External data protection officer: how to compare providers

External data protection officer: how to compare providers

Do you have to appoint a DPO, what may the role do, internal or external, and eight criteria for comparing providers of an external data protection officer.

Summary: An external data protection officer must be independent, available and able to report directly to top management. The price varies with the size of the organisation and the complexity of the processing, but what separates providers is usually something else: how the monitoring is documented, how quickly you get answers, what happens during an incident and who steps in when the DPO is unavailable. Here are eight criteria and the questions that go with them.

Do you have to appoint a data protection officer?

Under Article 37 of the GDPR, a data protection officer must be designated if you are a public authority or body, if your core activities involve regular and systematic monitoring of individuals on a large scale, or if you process special categories of personal data or data relating to criminal convictions on a large scale. Other organisations may appoint a DPO voluntarily.

Two things are worth knowing. An organisation that appoints a DPO voluntarily is bound by the same requirements for the role as one that must. And the DPO’s contact details must be published and communicated to the Swedish Authority for Privacy Protection (IMY).

What the role may and may not do

Articles 38 and 39 describe the position and tasks of the DPO. The DPO informs and advises, monitors compliance, advises on data protection impact assessments, cooperates with IMY and acts as the contact point for the authority and for data subjects. The DPO reports directly to the highest management level, must not receive instructions on how to perform the tasks and must not hold a role that leads to a conflict of interests.

This is why the DPO should not own the operational GDPR work. The person who writes the records, approves the suppliers and decides on the processing cannot at the same time be the one who independently monitors them. The organisation owns the processing. The DPO monitors, challenges and advises.

Internal or external DPO?

Internal DPOExternal DPO
Knowledge of the organisationHigh from the startBuilt up during the first year
IndependenceRequires the role to be kept separate from operational responsibility, which is hard in smaller organisationsBuilt in, as long as the provider does not also do the operational work
Breadth of competenceDepends on one personAccess to a team with legal, technical and sector expertise
ContinuityVulnerable to absence and staff turnoverA deputy should be part of the agreement
CostPart of a salary plus training and timeAn agreed fee, often lower than a part-time position

Many organisations choose a combination: an external DPO who monitors and reports, and an internal data protection coordinator who owns the day-to-day work. The roles complement each other and should be kept apart.

Eight criteria for comparing external DPOs

  1. Independence. Does the provider also do the operational work for you? Then you need to know how the conflict of interests is handled, for example through separate people and documented boundaries.
  2. Availability and response times. How quickly do you get an answer to an ordinary question, and what applies during an incident in the evening or at the weekend? Put it in the agreement.
  3. Sector knowledge. Healthcare, municipalities, schools, finance and SaaS have different legal bases, different supervision and different risks. Ask for experience from your sector.
  4. Reporting to management. How often, in what format and with what content? An annual report with observations, risks and recommendations is a minimum.
  5. Documented monitoring. Ask to see how a review is documented. That is the documentation you show IMY if the question comes.
  6. Incident support. Who assesses the severity, who writes the notification and how is the 72-hour deadline secured? Ask how many incidents the provider has handled.
  7. Continuity. Who stands in for the designated DPO during absence, and how is knowledge about your organisation transferred?
  8. Handover and exit. What happens to the documentation if you change provider or take the role in-house? Everything that concerns you should be yours.

Pricing models on the market

External DPOs are priced in a few different ways. The most common is a fixed monthly or annual fee that reflects the size of the organisation and the complexity of the processing. Some providers work with a bank of hours that is topped up, others with a low fixed fee and variable charges for anything outside it. For defined assignments, such as an impact assessment or a review, a fixed price per assignment is common.

No model is right for everyone. What matters is what is included. Always compare proposals on the same scope: number of processing activities, number of systems, number of questions per month, incident support and reporting. A low fee with little content becomes expensive the day something happens.

Questions to ask

  • Who will be our named DPO, and who is the deputy?
  • How many DPO engagements does that person hold at the same time?
  • What does an annual monitoring plan look like with you?
  • How do you handle contact with IMY and with data subjects who turn to the DPO?
  • What is included in the fee, and what is charged separately?
  • What are the notice period and the handover arrangements?

Warning signs

  • The DPO writes and approves their own documentation. Then nobody is monitoring.
  • The DPO has so many engagements that you get answers only after several days.
  • No notification to IMY and no published contact details.
  • Reporting goes to the IT manager or HR instead of to top management.
  • The agreement lacks a deputy, response times and exit arrangements.

Want to discuss how an external data protection officer would work for you? Read about our data protection and privacy services or contact us for a first conversation.

Sources: the General Data Protection Regulation (GDPR), Articles 37–39 on the designation, position and tasks of the data protection officer and Article 33 on notification of personal data breaches; the Swedish Authority for Privacy Protection (IMY), guidance on data protection officers.

This text is general information and does not constitute legal advice in an individual case.