Regulated function · GDPR

Data Protection Officer

We act as external Data Protection Officer for public bodies, companies and groups, under Articles 37 to 39 of the GDPR and the national law that applies.

Key facts

The DPO at a glance

When it is mandatory

Public authorities and bodies must designate a DPO, as must organisations whose core activities involve large-scale monitoring or large-scale processing of sensitive data.

Internal or external

Article 37(6) allows the DPO to be a staff member or to fulfil the tasks on the basis of a service contract.

Independence

The DPO receives no instructions on the tasks, cannot be dismissed or penalised for performing them and reports to the highest management level.

Publication and notification

The DPO's contact details must be published and communicated to the supervisory authority.

By jurisdiction

Offers written under the applicable law

Each offer covers public bodies, private organisations, shared public arrangements and corporate groups, in the language of the country.

Portugal

Encarregado de Proteção de Dados · RGPD e Lei n.º 58/2019

Brasil

Encarregado de Dados · LGPD e normas da ANPD

España

Delegado de Protección de Datos · RGPD y LOPDGDD

European Union

Data Protection Officer · GDPR Articles 37 to 39

What the DPO does

Article 39 of the GDPR entrusts the DPO with a set of minimum tasks, performed with due regard to the risks of each processing operation:

  • information and advice: to the controller or processor and to the employees who carry out processing;

  • monitoring: of compliance with the GDPR, national law and internal policies, including the assignment of responsibilities, awareness-raising, training and audits;

  • impact assessments: advice on data protection impact assessments and monitoring of their performance;

  • supervisory authority: cooperation with the authority and acting as its contact point;

  • data subjects: a point of contact on the processing of their data and the exercise of their rights.

How we perform the role

We act as external DPO under a service contract, with a named lead professional, a deputy and a time commitment proportionate to the volume and risk of the processing. Before accepting each engagement, we review potential conflicts of interest and keep that review up to date. The organisation remains responsible for compliance and must provide access to the data and the resources the DPO needs.

Four segments

  • public bodies: central, regional and local government, agencies and public universities;

  • private organisations: controllers and processors, under a mandatory or voluntary designation;

  • shared arrangements: one DPO for several public bodies, as Article 37(3) allows;

  • corporate groups: one DPO for a group of undertakings, as Article 37(2) allows.

Fees are set in a tailored proposal, according to the size of the organisation and the risk of its processing.

Other regulated functions: Information Security Officer · Compliance Officer · Whistleblowing Officer

General information as at October 2026; it does not constitute legal advice.

Find out whether you need a DPO

Start with the free assessment or request a proposal for your organisation.