External data protection officer (DPO)
An external data protection officer who is independent, available and reports directly to management. We take the role under GDPR Articles 37 to 39, or support the officer you have already appointed.
Who it is for and when
The external DPO suits organisations that must or want to have an officer but lack the right expertise in-house, or where an internal solution would create conflicts of interest.
- You are a public authority, a public body or a company that must appoint a data protection officer under Article 37.
- You process sensitive personal data on a large scale, for example in healthcare, education or HR services.
- Your current officer also does the operational GDPR work, and it is hard to review your own work independently.
- You want a senior contact point towards IMY and the data subjects, with a deputy during absence.
What we do
- Start-up and notification. We get to know your processing activities, roles and risks, prepare an annual plan and notify the officer’s contact details to IMY.
- Ongoing advice. Questions from the business are answered within the agreed time: new processing activities, suppliers, data subject rights and impact assessments.
- Monitoring according to the annual plan. We monitor compliance through spot checks, reviews and walkthroughs of records, agreements and procedures, and document the observations.
- Incident support. In a personal data breach we assess the severity and support the notification within 72 hours and the documentation afterwards.
- Reporting to management. At least once a year management receives a report with observations, risks and recommendations.
You get
- A named data protection officer and a named deputy
- Notification to IMY and published contact details
- Annual monitoring plan and documented reviews
- Advice with agreed response times
- Incident support and an annual report to management
Scope and price
An ongoing engagement where the scope is adapted to the size of the organisation, the number of processing activities and how many questions usually arise. Most common is a number of days per month.
The price varies from engagement to engagement and depends on the scope. You get a clear proposal with set-up and monthly cost after the first conversation. The engagement has a notice period and an agreed handover.
How it works
- A first conversation. We listen to your situation and explain how we usually set up the work. You get our assessment straight away, free of charge.
- A proposal with scope and price. A short written proposal with what is included, what you get, who does the work and what it costs.
- Delivery and handover. We work together with your organisation, report continuously and hand over so that you can maintain the result yourselves.
Frequently asked questions
Do we have to appoint a data protection officer?
Yes, if you are a public authority or body, if your core activities involve regular and systematic monitoring of individuals on a large scale, or if you process special categories of personal data or data on criminal convictions on a large scale. Others may appoint an officer voluntarily and are then bound by the same requirements for the role.
Can the officer also do our operational GDPR work?
Preferably not. The GDPR allows the officer to have other tasks as long as they do not create a conflict of interest, but the person who monitors the data protection work should not also make the decisions about the processing. If you also need operational support, for example records or impact assessments, we do that with other consultants and clear boundaries.
What does an external data protection officer cost?
It varies from engagement to engagement. The set-up depends on the size of the organisation, how many and how sensitive the processing activities are and how much ongoing support you need. We go through the arrangement that suits you in a first conversation.
Want to know how an external data protection officer would work for you?
Contact us