Häufig gestellte Fragen
Is a data protection officer mandatory when using an ERP system?
A data protection officer is not mandatory because of the ERP use itself but due to company-related criteria: under Section 38 BDSG (German Federal Data Protection Act), an appointment is required as soon as, as a rule, at least 20 people are permanently engaged in the automated processing of personal data; independently of this, an appointment can also become necessary under Article 37 GDPR in the case of particularly high-risk or extensive processing. Since an ERP is used by many departments, the constant handling of personal data very often reaches this threshold in mid-sized companies. A politically debated relaxation of this threshold rule had not yet come into force as of mid-2026, which is why the existing value of 20 people continues to apply. What matters for the assessment is always the company as a whole, not just the number of ERP users.
Which contract is required if the ERP runs as a cloud solution hosted by the vendor?
If an ERP is operated as a SaaS or cloud solution, the vendor processes personal data on behalf of the company, which thus remains the controller within the meaning of the GDPR. In this case, a data processing agreement is required under Article 28 GDPR, which regulates, among other things, the subject matter, duration, nature and purpose of the processing, the technical and organisational measures and the handling of subcontractors. If such a contract is missing or incomplete, this in itself constitutes an independent data protection violation, regardless of whether a data breach occurs. Companies should therefore check before implementation whether the vendor provides a robust data processing agreement including an up-to-date list of sub-processors.
May personal ERP data be processed by a US cloud provider?
Processing by US providers is possible but requires a valid legal basis for the transfer to a third country. Since 10 July 2023, the adequacy decision on the EU-US Data Privacy Framework has permitted data flows to US companies certified under this framework, and the General Court of the European Union upheld the decision at first instance in September 2025. Nevertheless, some residual uncertainty remains, as an appeal against the judgment has been lodged with the European Court of Justice and the framework's viability also depends on the US side maintaining the guarantees it has given. For sensitive data, EU hosting is therefore advisable, or at least additional safeguards via standard contractual clauses under Article 46 GDPR as a fallback option.
How do you implement the right to erasure in an ERP system?
A staged deletion concept makes sense, in which data is first blocked — that is, withdrawn from active use by removing permissions and visibility — and then automatically deleted or anonymised once all statutory retention periods have expired. Modern ERP systems offer dedicated deletion modules for this with data categories, deadlines, blocking flags and logging of deletion operations. Field-level differentiation is important because one person can simultaneously have freely deletable marketing data and accounting records subject to retention obligations in the system. In practice, the specific implementation varies depending on the industry, company size and degree of customization of the respective ERP setup.
How do you resolve the conflict between the obligation to erase and tax retention obligations?
The apparent contradiction can be resolved in a legally sound way because the GDPR itself recognises retention obligations: under Article 6(1)(c), processing is lawful insofar as it is necessary for compliance with a legal obligation. Since 2025, accounting records and invoices have generally been subject to an eight-year retention period under the German Commercial Code (HGB) and the German Fiscal Code (AO), while ledgers, inventories, balance sheets and annual financial statements must still be retained for ten years, and these obligations take precedence over a data subject's erasure request for the respective records. In practice, the affected data is therefore not deleted but blocked for ongoing use and only removed after the period expires, while freely available data such as contact or marketing information can be deleted immediately. An ERP with blocking mechanisms and deadline-driven deletion workflows can map this staged process without the need for permanent manual intervention.
What fines can be imposed for GDPR violations in the ERP environment?
Article 83 of the GDPR provides for a two-tier system of fines: formal violations, such as a missing data processing agreement or an incomplete record of processing activities, can be penalised with up to 10 million euros or 2 percent of worldwide annual turnover. More serious substantive violations of the processing principles or data subject rights carry fines of up to 20 million euros or 4 percent of worldwide annual turnover, with the higher amount applying in each case. Since an ERP often bundles large volumes of personal data centrally, a violation can affect many data subjects and carry correspondingly heavy weight. In addition to the fine, claims for damages by affected persons and reputational damage can also arise.
