Regulated function · GDPR
We act as external Data Protection Officer for public bodies, companies and groups, under Articles 37 to 39 of the GDPR and the national law that applies.
Key facts
Public authorities and bodies must designate a DPO, as must organisations whose core activities involve large-scale monitoring or large-scale processing of sensitive data.
Article 37(6) allows the DPO to be a staff member or to fulfil the tasks on the basis of a service contract.
The DPO receives no instructions on the tasks, cannot be dismissed or penalised for performing them and reports to the highest management level.
The DPO's contact details must be published and communicated to the supervisory authority.
By jurisdiction
Each offer covers public bodies, private organisations, shared public arrangements and corporate groups, in the language of the country.
Article 39 of the GDPR entrusts the DPO with a set of minimum tasks, performed with due regard to the risks of each processing operation:
information and advice: to the controller or processor and to the employees who carry out processing;
monitoring: of compliance with the GDPR, national law and internal policies, including the assignment of responsibilities, awareness-raising, training and audits;
impact assessments: advice on data protection impact assessments and monitoring of their performance;
supervisory authority: cooperation with the authority and acting as its contact point;
data subjects: a point of contact on the processing of their data and the exercise of their rights.
We act as external DPO under a service contract, with a named lead professional, a deputy and a time commitment proportionate to the volume and risk of the processing. Before accepting each engagement, we review potential conflicts of interest and keep that review up to date. The organisation remains responsible for compliance and must provide access to the data and the resources the DPO needs.
public bodies: central, regional and local government, agencies and public universities;
private organisations: controllers and processors, under a mandatory or voluntary designation;
shared arrangements: one DPO for several public bodies, as Article 37(3) allows;
corporate groups: one DPO for a group of undertakings, as Article 37(2) allows.
Fees are set in a tailored proposal, according to the size of the organisation and the risk of its processing.
Other regulated functions: Information Security Officer · Compliance Officer · Whistleblowing Officer
General information as at October 2026; it does not constitute legal advice.
Start with the free assessment or request a proposal for your organisation.