It would be helpful if the Law Societal could set out the rationale for the advice 'If in doubt, firms may wish to appoint a DPO anyway on a voluntary basis', as there are strong views to the contrary. In particular, there is a requirement for independence, which will be hard to achieve in many firms (unless they opt to outsource): in 2016, the Bavarian State Commissioner for Data Protection fined an organisation for appointing its IT manager as data protection officer. It also creates other rights and obligations.

