Outsourced Data Protection Officer Outsourced DPO — your dedicated GDPR expert, from €290/month

We fulfil the outsourced DPO (Data Protection Officer) role for your organisation: official designation with the CNIL, records of processing maintenance, handling data subject rights requests, team awareness and ongoing regulatory monitoring. Support aligned with GDPR Articles 37 to 39, without recruitment costs.

GDPR explicitly allows a DPO to be internal or to perform their tasks under a service contract; the CNIL also confirms that a DPO may be external and, under certain conditions, shared across several organisations.

Formality of designation with the CNIL included
From €290/month
Identity and competence evidence before designation

What you get

With your outsourced DPO

A dedicated DPO for your organisation, designated by name with the CNIL — ongoing advice, monitoring and support, without recruitment costs. Identity and competence evidence provided before engagement.

from €290 /month
Art. 37–39 GDPR missions
24h response time

An in-house DPO costs €50,000 to €80,000/year — the Essential DPO starts at €3,480 excl. VAT/year (€290 excl. VAT/month)

DPO designation with the CNIL in under 5 days Priority alert in case of a data breach No minimum contract term

+80 organisations supported

0 CNIL sanctions

4.9/5 client satisfaction

DPO: meaning, definition and role under the GDPR

DPO means Data Protection Officer, or Délégué à la Protection des Données (DPD) in French. The DPO advises the organisation on data protection, monitors compliance with the applicable rules and acts as a point of contact for the supervisory authority and for data subjects.

The DPO’s minimum tasks are set out in particular in GDPR Articles 38 and 39: information and advice, monitoring compliance, advice on DPIAs, cooperation with the supervisory authority and acting as a point of contact.

Advice

The DPO helps management and teams interpret the applicable requirements.

Monitoring

The DPO reviews the organisation, documentation and practices relating to personal data.

Point of contact

The DPO engages with data subjects and cooperates with the CNIL when required.

Support

Team support: awareness-raising, answers to operational questions and integration of data protection into the organisation’s projects. Monitoring GDPR compliance includes, in particular, awareness and training of staff involved in processing activities.

Which outsourced DPO package fits your organisation?

Answer the questions — the result shows an indicative range, not a quote.

Number of employees

Number of entities

Approximate number of processing activities

Sensitive data

International activity

Frequency of requests

Training need

DPIA need

Current compliance level

When is designation of a DPO mandatory?

Under GDPR Article 37, designating a DPO is not automatic for every organisation. It becomes mandatory in three main situations.

Public bodies

Designation is mandatory for public authorities and bodies, subject to the exceptions provided for in the text.

Regular and systematic large-scale monitoring

Where core activities involve regular and systematic monitoring of individuals on a large scale.

Large-scale processing of certain sensitive or criminal data

Where core activities involve, on a large scale, certain special categories of data or data relating to criminal convictions and offences.

Outside these situations, an organisation may also designate a DPO voluntarily in order to structure and steer its compliance.

Can you outsource the DPO function?

Yes. GDPR expressly provides that the DPO may be a member of the organisation’s staff or perform their tasks on the basis of a service contract. The CNIL also confirms that a DPO may be external and, under certain conditions, shared across several organisations. See what a shared external DPO is.

Expertise available quickly

Immediate access to DPO expertise, without a recruitment delay or an internal upskilling period.

Independence

Generally a clearer separation from determining the purposes and means of processing: conflicts of interest still need to be analysed, including for an external or shared DPO.

Continuity

The mission remains covered in case of absence, with a replacement arrangement around the named DPO.

No recruitment

No dedicated headcount and no salary cost: the DPO function is entrusted under a service contract.

Cost matched to the need

A monthly fee sized to the actual processing volume, rather than a fixed recruitment cost.

Access to several areas of expertise

The named DPO is supported by a back office (documentation, monitoring, continuity) rather than a single isolated skill set.

What is a shared external DPO?

The same DPO may, under certain conditions, perform the role for several organisations. This arrangement makes it possible to share specialised expertise while maintaining the accessibility, resources and absence of conflicts of interest required to perform the function. The CNIL confirms that sharing a DPO is possible under conditions. A shared DPO is a form of outsourced DPO.

Accessibility

A shared DPO must remain easily reachable from each organisation: data subjects, the supervisory authority and internal teams.

Resources

They must have the time, means and organisation needed to perform their tasks for all of the organisations concerned.

No conflict of interest

Sharing a DPO does not remove the need to analyse conflicts of interest. Each designation remains nominative and specific to the organisation.

The CNIL states that a DPO, internal or external, may be designated for several organisations under certain conditions. It has also published a method for identifying conflicts of interest, including for shared DPOs.

How to designate your external DPO with the CNIL?

Designating an external DPO with the CNIL follows a clear process. The organisation remains the designating body; we prepare the file and support the formality on the online service.

01

Choosing the DPO

Skills, independence and absence of conflict of interest — to be verified, including for an external DPO.

02

Service contract

Definition of the scope and of the resources, set out in the letter of engagement.

03

Designation with the CNIL

Submitting the designation via the online service provided for that purpose.

04

Publication of contact details

The GDPR notably requires the DPO’s contact details to be published and communicated to the supervisory authority.

05

Mission launch

Initial review, roadmap and ongoing steering.

The designation is nominative. Before submission to the CNIL online service, you know the person who will actually perform the role. See who will perform the DPO function.

What does your outsourced DPO actually do?

This structure reflects the tasks set out in GDPR Articles 38 and 39: information and advice, monitoring compliance, DPIAs, cooperation with the supervisory authority and acting as a point of contact. The exact scope of each package is set out in the pricing and the letter of engagement.

Governance & documentation

  • records of processing;
  • documentation;
  • policies;
  • procedures;
  • evidence tracking.

Operational advice

  • new projects;
  • tools;
  • contracts;
  • marketing;
  • HR;
  • processors.

Compliance monitoring

  • reviews;
  • audits;
  • gap tracking;
  • action plan.

DPIA

  • identifying when a DPIA is needed;
  • methodological advice;
  • DPO opinion.

Data subject rights

  • organising procedures;
  • support on complex requests.

Personal data breaches

  • qualification;
  • support;
  • documentation;
  • help with notification if needed.

Awareness

  • teams;
  • business owners;
  • management.

Relations with the CNIL

  • point of contact;
  • support for exchanges.

The first steps of your DPO support

A structured start to move from designation to operational steering within a month.

Week 1

Designation and scoping

  • letter of engagement;
  • collection of the necessary information;
  • designation with the CNIL;
  • identification of internal contacts;
  • opening of the communication channel.

Week 2

Initial review

  • records of processing;
  • documents;
  • processors;
  • rights;
  • security;
  • sensitive processing;
  • DPIAs;
  • incident history.

Week 3

Prioritisation

  • identification of the main gaps;
  • initial action plan;
  • definition of urgencies;
  • organisation of internal responsibilities.

Week 4

Steering setup

  • first meeting with management;
  • annual calendar;
  • scheduling of actions;
  • definition of reporting.

The DPO then becomes the ongoing owner of the framework, not a one-off audit assignment.

The exact timetable depends on maturity, the number of processing activities and the availability of documents.

How does your DPO steer compliance throughout the year?

The monthly subscription funds a governance function that is actually steered — not merely a presence “just in case”.

Ongoing

  • team questions;
  • new projects;
  • incidents;
  • contracts.

Monthly

  • request tracking;
  • action plan;
  • new processing activities.

Quarterly

  • KPIs;
  • risk review;
  • roadmap progress.

Annually

  • DPO annual review;
  • priorities;
  • control programme;
  • awareness;
  • plan update.

The exact frequency of review meetings depends on the package. See outsourced DPO pricing.

In-house DPO or outsourced DPO: which option should you choose?

Two possible models — the right choice depends on your organisation, not only on company size.

Criterion In-house DPO Outsourced DPO
Recruitment needed if a dedicated role no
Integration in the organisation very strong strong if the mission is well scoped
Independence to be organised generally easier to preserve
Conflicts of interest to be monitored also to be verified
Availability depends on the role depends on the package / SLA
Skills depends on the profile specialisation possible
Cost salary + charges subscription / service fee
Continuity depends on one person provider’s organisation

An external DPO is not automatically independent, nor free of conflicts of interest. Even an external DPO must be assessed in light of their other tasks and relationships. The CNIL has published a method for identifying conflicts of interest, including for shared DPOs. The right choice also depends on processing volume, sensitivity and internal resources.

What is the difference between a GDPR consultant and an outsourced DPO?

A DPO subscription is not “a few hours of advice”. A formally designated DPO performs a function set out in the GDPR, over time.

GDPR consultant

They generally work on a defined assignment: audit, documentation, compliance implementation or a specific project.

Outsourced DPO

They formally perform the DPO function, in line with independence requirements and the tasks set out in the GDPR, and the role is ongoing.

A formally designated DPO benefits from a specific status and safeguards set out in Articles 37 to 39 of the GDPR. A GDPR consultant may prepare or support a project; that role alone does not mean they perform the DPO function.

Who will perform the DPO role for your organisation?

The designation is nominative. Before signing, you know the person who will perform the role — not merely an anonymous “certified expert”.

Named DPO, designated individually

An identified person, not a black box

You are not designating Complianz System as a black box: before signing, you know who will actually perform the DPO function, as well as the operational framework of the engagement.

Receive the designated DPO profile

Before signing, you know:

  • Identity and profile of the designated person Name and profile of the person who will be declared to the CNIL for your organisation.
  • Experience Background, types of organisations supported and level of experience in data protection.
  • Skills Skills brought to the mission (advice, monitoring, DPIAs, data subject rights, relations with the authority).
  • Any competence certification If the designated person holds one: exact title, certifying body and, where applicable, the CNIL accreditation number of the certifier — on documentary evidence. The CNIL does not accredit the DPO personally, but the certifying body.
  • Continuity contact Replacement arrangement to maintain DPO availability in case of absence.
  • Access arrangements Channels and conditions for exchanging with the named DPO (review meetings, urgencies, documentation).
  • Scope Mission scope set out in the letter of engagement, aligned with the selected package.
  • Time included Volume of support included in the package, before any possible overage.
  • Response times Contractual first-response and handling times, according to the package.

A competence certification is not required to act as DPO, and the CNIL does not itself certify the officer: it accredits certifying bodies. We do not use the wording “CNIL-certified DPO”. When a certification is presented, it is only for the person actually assigned, as “DPO holding a competence certification issued by a body accredited by the CNIL”, on verifiable documents provided before designation.

An independent DPO, yet integrated into your organisation

The DPO must be able to perform their role without a conflict of interest, while having the access and resources they need. This is assessed case by case, including for an external or shared DPO.

Access to management

The DPO can escalate risks and recommendations to the appropriate decision-making level.

No conflict of interest

Even an external DPO must be assessed in light of their other tasks and relationships. They must not themselves determine the purposes or means of the processing they monitor.

Access to information

Teams provide the documents, projects and incidents needed for the DPO to perform their role.

Adequate resources

The level of service must be consistent with the size, structure and complexity of the organisation.

Involved early enough in projects

The DPO must be involved in a timely manner in matters relating to the protection of personal data.

No instructions on their conclusions

The GDPR provides that the DPO does not receive instructions regarding the exercise of their tasks.

The CNIL stresses independence, the identification of conflicts of interest — including for shared DPOs — and the allocation of sufficient resources to the DPO.

How much does an outsourced DPO cost?

The fee depends mainly on the number of processing activities, the size of the organisation, the sensitivity of the data, the number of entities, the support frequency and the DPO time required. No minimum contract term.

Essential DPO

from €290 excl. VAT / month

For organisations with low GDPR activity. Range €290 to €490 excl. VAT/month depending on volume.

  • Designation with the CNIL
  • Named DPO contact
  • 4 hours / quarter of DPO time included
  • Advice
  • Annual review
  • Documentation follow-up
Choose this package

Reinforced DPO

from €990 excl. VAT / month

Complex organisations, multiple entities, sensitive data. Range €990 to €1,490 excl. VAT/month.

  • 12 hours / month of DPO time included
  • Complex organisations
  • Multiple entities
  • Sensitive data
  • Numerous projects
  • Higher assistance volume
Choose this package

Package comparison matrix

Criterion Essential Steering Reinforced
Indicative fee from €290 excl. VAT/month from €590 excl. VAT/month from €990 excl. VAT/month
DPO time included 4 h / quarter 6 h / month 12 h / month
Consumption Quarterly allowance Monthly allowance Monthly allowance
Number of entities 1 Up to 3 Up to 5
Processing activities Up to 15 Up to 40 Unlimited*
Meeting frequency Quarterly Monthly Monthly + committee
Rights requests included 4 / month 8 / month Unlimited*
Awareness Extra 1 session / year Recurring sessions
DPIA Extra Advice included Advice + closer follow-up

Hours are a DPO availability allowance (advice, reviews, documentation, incidents). They are consumed within the period (quarter or month) and are not carried over. Overage is quoted separately. * Within a reasonable volume defined in the letter of engagement.

The entry price of €290 excl. VAT/month corresponds to the Essential DPO package (low GDPR activity, 4 h / quarter). Steering DPO starts at €590 excl. VAT/month (6 h / month) and Reinforced DPO at €990 excl. VAT/month (12 h / month). Indicative pricing excl. VAT — no minimum contract term. A tailored quote is provided within 24 hours.

The DPO advises and monitors — they do not decide in the organisation’s place

A clear scope, without misleading promises. The DPO informs, advises and monitors; the organisation remains responsible for its processing and the decisions it takes.

They are not the controller

Responsibility for processing choices remains with the organisation.

They do not decide on purposes and means

Otherwise they could become judge and party and create a conflict of interest. The CNIL states that a DPO must not hold a role that leads them to determine the purposes and means of the processing they are then required to monitor.

They do not guarantee “100% compliance”

They advise, monitor, alert and support; the organisation itself must implement the necessary decisions.

They are not a mere documentation provider

To actually fulfil their role, they must be involved early enough in personal-data matters and have the information and resources they need.

Your questions about outsourced DPO

Our DPO experts respond within 24 hours to any question about your Data Protection Officer.

Contact us
What does DPO stand for?

DPO stands for Data Protection Officer. In French, the equivalent is délégué à la protection des données (DPD). The DPO supports the organisation in applying the GDPR and the rules on personal data protection. See also DPO meaning, definition and role.

What is a DPO?

A DPO is the Data Protection Officer designated by an organisation. They inform, advise and monitor compliance with the applicable framework, and act in particular as a contact point for the supervisory authority and for data subjects.

What is the role of a DPO?

The DPO’s role is to support the organisation: advice, compliance monitoring, opinions on DPIAs, cooperation with the supervisory authority and contact point. They are not the controller and do not determine the purposes and means of processing. See the DPO role and what the DPO does not do.

What are the DPO’s tasks?

The DPO’s minimum tasks are set out in particular in Articles 38 and 39 of the GDPR: information and advice, monitoring compliance, advice on DPIAs, cooperation with the supervisory authority and acting as a contact point. Operational detail is in what your outsourced DPO actually does.

In which organisations is a DPO mandatory?

Under Article 37 of the GDPR, designation is in particular mandatory:

  • for public authorities and bodies;
  • where core activities require regular and systematic monitoring of individuals at large scale;
  • where core activities consist of large-scale processing of sensitive data or data relating to criminal offences.

See when designating a DPO is mandatory.

Does an SME have to have a DPO?

Not automatically. The obligation does not depend on company size, but on the criteria in Article 37. An SME may still designate a DPO voluntarily to structure and steer compliance. For an indicative range, use the package estimator.

Can you outsource your DPO?

Yes. The GDPR expressly allows an external service: the DPO may be a staff member or perform their tasks under a service contract (Article 37.6). See Can you outsource the DPO function?.

Must an external DPO be declared to the CNIL?

The formal designation is communicated to the supervisory authority. The designating organisation submits it via the CNIL online service. The DPO’s contact details are also published so they can be reached easily. See how to designate your external DPO with the CNIL.

Does the CNIL choose my DPO?

No. The organisation chooses and designates its DPO. The CNIL receives the communication of that designation; it does not choose the officer in the organisation’s place.

Do you need a certification to become a DPO?

No. A skills certification is not mandatory to perform the DPO function. Where a certification exists, it is issued by a certification body accredited by the CNIL, not by the CNIL itself.

What is the difference between an in-house and an external DPO?

An in-house DPO is an employee of the organisation. An external DPO performs the same function under a service contract. Independence, resources and the absence of conflicts of interest apply in both cases. See the in-house / outsourced comparison and the distinction with a GDPR consultant.

What is a shared DPO?

The same DPO may, under certain conditions, perform the role for several organisations. This arrangement makes it possible to share specialised expertise while maintaining accessibility, resources and the absence of conflicts of interest. The CNIL confirms that sharing a DPO is possible under conditions. See what a shared external DPO is.

What is the fee for an outsourced DPO?

The fee depends mainly on the number of processing activities, organisation size, data sensitivity, number of entities and the DPO time required. Essential DPO starts from €290/month excl. VAT (4 h / quarter), Steering DPO at €590 excl. VAT/month (6 h / month) and Reinforced DPO at €990 excl. VAT/month (12 h / month). See outsourced DPO pricing.

How many DPO hours are needed per month?

It depends on processing volume, projects and incoming requests. Packages include 4 h / quarter (Essential DPO), 6 h / month (Steering DPO) or 12 h / month (Reinforced DPO). These hours are a period allowance and do not roll over. The package estimator gives an indicative range.

Is the DPO liable if the organisation is not GDPR-compliant?

No. The DPO performs an advisory and monitoring function. Their presence does not transfer the controller’s organisational responsibilities to the DPO. The organisation remains responsible for its processing and the decisions it takes. See what the DPO does not do.

Can a DPO hold other roles?

Yes, only if they do not create a conflict of interest. A DPO must not hold a position that leads them to determine the purposes and means of the processing they would then have to monitor. See DPO independence.

Can the DPO be a lawyer?

Yes, depending on the context, like other external professionals, provided in particular that the requirements of the function are met and conflicts of interest are avoided. The CNIL accepts an external DPO, whether a natural or legal person.

Ready to designate your outsourced DPO?

We fulfil your DPO role from €290/month, with a named designation and competence evidence shared before engagement. DPO designation with the CNIL in under 5 days. First conversation free, no obligation.

Designate my outsourced DPO
From €290/month excl. VAT Designation with the CNIL within 5 days No commitment
Innovation hub