Data Protection Officer · European Union
External DPO for controllers and processors that must designate one under Article 37 of the GDPR or national law, and for organisations that choose to appoint one voluntarily.
Legal framework
A DPO is required where the core activities consist of processing that requires regular and systematic monitoring of data subjects on a large scale.
A DPO is also required where the core activities consist of large-scale processing of special categories of data or of data relating to criminal convictions and offences.
Article 37(4) allows Member State law to require a DPO in other cases, as Germany and Spain have done.
Failure to comply with Articles 37 to 39 may lead to fines of up to €10 million or 2% of total worldwide annual turnover, whichever is higher.
The obligation applies to controllers and processors alike. It depends on the organisation's core activities, not on its size: a small company whose business is large-scale profiling or the processing of health data may need a DPO, while a large company with only ancillary processing may not. The European data protection authorities recommend documenting the internal analysis carried out to decide whether a DPO is required. Organisations that appoint a DPO voluntarily are subject to the same requirements as those that must appoint one.
information and advice: to management and staff on their obligations;
monitoring: of compliance with the GDPR, national law and internal policies, with periodic audits;
impact assessments: advice and monitoring of their performance;
supervisory authority: cooperation with the authority and acting as its contact point;
data subjects: a point of contact for requests and complaints;
personal data breaches: support in assessing breaches and notifying the authority and data subjects.
We act as an external DPO under a service contract (Article 37(6)), with a named lead professional, a deputy and a time commitment proportionate to the volume and risk of the processing. We confirm the absence of conflicts of interest before accepting the role and keep it under review, as required by Article 38(6). The organisation must give access to the data and the resources needed and remains responsible for compliance.
Essential: the statutory DPO tasks, contact point and an annual report;
Advanced: adds impact assessments, annual training and support with personal data breaches;
Comprehensive: adds the implementation of the privacy management programme, with records of processing, policies and processor contracts.
Fees are set in a tailored proposal, according to the size of the organisation, the volume and nature of the data and the high-risk processing involved.
designation: a designation document and the notification to the supervisory authority;
publication: content for publishing the DPO's contact details;
annual activity plan: with a schedule and indicators;
annual report: on the state of compliance and recommendations.
National offers: Portugal · Spain · Brazil
Other offers: Corporate groups · Public bodies · Shared DPO for public bodies · European Union
General information as at October 2026; it does not constitute legal advice.
Frequently asked questions
It does if its core activities involve large-scale regular and systematic monitoring, or large-scale processing of special categories of data or criminal data, or if national law requires one. Our free assessment helps you reach and document that conclusion.
Yes. Article 37(1) applies to processors in the same way as to controllers, so a service provider may need a DPO even when its clients do not.
No. The European Data Protection Board considers the role of the representative under Article 27 incompatible with that of an external DPO for the same organisation, because of the risk of conflicts of interest.
Only if they do not create a conflict of interest. The Court of Justice has confirmed that this must be assessed case by case, taking into account all relevant circumstances (Case C-453/21).