CDPO / DPO as a Service
An external Data Protection Officer who truly knows your organisation
A certified DPO on subscription, interim or per project. Independent, legally grounded, and technical enough to discuss details with your IT department.
When do you need a DPO?
Under Article 37 GDPR a Data Protection Officer is mandatory when you:
- are a public authority or body;
- carry out, as a core activity, regular and systematic monitoring of individuals on a large scale;
- process, as a core activity, special categories of data (such as health data) or criminal-offence data on a large scale.
Many organisations appoint a DPO or privacy officer even without an obligation, so that regulators, clients and staff have a clear point of contact.
Three models
DPO as a Service
A dedicated external DPO on subscription, with a fixed number of hours per month and one point of contact. We are registered with the supervisory authority and report to the highest management level.
Interim DPO / privacy lawyer
Temporary capacity for vacancies, leave, reorganisations or backlogs. Available at short notice, with handover to your permanent team.
Projects
Defined engagements such as a baseline assessment, a DPIA programme, a breach procedure or an AI Act inventory of your systems.
What we do for you
- GDPR / BIO baseline and privacy maturity assessment
- Setting up and maintaining records of processing activities
- Data Protection Impact Assessments (DPIAs)
- Reviewing and drafting data processing agreements
- Breach procedure and handling, including 72-hour notification
- Privacy notices and transparency obligations
- Privacy by design for new systems and platforms
- Advice on procurement, tenders and vendor selection
- Review of employee monitoring and logging (e.g. Microsoft 365 / Defender)
- EU AI Act: inventory, risk classification and AI literacy
- Reporting to the board, management team and in-control statements
- Awareness training for staff and management
Independent, and it stays that way
A DPO may not receive instructions on how to perform their tasks and must not have a conflict of interest (Article 38 GDPR). An external DPO is by definition outside your line organisation, so we can advise critically, even when that is uncomfortable.
Frequently asked questions
What does an external DPO cost?
That depends on the scale and risk profile of your processing. After an introduction call you receive a proposal with a fixed monthly fee or a fixed project price. There is no open-ended billing.
How quickly can you start?
For interim engagements usually within a few weeks. In case of an acute data breach we can help immediately.
Do you work alongside our own privacy team?
Yes. We reinforce existing teams as often as we fill the role entirely.
Can you assess technical measures as well?
Yes. We also assess logging, identity and access management, encryption and cloud configuration (Azure, AWS). That is often what separates a GDPR file on paper from demonstrable compliance.
Curious where your organisation stands?
Start with a no-obligation 30-minute introduction.
