Summary: A data protection consultant should leave behind something you can maintain: records of processing activities, assessments that stand up to scrutiny, procedures the organisation actually uses and a proper handover. This guide covers when you need help, what to require as deliverables, seven questions that reveal the differences between providers and the warning signs to watch for.
The market for data protection consultants is broad. There are law firms, IT companies, dedicated GDPR consultancies and broad security firms. They all say roughly the same thing: we help you comply with the GDPR. The differences only show in what is delivered and in how it works a year later.
This guide is written for anyone buying data protection support for the first time, or changing provider, who wants to compare offers on a reasonable basis.
When do you need a data protection consultant?
The need rarely arises because someone has read the GDPR. It arises when something happens in the business. Some common triggers:
- A customer or a procurement demands evidence. You have to show records, data processing agreements or an impact assessment before a contract can be signed.
- A new processing activity is being introduced. A new system, service or technology that may pose a high risk to individuals and therefore requires a data protection impact assessment (DPIA).
- You do not know where all the personal data is. Documentation is incomplete or outdated and nobody owns the question.
- An incident has occurred, or a customer, a data subject or the Swedish Authority for Privacy Protection (IMY) has asked questions.
- The organisation is growing and what worked with twenty employees no longer works with two hundred.
- The data protection officer needs relief. The DPO is meant to monitor and advise, not to do all the operational work. Someone else needs to own that work.
What should the consultant actually deliver?
Always ask for a list of concrete deliverables before you compare prices. A serious data protection engagement usually consists of some of the following:
- A current-state analysis with identified gaps and a prioritised action plan that management can decide on.
- Records of processing activities under Article 30, linked to systems, purposes, legal bases and retention periods.
- Data protection impact assessments (DPIAs) for high-risk processing, with documented measures and residual risk.
- Reviewed data processing agreements and a procedure for assessing new suppliers.
- Procedures for data subject rights: access, rectification, erasure and objections, with deadlines and responsibilities.
- An incident procedure that manages assessment and notification within 72 hours, preferably tested in an exercise.
- Training for the people who handle personal data every day.
- A handover that lets you maintain the documentation yourselves, with clear roles and an annual plan.
The last item is the one most often missing from proposals. A delivery without a handover becomes a binder nobody opens.
Seven questions to ask before you choose
- Which concrete documents and procedures will we have when the engagement is complete? The answer should be a list, not a description of the way of working.
- Can we see an anonymised example of a record or an impact assessment you have produced? The quality shows in the example.
- Who will do the work for us, and what experience does that person have? The salesperson and the consultant are not always the same person.
- How do you work with legal, technical and business aspects at the same time? Data protection needs all three. A provider that covers only one of them leaves the rest to you.
- What does the handover look like, and what will it take for us to maintain the result? Ask for the annual plan, the roles and the number of hours per year.
- How is the engagement priced, and what is not included? A fixed price, an hourly rate or a combination all work, but you need to know where the line is.
- How do you handle confidentiality and the data you get access to at our organisation? A data protection consultant is often a processor. That requires an agreement.
Warning signs
- Template packages without adaptation. Policies that do not mention your systems, your processing activities or your suppliers are not documentation, they are text.
- Promises of becoming “GDPR certified” or “one hundred percent compliant”. There is no such certification to buy, and compliance is a state that has to be maintained.
- No plan for the handover. If you depend on the consultant for every access request, you have not received a working data protection programme.
- Everything depends on one person. Ask what happens in case of illness, holidays or if the person changes employer.
- No connection to information security. The GDPR requires appropriate technical and organisational security measures. A consultant who cannot talk about access control, logging and encryption covers only half the requirement.
How to compare proposals
| Criterion | What to look at | Why it matters |
|---|---|---|
| Deliverables | Named documents, procedures and assessments | This is what you can show customers, auditors and IMY |
| Method | Interviews, system walkthroughs, document review | A record built on interviews alone misses what sits in the systems |
| Competence | Experience from your type of organisation, relevant certifications | Healthcare, municipalities, finance and SaaS have different risks and requirements |
| Breadth | Legal, technical and business expertise in the same team | Otherwise questions fall between the chairs |
| Maintenance | Handover, annual plan, training | Decides whether the result survives the engagement |
| Price | What is included, what costs extra, how changes are handled | Only compare proposals with the same scope |
Prepare the first conversation
You get better proposals if you can describe your situation yourselves. Bring the types of personal data you process and whether you process sensitive data, the systems that hold it, what triggered the need, what documentation already exists and when you need to be done. Approximate is fine. A good consultant asks the rest of the questions.
Want to know how we work with this? Read about our data protection and privacy services or contact us for a first conversation.
Sources: the General Data Protection Regulation (GDPR), including Article 24 on the responsibility of the controller, Article 28 on processors, Article 30 on records of processing activities, Article 32 on security, Article 33 on notification of personal data breaches and Article 35 on data protection impact assessments; the Swedish Authority for Privacy Protection (IMY), guidance for organisations.
This text is general information and does not constitute legal advice in an individual case.

