Skip to main content
Logo von MKM LEGAL
A data protection officer enters an office

Guide 
External Data Protection Officer

From legal requirements to costs—everything you need to know at a glance.

 ⬥  What does a data protection officer do?
 ⬥  When is a data protection officer required by law?
 ⬥  What are the benefits of an external data protection officer?
 ⬥  How much does an external data protection officer cost?

What are the responsibilities of a data protection officer?

Many task bubbles originate from a data protection officer: documents, checklists, meetings, regulatory agencies, training sessions, alerts

Advise, Monitor, Protect

The Data Protection Officer (DPO) is the central point of contact for all data protection issues within the company. The DPO advises, monitors, and provides training—and also serves as the link between your company, data subjects, and supervisory authorities.

Their job is not just to monitor regulations. A good DPO thinks proactively: they identify risks early on, support new projects from the start, and ensure that data protection remains practical in day-to-day operations. 

What a DPO Actually Does

  • Monitoring and Compliance with Data Protection Regulations under the GDPR and the BDSG

  • Advising management and functional departments on decisions related to data protection

  • Training Employees on the Handling of Personal Data

  • A point of contact for affected individuals, for example, regarding requests for information or complaints

  • Communication with regulatory authorities, particularly in the event of a data breach

  • Data Protection Management & Documentation: From the Record of Processing Activities to the Data Protection Impact Assessment

  • Optimizing Processes for the Protection of Personal Data

What are the responsibilities of an external DPO?

An external data protection officer has the same responsibilities as an in-house DPO: He or she serves as the point of contact for government agencies, management, employees, and data subjects. The scope of responsibilities includes, among other things, providing advice on decisions related to data protection, assisting with data breaches, conducting audits, organizing employee training, and maintaining documentation. 

Examples from Everyday Work Life

Data protection plays a role in many areas

Here's what a data protection officer's work looks like in practice—three typical situations in which a DPO makes a difference.

When is a DPO Necessary?

All companies in the EU must comply with the GDPR. In addition, certain companies are legally required to appoint a data protection officer. According to Article 37 of the GDPR and Section 38 of the BDSG, this applies to the following cases:

  • At least 20 people regularly process personal data by automated means.
  • The company processes particularly sensitive categories of data, including:
    • Health data or data from clinical trials
    • Genetic and biometric data
    • Data on medical devices covered by the Medical Device Regulation
    • Data regarding worldview, religion, or political beliefs
  • The company’s core business involves the extensive processing of personal data.
  • Any processing is subject to a data protection impact assessment (DPIA) under Article 35 of the GDPR, which is required in the following cases, for example:
    • Automated decision-making using AI
    • Extensive surveillance measures

When is it worth having a DSB even if there is no legal requirement?

The GDPR applies to all companies, regardless of their size. For this reason, many companies benefit from appointing a data protection officer, even if they are not yet legally required to do so—for example, in the following cases:

  • A Data Protection Officer serves as a dedicated point of contact for data protection issues, such as when customers request information about their stored data, regulatory authorities submit inquiries, or business partners demand proof of GDPR compliance.
  • A data protection officer reviews data processing agreements that your company enters into with external service providers, such as the IT service provider that needs access to personal data for updates.
  • In the context of international collaboration, a data protection officer ensures that data transfers to third countries are legally compliant and that the relevant data protection standards are met.

Internal or external data protection officer?

What's the right fit for your company?

In general, you can fill the DPO position internally or hire someone from outside the company. Both options are permitted by law. Which one is a better fit for your company depends on the size of your company, your internal resources, and the complexity of data protection in your operations and industry.

A person is sitting at their desk in the office, and a certificate is hanging on the wall

Internal 
Data Protection Officer

An employee of your company assumes the role of Data Protection Officer (DPO) in addition to their regular duties. While this may sound pragmatic, it presents certain challenges:

  • ⬥  Data protection expertise must be developed internally and kept up to date on an ongoing basis
  • ⬥  Conflicts of interest are possible, as the DPO operates within the company under the direction of management
  • ⬥  In the event of data breaches or inquiries from regulatory authorities, liability rests entirely with the company
  • ⬥  The time required—and thus the costs—are often underestimated
Eine Person mit Datenschutz-Akten in der Hand steht vor einem Unternehmen

External 
Data Protection Officer

A specialized service provider assumes the role of data protection officer (DPO) for your company. This offers structural advantages that are difficult to replicate internally:

  • ⬥  Up-to-date expertise without the need for internal training
  • ⬥  Structural independence: no conflict of interest, but rather clear objectivity
  • ⬥  Liability rests with the external service provider provided its recommendations are followed
  • ⬥  Transparent, needs-based costs—without the fixed costs of an in-house position

Special Requirements in Sensitive Industries

Companies in the healthcare sector, the pharmaceutical industry, or social service organizations are subject to particularly strict requirements: Since health data, biometric information, or other categories of sensitive data as defined in Article 9 of the GDPR are regularly processed in these sectors, there is little room for error and the documentation burden is high. 

An external data protection officer with specific industry experience understands these requirements from a practical perspective—and can develop solutions that are both legally sound and feasible in day-to-day operations.

For years, MKM Datenschutz has served as an external data protection officer for companies in highly regulated industries, including medical practices, pharmaceutical companies, and firms in the financial and tax consulting sectors. We are familiar with the industry-specific requirements—from EHDS to SGB-V.

How much does an external data protection officer cost?

There is no fixed fee for an external data protection officer. The price depends on several factors: 

  • Company size and number of employees: As a company grows, the amount of support required and the complexity of data protection processes generally increase—for example, due to more locations, more employees, or a larger number of processing activities.
  • Nature and Sensitivity of the Processed Data: Companies that process categories of data requiring special protection—such as health data, biometric data, or data pertaining to children—are subject to stricter legal requirements, which entail a greater administrative burden.
  • Scope of Services and In-House Contribution: The key factor is which tasks the external DPO will handle entirely and which the company will manage on its own. If an internal contact person takes on coordinating tasks under guidance, this can reduce the scope—and thus the cost.
  • International Operations: Companies with multiple locations or that transfer data internationally have more complex requirements, which are reflected in the level of support required.

Many providers offer a monthly flat rate that covers a defined scope of services, such as a specific number of consulting hours, regular audits, and availability for day-to-day business. 

As a rough guide: Monthly flat rates for smaller companies typically start in the low three-digit range. For medium-sized companies, prices generally range from €300 to €600 per month. A transparent contract should clearly define the scope of services, response times, and options for adjustments.

Our Recommendation

Why the Lowest Price Is Rarely the Best Choice

In our work with over 150 companies, we regularly hear the same thing: Those who previously used a particularly low-cost provider often ended up doing more themselves than they expected. An offer for €100 a month sounds attractive, but in practice it usually means that questions are answered superficially, processes aren’t reviewed, and no personalized recommendations are provided.

This becomes a problem when it really matters: An external DPO is only liable if their recommendations have been correctly implemented. Without professional guidance during implementation, this is virtually impossible to prove, and the risk falls on the company.

So here’s what matters: The DPO should not only make recommendations but also actively oversee their implementation—only then will liability apply in the event of a serious incident. 

For these reasons, we offer a full-service package for an external data protection officer.

What should you look for when making your selection?

The title “Data Protection Officer” is not a protected designation. The GDPR requires that a Data Protection Officer possess expertise in data protection law and data protection practices. When selecting an external Data Protection Officer, we recommend considering the following points: 

Eine Datenschutzbeauftragte im Gespräch mit einer anderen Person über Kosten, Zertifikate u.ä.

Important Questions: 

  • ⬥  Professional Qualifications: Is there verifiable expertise in data protection law, such as through legal training, certifications from reputable providers, or many years of practical experience?
  • ⬥  Availability and Response Time: Data protection incidents must be reported within 72 hours. Is your DPO reliably available in such situations?
  • ⬥  Industry experience: Does the provider understand the specific requirements of your industry? This should be a key consideration, especially when handling sensitive data.
  • ⬥  Contract terms: Are the scope of services, contract term, and notice periods clearly defined? You should carefully review the scope of services, particularly for low-cost offers under €250 per month.

Five Steps to Hiring an External Data Protection Officer

Two speech bubbles: one shows a factory and people, and the other shows a euro symbol

Initial Contact

During the first meeting, the company’s data protection requirements are clarified: industry, company size, and type of data processed. Based on this information, the provider prepares a customized proposal.

A document bearing a seal

Appointment and Contract Execution

Once the contract is signed, the external data protection officer is officially appointed in writing. From that point on, the position of data protection officer is filled in a legally compliant manner.

A document with to-do items and a magnifying glass showing an exclamation point

Assessment (Audit)

The DPO analyzes the company’s existing data protection processes and documents—and identifies any vulnerabilities that should be addressed.

A checklist with some items checked off

Recommendations and Implementation

Based on the assessment, the DSB develops customized recommendations for action and supports their implementation—from adapting processes to creating missing documentation.

A person with several speech bubbles representing inquiries, such as those from regulatory agencies

Ongoing Support

During normal operations, the DSB is available to address all data protection-related issues, such as new projects, inquiries from government agencies, data breaches, or employee training.

Privacy Shield

Our Services

Upon request, MKM Datenschutz will serve as your company’s external data protection officer. Read on to learn how we can support you. 

Häufige Fragen und Antworten

Logo von MKM LEGAL
Newsletter-Anmeldung