Search
Contact
11.03.2021 | KPMG Law Insights

MV Regional Labor Court: Conditions for the Dismissal of a Data Protection Officer

MV Regional Labor Court: Conditions for the Dismissal of a Data Protection Officer

In a nutshell

Universities and research institutions (which have more than 20 employees) are also required to appoint a data protection officer. In this decision (LAG M-V AZ: 5 Sa 108/19), the court dealt with the requirements to be met by the professional qualifications of a data protection officer and the conditions under which dismissal is possible. The court ruled that the plaintiff, who opposed his dismissal, was sufficiently qualified as a fully qualified lawyer who had apparently studied the requirements of data protection law. In addition, even after a data protection officer has been appointed, the organization continues to be the addressee of the obligations under data protection laws (data protection officer). The data privacy officer acts largely independently as an internal control body and primarily provides assistance in implementing data privacy requirements. An erroneous decision from 2007, is not sufficient to establish unreliability as a data protection officer.

Background

The defendant university hospital employed the plaintiff as data protection officer. At the beginning of 2018, the defendant university hospital and the plaintiff argued about whether he, as data protection officer, should already have done more for the implementation of the GDPR that followed in May 2018. The data protection officer drew attention to the fact that only with the implementation of state law and the regulation of area-specific requirements for data protection could the implementation be complete. Since the basic regulations have been clear since the adoption of the GDPR, the university hospital also doubted the suitability of the data protection officer because of these statements. The latter had indeed dealt with the requirements of the GDPR, as suggested by an article on the requirements published in a trade journal in 2017. However, he had no special qualifications (beyond being a fully qualified lawyer) to adequately fulfill the role of data protection officer.

The data protection officer had participated in the establishment of committees on data protection and organized training sessions for the hospital’s employees. In his understanding, the role of the data protection officer is that of a supervisory body. In no way was he himself – with around 10,000 data processing operations per day – responsible for implementing the requirements of the GDPR in detail. In addition, he had professionally excellent employees.

The university hospital dismissed the man as data protection officer in February, citing a lack of implementation efforts to date and an incorrect assessment in 2007 that had cost the university hospital several hundred thousand euros and raised the question of whether he was reliable at all. In August 2018, after the introduction of the GDPR, the hospital was reprimanded by the State Data Protection Commissioner for an organizational program that had been used internally for several years. The plaintiff had not drawn attention to the problems during his time as data protection officer.

The parties disputed what qualifications a data protection officer must have and whether the man’s conduct was sufficient for dismissal.

Decision

The court essentially upheld the plaintiff. The dismissal was invalid. The evaluation standards for this decision are similar before and after the introduction of the GDPR in May 2018, even if they were based on different legal bases.

  1. Professional qualification of a data protection officer

Prior to May 2018, the state law required that the data protection officer had the necessary expertise and reliability to perform his or her duties (Section 20 (1) sentence 3 DSG M-V old version). According to Art. 37 GDPR, he must have sufficient professional qualification and expertise in data protection law. No specific training or qualification is required. Specifically, the requirements must be based on the size of the organization and the scope and sensitivity of the data processing operations. The plaintiff, as a fully qualified lawyer who, as evidenced by the technical essay, has in any case dealt with the subject matter, is in principle appropriately qualified. In addition, he can rely on professionally qualified employees.

  1. Dismissal due to lack of measures for implementation

A data protection officer is to be distinguished from the data protection officer (of the organization). The data protection officer must verify compliance with the requirements and, according to the conception of the laws, holds an independent position. Under both the old (Section 20 (2) DSG M-V old version) and the new (Section 6 (4) sentence 1 BDSG) legal situation, dismissal requires serious misconduct with corresponding application of Section 626 BGB. In any case, the measures taken by the plaintiff to monitor the introduction were not so faulty that he seriously breached his duties. It is not sufficient for such a breach of duty that the plaintiff did not point out the data protection problems of an internal organizational program that he had not introduced himself. Finally, the data protection officer cannot oversee every data processing operation.

  1. Dismissal due to lack of reliability

An employee’s conduct prior to his or her appointment as a DPO has an impact on the employee’s reliability assessment. However, the defendant did not provide sufficiently concrete evidence that such a serious doubt of reliability could be identified in the erroneous assessment of a situation in 2007, which in retrospect turned out to be disadvantageous for the university hospital. Suspicion of intentional injury is not enough unless it is properly substantiated.

What can readers take away?

  1. A data protection officer does not have to have any particular professional qualifications. In detail, he can also rely on his employees.
  2. The prerequisite for dismissal is serious misconduct due to the independent position of the data protection officer as a supervisory body (analogous to 626 BGB).
  3. Reliability may also be due to misconduct prior to commencing work as a data protection officer.

Explore #more

16.04.2026 | KPMG Law Insights

Index clauses in commercial leases: BGH ruling opens up clawback risks for landlords

Value assurance provisions in the form of index clauses in standard commercial leases are not only subject to the restrictions of the Price Clause Act,…

16.04.2026 | In the media

Guest article in Beschaffung aktuell: Faster procurement for the Bundeswehr

With the Planning and Procurement Acceleration Act, the German government wants to make Bundeswehr procurement significantly faster. The temporary special law simplifies procurement procedures, allows…

09.04.2026 | Press releases

KPMG Law strengthens its insurance practice in Cologne with Dr. Julia Faenger

Since April 1, 2026, Dr. Julia Faenger, LL.M., has been strengthening the insurance law advice of KPMG Law Rechtsanwaltsgesellschaft mbH (KPMG Law) in Cologne as…

08.04.2026 | KPMG Law Insights

New Package Travel Directive 2026: Complaint management becomes mandatory

The EU is reforming the Package Travel Directive. The amendments were adopted by the European Parliament and Council in March 2026 and are expected to…

02.04.2026 | KPMG Law Insights

Building Modernization Act (GMG): What is now important for companies

The planned Building Modernization Act (GMG) is set to replace significant parts of the previous Building Energy Act (GEG). Companies in the real estate industry,…

01.04.2026 | In the media

Manager Magazin: KPMG Law in first place for legal advice

Every two years, Manager Magazin, together with the Wissenschaftliche Gesellschaft für Management und Beratung (WGMB), awards Germany’s best auditors with a “Best-in-Class” seal and evaluates

27.03.2026 | KPMG Law Insights

Special Infrastructure Fund and State Aid Law: Orientation for Funding Practice and Planning

The special fund “Infrastructure and Climate Neutrality” (SVIK) also entails considerable responsibility under state aid law for federal states, municipalities and recipients of funds. Anyone

23.03.2026 | Deal Notifications

KPMG Law, KPMG Law AT as well as KPMG in Germany and KPMG in Austria advise GOLDBECK GmbH on the acquisition of 50 percent of the shares in ZAUNERGROUP Holding GmbH

KPMG Law Rechtsanwaltsgesellschaft mbH (KPMG Law) and Buchberger Ettmayer Rechtsanwälte GmbH (KPMG Law AT) as well as KPMG AG Wirtschaftsprüfungsgesellschaft (KPMG in Germany) and KPMG…

19.03.2026 | KPMG Law Insights

Business Judgement Rule in the use of AI: how governing bodies are liable for decisions

If an AI provides the basis for business decisions, the people responsible are liable, not the machine. This makes the use of artificial intelligence risky…

16.03.2026 | KPMG Law Insights

KPIs in the legal department: How legal becomes strategically effective through control, transparency and data analysis

Today, legal departments are facing a strategic turning point: they must reliably hedge risks, but at the same time enable speed, control costs and make…

Contact

Julia Hornbostel

Senior Associate

Fuhlentwiete 5
20355 Hamburg

Tel.: +49 40 3609945162
jhornbostel@kpmg-law.com

© 2026 KPMG Law Rechtsanwaltsgesellschaft mbH, associated with KPMG AG Wirtschaftsprüfungsgesellschaft, a public limited company under German law and a member of the global KPMG organisation of independent member firms affiliated with KPMG International Limited, a Private English Company Limited by Guarantee. All rights reserved. For more details on the structure of KPMG’s global organisation, please visit https://home.kpmg/governance.

KPMG International does not provide services to clients. No member firm is authorised to bind or contract KPMG International or any other member firm to any third party, just as KPMG International is not authorised to bind or contract any other member firm.

Scroll