A data protection officer is a statutory role under GDPR Article 37, not a job title a company can hand out informally. This page covers what the role has to do, which companies are required to appoint one, and how an outsourced appointment works in practice.

The short answer: data protection officer services put a qualified, named DPO into your organization on a service contract, notified to the supervisory authority, doing the Article 39 tasks without you hiring a full-time person. GDPR Article 37(6) allows exactly this, so an external appointment is a normal way to meet the requirement rather than a workaround for it.

Engage Compliance provides outsourced data protection officer services to technology companies in the EU, the UK, and the US. We act as the named DPO, notified to the supervisory authority, with the same senior person on your account throughout the engagement. Experience across 100+ startups and enterprises including Amazon, Coinbase, and Robinhood.

Key takeaways

  • A DPO is a statutory role under GDPR Articles 37 to 39, with independence and reporting protections that an ordinary consultant does not have.
  • Article 37(6) permits the role to be filled on a service contract, so outsourcing is contemplated by the regulation itself.
  • Three circumstances trigger a mandatory appointment: public authority processing, large-scale regular and systematic monitoring, or large-scale special category and criminal conviction data.
  • The appointment has to be notified to the supervisory authority, and the DPO’s contact details have to be published.
  • Named DPO tiers start From €1,000 per month, against €90,000 to €160,000 a year for a full-time in-house appointment.
  • Engage Compliance is appointed under Article 37(6) as the named DPO on your notification, which is what separates the service from privacy consulting.

What a data protection officer is

The DPO is the person GDPR names as responsible for monitoring an organization’s compliance with the regulation. The role is defined across three articles, and reading them together is what separates a real appointment from a nameplate.

Article 37 sets who has to appoint one and says the DPO must be designated on the basis of professional qualities, in particular expert knowledge of data protection law and practice. It also allows a group of undertakings to appoint a single DPO, and it allows the role to sit on a service contract.

Article 38 sets the conditions the organization has to provide. The DPO must be involved properly and in a timely manner in all issues relating to personal data. They must be given the resources to do the job and access to the processing. They must not receive instructions on how to perform their tasks, must not be dismissed or penalized for performing them, and must report to the highest level of management.

Article 39 sets the tasks. Informing and advising the organization and its staff of their obligations. Monitoring compliance, including assigning responsibilities, awareness raising, staff training, and audits. Advising on data protection impact assessments and monitoring their performance. Cooperating with the supervisory authority and acting as its contact point.

Those are duties owed under the regulation, not deliverables negotiated in a statement of work. That is the practical difference between a data protection officer and a privacy consultant, and it is why the two are priced and contracted differently.

Who needs to appoint one

Article 37(1) makes appointment mandatory in three circumstances. The test is about your core activities, meaning the processing that is inseparable from what you sell, not the payroll and HR processing every company does.

Public authority or body

Any public authority or body has to appoint a DPO, whatever the scale, with the narrow exception of courts acting in a judicial capacity. Private companies delivering a public function are not automatically caught, though several member states extend the requirement further than GDPR does.

Large-scale regular and systematic monitoring

This is the trigger most technology companies hit. Regular and systematic monitoring covers behavioral advertising, profiling, location tracking, fraud and risk scoring, connected devices, and most product analytics that follow an identified user over time. There is no headcount threshold in the regulation and no user-count threshold either; scale is judged on the number of people affected, the volume and range of data, the duration, and the geographic reach.

Large-scale special category or criminal conviction data

Health data, biometric data used for identification, genetic data, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life and sexual orientation, plus criminal conviction and offense data. HealthTech, digital therapeutics, insurance, background checking, and any product built on identity verification usually land here.

Two national extensions catch companies that read the GDPR test and conclude they are outside it. Germany requires a DPO once at least 20 people are constantly engaged in automated processing of personal data, under Section 38 of the Bundesdatenschutzgesetz, which is a headcount test rather than a risk test. Spain lists specific sectors in Article 34 of the LOPDGDD. If you are unsure where you land, the do I need a DPO decision guide runs the test end to end.

There is also the voluntary appointment, which more companies make than the mandatory one. Enterprise procurement, investor due diligence, and insurance underwriting all ask the question, and a named DPO answers it in one line. A voluntary DPO is held to the same Article 38 and 39 standards once appointed, so it is a commitment rather than a label.

What we do

The engagement covers the Article 39 tasks and the operational work that makes them possible.

  • Named DPO appointment, notified to the supervisory authority, with contact details published in your privacy notice as Article 13 requires.
  • Records of processing. Building and maintaining the Article 30 record, which is the artifact a regulator asks for first and the one most companies cannot produce on request.
  • Data protection impact assessments. Screening new processing, running the assessment where Article 35 requires it, and documenting the decision where it does not.
  • Vendor and transfer work. Reviewing processor agreements, running transfer impact assessments, and keeping the subprocessor position current.
  • Data subject requests. Handling access, erasure, portability, and objection requests inside the one-month statutory clock, with the extension documented where it applies.
  • Breach response. The 72-hour assessment under Article 33, the notification decision, and the record whether or not you notify.
  • Training and awareness. Role-specific sessions for engineering, sales, and support, because the people who create the risk are rarely the people who read the policy.
  • Regulator contact. Acting as the point of contact for the supervisory authority and handling correspondence, inquiries, and complaints.
  • Reporting. A standing report to management, which is what Article 38(3) contemplates by requiring the DPO to report at the highest level.

Where a company already has a strong internal privacy lead and needs advice rather than an appointment, Privacy Advisory covers the advice without the named role.

How it works

Week one. A scoping call, a review of what already exists, and a short questionnaire covering your processing, your systems, your transfers, and your customer commitments. We tell you at the end of it whether appointment is mandatory for you or voluntary, and we say so plainly either way.

Week two. Contract signed, DPO named, notification filed with the supervisory authority, and contact details added to your privacy notice. From this point you can answer the DPO question on any questionnaire truthfully.

Month one. A gap assessment against the obligations that apply to you, a prioritized remediation plan, and the Article 30 record started. You get a document you can hand to a customer, not a dashboard score.

Ongoing. Scheduled advisory time, request and breach handling as they arise, quarterly reporting, and an annual review of the whole program. The same senior DPO stays on the account, so nobody re-learns your architecture every quarter.

What we need from you is a named internal contact, access to the people who actually know how the data moves, and a decision-maker who can approve remediation. Companies that supply those three things get a working program inside a quarter, and companies that supply none of them get a document nobody acts on.

What it costs

Named DPO tiers, all billed annually in euros:

  • DPO Foundation, From €1,000 per month. A named DPO for a company with a defined product and a manageable processing footprint.
  • DPO Partner, From €2,500 per month. For companies with multiple products, international transfers, or an enterprise customer base that puts real weight on the privacy answers.
  • DPO Complete, From €4,500 per month. For complex or multi-jurisdiction programs where the DPO is engaged continuously rather than periodically.
  • Enterprise, tailored. Scoped against the actual program.

Privacy Advisory is From €600 per month and covers advice without the named appointment, for companies that already have a DPO or do not need one yet.

For the comparison against hiring, and the ranges other provider types charge, see the outsourced DPO cost guide.

Why Engage Compliance

You work with a senior DPO directly, and it is the same person for the life of the engagement. Experience across 100+ startups and enterprises including Amazon, Coinbase, and Robinhood. Your DPO is an expert, never a junior handoff to a delivery team.

The named DPO is notified to the supervisory authority and backed by a network of specialist advisors for cross-border, sectoral, and technical questions that sit outside any one person’s depth. Every engagement carries professional indemnity and cyber insurance.

We work across SaaS, FinTech, HealthTech, AI, e-commerce, HR tech, and marketplaces, from pre-seed through enterprise. Where your obligations run past GDPR into the US state laws, the UK, Brazil, or APAC, the global privacy compliance service covers the whole footprint under one point of contact.

Sources and references

  • Same-business-day response
  • Professional indemnity and cyber insurance
  • Named DPO notified to the supervisory authority

FAQ

Frequently asked questions

What are data protection officer services?

They are the outsourced provision of the GDPR Article 37 data protection officer role. A provider supplies a qualified person who is appointed as your organization's DPO, notified to the supervisory authority, and carries out the Article 39 tasks: monitoring compliance, advising on DPIAs, training staff, and acting as the contact point for the regulator and for data subjects. The person is named on your notification and answerable for the role, which is what separates this from general privacy consulting.

Is a data protection officer the same as a privacy consultant?

No. A DPO is a statutory role with protections and duties written into GDPR Articles 37 to 39, including independence from instruction on how to perform the role and a direct reporting line to the highest level of management. A privacy consultant has no statutory standing and can be told what to conclude. Many companies need both, and quite often the same provider supplies the DPO and separate advisory hours.

Can a company outsource the data protection officer role?

Yes. Article 37(6) allows the DPO to fill the role on the basis of a service contract rather than employment, so an external appointment is expressly contemplated by GDPR. The appointment still has to be notified to the supervisory authority and the external DPO still has to be given the access, resources, and independence Article 38 requires.

Which supervisory authority do we notify?

Your lead supervisory authority, which for most companies is the one in the country of your main EU establishment. A company with no EU establishment notifies in each member state where it has a representative or where its processing has effect. The notification is a short online filing naming the DPO and giving their contact details, and we handle it as part of onboarding.

What does an outsourced data protection officer cost?

Our named DPO tiers start From €1,000 per month for DPO Foundation, with DPO Partner From €2,500 per month and DPO Complete From €4,500 per month. Privacy Advisory, which is advice without a named DPO appointment, is From €600 per month. A full-time in-house senior DPO in Western Europe typically runs €90,000 to €160,000 a year before recruitment time.

How quickly can a DPO be appointed?

Engagement typically starts within one to two weeks. The notification to the supervisory authority can be filed as soon as the contract is signed and the contact details are settled, so a company that needs a named DPO on a customer questionnaire or an investor checklist can usually show one inside a fortnight.

Does the DPO take on our legal liability?

No, and no provider can. Accountability under GDPR sits with the controller or processor, and Article 38(3) explicitly says the DPO must not be dismissed or penalized for performing the role, which only makes sense because the organization stays responsible. What the DPO does is monitor, advise, and document, which is what a regulator looks for when it asks whether you took your obligations seriously.