cogito

External officers for businesses

Data protection. AI. Compliance.

cogito.consulting provides external officers in three areas. Only one of them is a role governed by law. This page explains the difference and leads to the service that fits.

In brief

Data protection, artificial intelligence and compliance are often mentioned in one breath, yet they rest on different legal foundations. The data protection officer is a role governed by Articles 37 to 39 GDPR: it must be appointed under certain conditions and carries its own statutory tasks. The AI officer and the compliance officer, by contrast, are organisational governance roles. They are not mandatory for ordinary businesses, but they bundle responsibility for duties that exist regardless — measures supporting AI literacy under the AI Regulation, and the management board’s duties of organisation and supervision in the compliance field. In all three cases the same applies: an external role does not take over the responsibility of the business. cogito.consulting is a brand of COGITO Gesellschaft für computergestützte Unternehmensorganisation mbH. Legal advice in individual cases and legal representation are provided by the law firm cogito.legal under a separate engagement.

The three roles

Which role suits a business depends on its size, activity, regulatory environment and risk profile. The roles can be filled individually or in combination.

Data protection

Governed by law

The data protection officer under Articles 37 to 39 GDPR informs, advises and monitors compliance with data protection law. In Germany, private-sector bodies generally appoint one where at least 20 people are constantly engaged in the automated processing of personal data; further mandatory cases apply irrespective of that figure.

External data protection officer

Artificial intelligence

Organisational role

The AI Regulation does not define an AI officer. It does, however, require providers and deployers to take measures supporting AI literacy, and effective human oversight for high-risk systems. A named role bundles these tasks and makes them demonstrable.

External AI officer

Compliance

Organisational role

Ordinary businesses are under no obligation to appoint a compliance officer. The management board must nonetheless organise and supervise operations properly. A compliance function coordinates risk analysis, policies, monitoring and reporting.

External compliance officer

At a glance

Data protection officer
A role governed by law with its own tasks under Article 39 GDPR. Appointment required under Article 37 GDPR and section 38 BDSG. Appointing an external person is expressly permitted under Article 37(6) GDPR.
AI officer
No statutory duty to appoint. An organisational governance role. The duties of the AI Regulation fall directly on providers and deployers.
Compliance officer
No general statutory duty to appoint. An organisational role. The duty to organise and supervise remains with the management board; section 130 OWiG covers the breach of required supervisory measures.
Common to all three
All three roles advise, coordinate, monitor and document. Operational implementation and the decision on necessary measures remain with the business.
Specially regulated roles
Money laundering officers and supervisory compliance roles in the financial sector are subject to their own requirements and must be assessed separately.
Distinction from legal advice
Legal advice in individual cases, binding legal assessments and legal representation are provided by the law firm cogito.legal under a separate engagement.

As at August 2026.

Frequently asked questions

Which of these three roles is required by law?

Only the data protection officer. Article 37 GDPR and section 38 BDSG oblige many businesses to appoint one, in particular where at least 20 people are constantly engaged in automated processing of personal data or where a data protection impact assessment is required. The AI officer and the compliance officer are organisational roles with no general statutory duty to appoint. Different requirements may apply in individual regulated sectors, for instance the money laundering officer under section 7 GwG.

Can one person hold all three roles?

That is possible and common in smaller organisations, because the subjects overlap. What matters is the independence of the data protection officer: another role must not place them in a conflict of interest, and in particular they must not themselves decide on the purposes and means of processing personal data. The allocation of roles is therefore clarified before appointment.

Does an external officer assume the responsibility of the business?

No. In all three areas the business remains responsible — as controller or processor under data protection law, as provider or deployer under the AI Regulation, and through the management board’s duties of organisation and supervision in the compliance field. The external role advises, coordinates, monitors and documents; it does not decide in place of the business and does not implement measures operationally.

Who is behind beauftragter.net?

COGITO Gesellschaft für computergestützte Unternehmensorganisation mbH, which operates as a management consultancy under the cogito.consulting brand and has supported digital projects since 1987. The same brand is used by the legally independent law firm cogito.legal, which holds it under licence and provides legal advice and representation.

How does the work begin?

With a structured review of the area in question: which processing activities, systems, processes and responsibilities exist, and what duties follow from them. The result is a prioritised overview with concrete measures. On that basis it is decided whether and to what extent ongoing external support makes sense.

Your contact

Malte Rheingans, Managing Director, cogito.consulting

Malte Rheingans

Managing Director, cogito.consulting

All three roles are coordinated from one place. For matters requiring legal advice, the law firm cogito.legal is available.

  • Certified data protection auditor (TÜV Rheinland)
  • Certified external data protection officer (TÜV Rheinland)
  • Certified data protection officer (TÜV Nord)
  • Certified AI officer (DEKRA)
  • Rechtsanwalt (German qualified lawyer)
  • Fachanwalt für IT-Recht (specialist lawyer for IT law)
  • Fachanwalt für Urheber- und Medienrecht (specialist lawyer for copyright and media law)

Legal services are provided exclusively through the law firm cogito.legal. No legal advice is offered on this page.

T +49 40 209 528 90
info@cogito.consulting

Certifications and memberships

Our consulting work is trusted by, among others

cogito.consulting

Management consultancy

We have supported digital and organisational projects since 1987. Today we advise in particular on data protection, AI governance and corporate compliance, and provide external data protection, AI and compliance functions.

cogito.consulting

cogito.legal

Legal services

A commercial law firm working exclusively for businesses. Legal advice, contract drafting and representation, in particular on data protection, AI, compliance and digital business models.

cogito.legal

cogito

Shared brand

Under the cogito brand, a specialised management consultancy and a commercial law firm work side by side – separate in law, joined in practice.

cogito.de

Let’s talk.

Not sure which role fits your business? Describe your situation and we will come back to you.

COGITO Gesellschaft für computergestützte
Unternehmensorganisation mbH Konzeption und Realisierung
Am Dreisberg 8, 33617 Bielefeld, Germany
T +49 40 209 528 90
info@cogito.consulting

We process your details solely to handle your enquiry. Further information in our privacy policy.