what the TDDDG means for cookies and which mistakes most often lead to cease-and-desist letters.

Thursday, 11 September 2025
Technical and organisational measures (TOM): What Art. 32 GDPR requires and how small businesses implement it
Technical and organisational measures (TOM) are the part of the GDPR that decides over fines and data breaches. This guide explains the requirements of Art. 32 GDPR, the classic TOM catalogue with examples, how to rate your protection needs, which measures are realistic for a company of ten people and how to build the TOM document that authorities and clients want to see.

Thursday, 23 October 2025
Data processing agreement (DPA): when you need one, what it must contain and when you don’t
A data processing agreement is mandatory as soon as a service provider processes personal data on your behalf: hosting, cloud, newsletters, CRM. With tax advisers, lawyers or banks, on the other hand, you don’t need one. This guide explains how to tell the difference, the mandatory contents under Art. 28 GDPR, how to deal with sub-processors and US providers, and how to check a provider’s DPA in ten minutes.
