A data protection officer is a statutory role under GDPR Article 37, not a job title a company can hand out informally. This page covers what the role has to do, which companies are required to appoint one, and how an outsourced appointment works in practice.
The short answer: data protection officer services put a qualified, named DPO into your organization on a service contract, notified to the supervisory authority, doing the Article 39 tasks without you hiring a full-time person. GDPR Article 37(6) allows exactly this, so an external appointment is a normal way to meet the requirement rather than a workaround for it.
Engage Compliance provides outsourced data protection officer services to technology companies in the EU, the UK, and the US. We act as the named DPO, notified to the supervisory authority, with the same senior person on your account throughout the engagement. Experience across 100+ startups and enterprises including Amazon, Coinbase, and Robinhood.
Key takeaways
- A DPO is a statutory role under GDPR Articles 37 to 39, with independence and reporting protections that an ordinary consultant does not have.
- Article 37(6) permits the role to be filled on a service contract, so outsourcing is contemplated by the regulation itself.
- Three circumstances trigger a mandatory appointment: public authority processing, large-scale regular and systematic monitoring, or large-scale special category and criminal conviction data.
- The appointment has to be notified to the supervisory authority, and the DPO’s contact details have to be published.
- Named DPO tiers start From €1,000 per month, against €90,000 to €160,000 a year for a full-time in-house appointment.
- Engage Compliance is appointed under Article 37(6) as the named DPO on your notification, which is what separates the service from privacy consulting.
What a data protection officer is
The DPO is the person GDPR names as responsible for monitoring an organization’s compliance with the regulation. The role is defined across three articles, and reading them together is what separates a real appointment from a nameplate.
Article 37 sets who has to appoint one and says the DPO must be designated on the basis of professional qualities, in particular expert knowledge of data protection law and practice. It also allows a group of undertakings to appoint a single DPO, and it allows the role to sit on a service contract.
Article 38 sets the conditions the organization has to provide. The DPO must be involved properly and in a timely manner in all issues relating to personal data. They must be given the resources to do the job and access to the processing. They must not receive instructions on how to perform their tasks, must not be dismissed or penalized for performing them, and must report to the highest level of management.
Article 39 sets the tasks. Informing and advising the organization and its staff of their obligations. Monitoring compliance, including assigning responsibilities, awareness raising, staff training, and audits. Advising on data protection impact assessments and monitoring their performance. Cooperating with the supervisory authority and acting as its contact point.
Those are duties owed under the regulation, not deliverables negotiated in a statement of work. That is the practical difference between a data protection officer and a privacy consultant, and it is why the two are priced and contracted differently.
Who needs to appoint one
Article 37(1) makes appointment mandatory in three circumstances. The test is about your core activities, meaning the processing that is inseparable from what you sell, not the payroll and HR processing every company does.
Public authority or body
Any public authority or body has to appoint a DPO, whatever the scale, with the narrow exception of courts acting in a judicial capacity. Private companies delivering a public function are not automatically caught, though several member states extend the requirement further than GDPR does.
Large-scale regular and systematic monitoring
This is the trigger most technology companies hit. Regular and systematic monitoring covers behavioral advertising, profiling, location tracking, fraud and risk scoring, connected devices, and most product analytics that follow an identified user over time. There is no headcount threshold in the regulation and no user-count threshold either; scale is judged on the number of people affected, the volume and range of data, the duration, and the geographic reach.
Large-scale special category or criminal conviction data
Health data, biometric data used for identification, genetic data, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life and sexual orientation, plus criminal conviction and offense data. HealthTech, digital therapeutics, insurance, background checking, and any product built on identity verification usually land here.
Two national extensions catch companies that read the GDPR test and conclude they are outside it. Germany requires a DPO once at least 20 people are constantly engaged in automated processing of personal data, under Section 38 of the Bundesdatenschutzgesetz, which is a headcount test rather than a risk test. Spain lists specific sectors in Article 34 of the LOPDGDD. If you are unsure where you land, the do I need a DPO decision guide runs the test end to end.
There is also the voluntary appointment, which more companies make than the mandatory one. Enterprise procurement, investor due diligence, and insurance underwriting all ask the question, and a named DPO answers it in one line. A voluntary DPO is held to the same Article 38 and 39 standards once appointed, so it is a commitment rather than a label.
What we do
The engagement covers the Article 39 tasks and the operational work that makes them possible.
- Named DPO appointment, notified to the supervisory authority, with contact details published in your privacy notice as Article 13 requires.
- Records of processing. Building and maintaining the Article 30 record, which is the artifact a regulator asks for first and the one most companies cannot produce on request.
- Data protection impact assessments. Screening new processing, running the assessment where Article 35 requires it, and documenting the decision where it does not.
- Vendor and transfer work. Reviewing processor agreements, running transfer impact assessments, and keeping the subprocessor position current.
- Data subject requests. Handling access, erasure, portability, and objection requests inside the one-month statutory clock, with the extension documented where it applies.
- Breach response. The 72-hour assessment under Article 33, the notification decision, and the record whether or not you notify.
- Training and awareness. Role-specific sessions for engineering, sales, and support, because the people who create the risk are rarely the people who read the policy.
- Regulator contact. Acting as the point of contact for the supervisory authority and handling correspondence, inquiries, and complaints.
- Reporting. A standing report to management, which is what Article 38(3) contemplates by requiring the DPO to report at the highest level.
Where a company already has a strong internal privacy lead and needs advice rather than an appointment, Privacy Advisory covers the advice without the named role.
How it works
Week one. A scoping call, a review of what already exists, and a short questionnaire covering your processing, your systems, your transfers, and your customer commitments. We tell you at the end of it whether appointment is mandatory for you or voluntary, and we say so plainly either way.
Week two. Contract signed, DPO named, notification filed with the supervisory authority, and contact details added to your privacy notice. From this point you can answer the DPO question on any questionnaire truthfully.
Month one. A gap assessment against the obligations that apply to you, a prioritized remediation plan, and the Article 30 record started. You get a document you can hand to a customer, not a dashboard score.
Ongoing. Scheduled advisory time, request and breach handling as they arise, quarterly reporting, and an annual review of the whole program. The same senior DPO stays on the account, so nobody re-learns your architecture every quarter.
What we need from you is a named internal contact, access to the people who actually know how the data moves, and a decision-maker who can approve remediation. Companies that supply those three things get a working program inside a quarter, and companies that supply none of them get a document nobody acts on.
What it costs
Named DPO tiers, all billed annually in euros:
- DPO Foundation, From €1,000 per month. A named DPO for a company with a defined product and a manageable processing footprint.
- DPO Partner, From €2,500 per month. For companies with multiple products, international transfers, or an enterprise customer base that puts real weight on the privacy answers.
- DPO Complete, From €4,500 per month. For complex or multi-jurisdiction programs where the DPO is engaged continuously rather than periodically.
- Enterprise, tailored. Scoped against the actual program.
Privacy Advisory is From €600 per month and covers advice without the named appointment, for companies that already have a DPO or do not need one yet.
For the comparison against hiring, and the ranges other provider types charge, see the outsourced DPO cost guide.
Why Engage Compliance
You work with a senior DPO directly, and it is the same person for the life of the engagement. Experience across 100+ startups and enterprises including Amazon, Coinbase, and Robinhood. Your DPO is an expert, never a junior handoff to a delivery team.
The named DPO is notified to the supervisory authority and backed by a network of specialist advisors for cross-border, sectoral, and technical questions that sit outside any one person’s depth. Every engagement carries professional indemnity and cyber insurance.
We work across SaaS, FinTech, HealthTech, AI, e-commerce, HR tech, and marketplaces, from pre-seed through enterprise. Where your obligations run past GDPR into the US state laws, the UK, Brazil, or APAC, the global privacy compliance service covers the whole footprint under one point of contact.
Sources and references
- Regulation (EU) 2016/679 (GDPR), Articles 37 to 39, EUR-Lex
- Guidelines on Data Protection Officers (WP243 rev.01), European Data Protection Board