Dieter
← All articlesData protection explained

Switching your data protection officer: costs, notice periods, termination letter template and handover checklist

Poor availability, high costs, one PDF report per year: there are good reasons to switch your data protection officer. Legally it is straightforward, as long as termination, handover and the notification to the supervisory authority happen in the right order. The complete roadmap with a termination letter template, a handover checklist and the mistakes that happen most often when switching.

Sebastian SchenkLegally reviewed by Franziska Breidenbach
Last reviewed: Thursday, 17 September 2026
Switching your data protection officer: costs, notice periods, termination letter template and handover checklist

Table of contents

  1. Context: when switching pays off
  2. Who needs a data protection officer at all?
  3. Terminating an external DPO: contract and notice periods
  4. Special case internal DPO: the special protection
  5. What does a data protection officer cost?
  6. The roadmap: a new DPO in six to eight weeks
  7. The handover: these records change hands
  8. Do not forget the notification to the supervisory authority
  9. The most common mistakes when switching
  10. How switching works with Dieter
  11. Conclusion

Context: when switching pays off

In many companies, the data protection officer is a line item that gets purchased once and then not questioned again for years. Yet quality and price vary considerably across the market. If one or more of the following points apply to your current arrangement, a comparison is worth your time:

  • Availability: You regularly wait several days for answers to your questions, and there is no fixed contact person.
  • Purely reactive: Your DPO gets in touch once a year for the report, but never on their own initiative when the legal situation changes.
  • Outdated documentation: The record of processing activities and TOM no longer reflect how your company works today.
  • No training: Your employees have not been trained in over a year, or training costs extra.
  • New topics missing: On AI tools, cloud services or the EU AI Act, you get no reliable answer.
  • Value for money: You pay an annual flat fee whose main deliverable is essentially a PDF.

The good news: switching an external data protection officer is legally straightforward. It only needs a clean sequence so that no gap arises and the documentation changes hands completely.

Who needs a data protection officer at all?

Before you switch, it is worth taking a quick look at the obligation itself. In Germany, you must designate a data protection officer if one of the following cases applies:

  • At least 20 people in your company are permanently engaged in the automated processing of personal data (§ 38 of the German Federal Data Protection Act, BDSG). This counts everyone who regularly works with personal data on a computer, including part-time staff and freelancers.
  • You carry out processing operations that require a data protection impact assessment (DPIA), or you process data on a commercial basis for the purpose of transfer or for market and opinion research. In that case the obligation applies regardless of headcount.
  • Your core activity consists of the extensive, regular monitoring of individuals or the extensive processing of particularly sensitive data (Art. 37 GDPR).

Whether the obligation applies to you is clarified by the obligation check on the external data protection officer page. Which supervisory authority is responsible for you depends on the German federal state in which your company is based.

Terminating an external DPO: contract and notice periods

An external data protection officer works on the basis of a service contract. Unlike an internal DPO, there is no statutory protection against removal: the terms and notice periods set out in the contract simply apply. Terms of twelve to 24 months with automatic renewal and notice periods of one to three months to the end of a month or quarter are common. So check your contract first, otherwise you may well end up paying for another year.

The order matters: only terminate once the successor is in place, or plan the notice period as your handover window. Companies subject to the designation obligation must never be without a data protection officer at any point. An overlap of two to four weeks between the old and the new DPO is ideal for handling the handover in an orderly way.

Send the termination by email with a read receipt and additionally by post or in whatever form the contract prescribes. Some contracts require the written form with a signature.

Special case internal DPO: the special protection

Things are quite different if your current data protection officer is one of your own employees. Where a designation obligation exists, internal DPOs enjoy strong statutory protection (§ 38(2) in conjunction with § 6(4) BDSG): removal is only permitted for good cause in accordance with § 626 of the German Civil Code (BGB), and the employment relationship enjoys special protection against dismissal during the role and for one year afterwards.

Good cause can include, for instance, a persistent breach of DPO duties, a conflict of interest or a lack of expertise. Whether the mere wish to switch to an external provider in future is enough is legally disputed; you should seek advice before any removal. The consensual route, on the other hand, is unproblematic: many internal DPOs are happy to give up the role, because it is hard to manage alongside their day-to-day work.

What does a data protection officer cost?

The costs depend on the model. For orientation, here are the typical ranges as cited, among others, by the German professional association of data protection officers (BvD):

ModelTypical costsSuitable for
Internal DPOA share of working time plus further training, realistically several thousand euros per year, plus the special protection against dismissalLarger companies with in-house data protection expertise and enough capacity
External DPO (traditional)€150 to €300 per month for small companies, €500 to €2,000 for larger ones; training and documents often only at an extra chargeCompanies that want purely personal support without software
External DPO + software (Dieter Premium)€99 per month, €79 with annual billing; TÜV-certified DPO, documents, training and website scans includedSelf-employed people and SMEs that want to solve the obligation and its implementation in one go

The switch itself has two cost traps. First, double payment: anyone who starts the new contract before the old one has been terminated pays for months twice. So clarify the notice period first. Second, hidden setup costs: some providers charge extra for familiarising themselves with your existing documentation. Ask about this before signing the contract.

The roadmap: a new DPO in six to eight weeks

In practice, an orderly switch takes six to eight weeks, counted from the decision. The four phases:

1
Woche 1
Vertrag prüfen und kündigen
Laufzeit und Kündigungsfrist im DSB-Vertrag nachschlagen, schriftlich kündigen und eine geordnete Übergabe ankündigen.
2
Woche 1–3
Neuen DSB auswählen
Qualifikation, Erreichbarkeit, Leistungsumfang und Preis vergleichen. Auch klären: Wer übernimmt die Übergabe?
3
2–4 Wochen parallel
Übergabe organisieren
Dokumente, Zugänge und offene Vorgänge an den neuen DSB übergeben — idealerweise mit Überlappung, damit keine Lücke entsteht.
4
Zum Stichtag
Melden und umstellen
Neuen DSB der Aufsichtsbehörde mitteilen, Datenschutzerklärung und interne Verweise aktualisieren, Team informieren.
The switching roadmap: four phases, no gap in the designation.

If your contract still runs for longer, the plan reverses: select the new DPO first, give notice at the earliest possible date and use the remaining term as a relaxed handover window.

The handover: these records change hands

The heart of the switch is the handover of the documentation. Your previous DPO has most likely built up records over years that your company needs for audits, enquiries from the authorities and day-to-day operations. Schedule a fixed handover date and have the handover confirmed in writing:

Dokumente, die der alte DSB übergibt
  • Verzeichnis der Verarbeitungstätigkeiten (VVT)
  • Dokumentation der TOMs
  • Datenschutz-Folgenabschätzungen
  • Übersicht aller AV-Verträge
  • Datenschutzerklärungen und Einwilligungstexte
  • Schulungsnachweise der Mitarbeitenden
  • Löschkonzept
  • Protokolle zu Datenpannen und Betroffenenanfragen
!Wird oft vergessen
  • Remote- und Systemzugänge des alten DSB beenden
  • Datenschutz-Postfach (z. B. datenschutz@…) übertragen
  • DSB-Angaben in der Datenschutzerklärung aktualisieren
  • Meldung an die Aufsichtsbehörde (Art. 37 Abs. 7 DSGVO)
  • Team und relevante Dienstleister informieren
  • Offene Vorgänge dokumentiert übergeben, nicht mündlich
The handover checklist: on the left the mandatory documents, on the right the points that get lost in everyday business.

Two points deserve particular attention. First, access rights: external DPOs often have remote access, a dedicated data protection mailbox or accounts in your systems. Terminate or transfer all of them. Second, the reverse direction: have the old DPO confirm that they will delete your company data after the statutory retention period. After all, they themselves were a recipient of sensitive information.

Do not forget the notification to the supervisory authority

The most frequently overlooked step comes at the end: under Art. 37(7) GDPR you must publish the contact details of the new data protection officer and communicate them to the supervisory authority. When switching, that means notifying the new DPO and thereby replacing the old notification. The supervisory authorities of all German federal states provide online forms for this purpose. A notification within about two weeks of the switch is recommended.

A well-known case shows that this is no paper tiger: the Hamburg supervisory authority imposed a fine of €51,000 on Facebook Germany because the authority had not been notified of the new data protection officer. Under Art. 83(4) GDPR, the range of fines for this violation extends to €10 million or 2 percent of worldwide annual turnover.

  • Supervisory authority: Notify the new DPO via the online portal of your federal state.
  • Privacy policy: Update the DPO contact details on your website; they are a mandatory disclosure in the privacy policy.
  • Internally: Inform the team and update notices and intranet entries so that data subject requests reach the right person.

The most common mistakes when switching

  • Terminating without a successor. A gap arises between the end of the contract and the new designation. Where a designation obligation exists, that is a violation, and experience shows that this is exactly when the data subject request comes in.
  • Missing the notice period. The contract renews for another year, and you pay two DPOs in parallel. Read the contract before you decide.
  • Verbal handover. Without a handover record, the training records or the correspondence with the authority will be missing later, and nobody can say where they went.
  • Access rights left open. The old DPO still has access to the data protection mailbox months after the contract ended.
  • Forgetting the notification. The supervisory authority still has the old DPO on file, and letters from the authority go nowhere.
  • Privacy policy not updated. The website still names the old contact person. A violation of Art. 37(7) GDPR that every visitor can spot.

How switching works with Dieter

The most laborious part of a switch is rarely the termination itself but everything around it: designation, notification to the authority, moving documents, training. With Dieter, exactly that is not project work but built-in product mechanics:

  • Designation in three guided steps: A short questionnaire generates the ready-made agreement on the designation of the data protection officer, you confirm it digitally, and a TÜV-certified data protection officer from the Dieter team becomes your fixed contact person.
  • Notification to the authority without searching: Dieter links directly to the notification portal of your federal state, all 16 are on file, and shows you all the DPO details you need to enter, ready to go. The notification is done in a few minutes.
  • Existing documents move with you: You upload the record of processing activities, data processing agreements, TOM and the like from your previous DPO by topic area and keep managing them. Whatever is missing or outdated, Dieter creates anew via questionnaire.
  • The privacy policy switches automatically with you: The DPO contact details are central master data. If you change them, all affected documents update, and via live embedding so does the privacy policy directly on your website.
  • Training including records: Your employees receive personalised training links, confirmations are documented, and reminders and annual refreshers run automatically.
  • Instead of an annual report: a continuously prioritised task list plus a data protection audit report from your DPO. Evidence you can present directly if an authority asks.

Conclusion

Switching your data protection officer is easier than most people think: check the contract, secure the successor, hand over in an orderly way, update the authority and the privacy policy. The whole process is done in six to eight weeks and often pays for itself within the first year, through lower costs, but above all through support that actually happens in everyday operations. Those who shy away from switching otherwise keep paying, year after year, for a PDF.

Author

Sebastian Schenk

Co-Founder & CEO

Lawyer and data protection officer. Drives product vision at simply Legal and ensures Dieter is sound legally and in practice.

Sources and further reading

Frequently asked questions

How long is the notice period for an external data protection officer?

There is no statutory notice period. The service contract applies; one to three months to the end of a month or quarter is common, with terms of twelve to 24 months and automatic renewal. Check the renewal clause especially carefully, it is the most common cost trap.

May I be without a data protection officer temporarily during the switch?

Not if a designation obligation exists. In that case the new DPO must be designated before the old one leaves. Plan an overlap of two to four weeks. Companies without a designation obligation are free to decide, but must continue to meet all other GDPR obligations.

Do I have to notify the supervisory authority of the switch?

Yes. Art. 37(7) GDPR obliges you to communicate the contact details of the data protection officer to the supervisory authority. When switching, you notify the new DPO via the online form of your federal state; this replaces the old notification. In addition, the contact details in the privacy policy must be updated.

Can I simply remove my internal data protection officer and designate an external one?

Where a designation obligation exists, only for good cause (§ 38(2) in conjunction with § 6(4) BDSG). Whether the mere wish for an external provider is enough is disputed. The safe route is for the internal DPO to give up the role by mutual agreement, recorded in writing.

Which records does the old data protection officer have to hand over to me?

Everything they kept for your company: the record of processing activities, TOM documentation, data processing agreements, training records, activity reports, documentation of data subject requests and data breaches, and the correspondence with the supervisory authority. The records belong to you, not to the DPO. Have the handover and the later deletion of their copies confirmed.

What does switching to Dieter cost?

Dieter Premium with a TÜV-certified external data protection officer costs €99 per month or €79 with annual billing. If your current DPO contract is still running, Dieter is free of charge until it ends, so that you do not pay twice. There are no setup costs.

This article reflects the position at the date of publication. We update our content when the law changes.

Related articles

Dieter helps you avoid fines

Ready to go

Dieter takes care of your data protection.

Get started without a demo call and set up your data protection in a few steps.

Get started