Number of employees
Outsourced Data Protection Officer Outsourced DPO — your dedicated GDPR expert, from €290/month
We fulfil the outsourced DPO (Data Protection Officer) role for your organisation: official designation with the CNIL, records of processing maintenance, handling data subject rights requests, team awareness and ongoing regulatory monitoring. Support aligned with GDPR Articles 37 to 39, without recruitment costs.
GDPR explicitly allows a DPO to be internal or to perform their tasks under a service contract; the CNIL also confirms that a DPO may be external and, under certain conditions, shared across several organisations.
What you get
With your outsourced DPO
A dedicated DPO for your organisation, designated by name with the CNIL — ongoing advice, monitoring and support, without recruitment costs. Identity and competence evidence provided before engagement.
An in-house DPO costs €50,000 to €80,000/year — the Essential DPO starts at €3,480 excl. VAT/year (€290 excl. VAT/month)
Understanding the DPO’s role
DPO: meaning, definition and role under the GDPR
DPO means Data Protection Officer, or Délégué à la Protection des Données (DPD) in French. The DPO advises the organisation on data protection, monitors compliance with the applicable rules and acts as a point of contact for the supervisory authority and for data subjects.
The DPO’s minimum tasks are set out in particular in GDPR Articles 38 and 39: information and advice, monitoring compliance, advice on DPIAs, cooperation with the supervisory authority and acting as a point of contact.
Advice
The DPO helps management and teams interpret the applicable requirements.
Monitoring
The DPO reviews the organisation, documentation and practices relating to personal data.
Point of contact
The DPO engages with data subjects and cooperates with the CNIL when required.
Support
Team support: awareness-raising, answers to operational questions and integration of data protection into the organisation’s projects. Monitoring GDPR compliance includes, in particular, awareness and training of staff involved in processing activities.
Pricing calculator
Which outsourced DPO package fits your organisation?
Answer the questions — the result shows an indicative range, not a quote.
Number of entities
Approximate number of processing activities
Sensitive data
International activity
Frequency of requests
Training need
DPIA need
Current compliance level
Mandatory or optional DPO?
When is designation of a DPO mandatory?
Under GDPR Article 37, designating a DPO is not automatic for every organisation. It becomes mandatory in three main situations.
Public bodies
Designation is mandatory for public authorities and bodies, subject to the exceptions provided for in the text.
Regular and systematic large-scale monitoring
Where core activities involve regular and systematic monitoring of individuals on a large scale.
Large-scale processing of certain sensitive or criminal data
Where core activities involve, on a large scale, certain special categories of data or data relating to criminal convictions and offences.
Outside these situations, an organisation may also designate a DPO voluntarily in order to structure and steer its compliance.
Can you outsource your DPO?
Can you outsource the DPO function?
Yes. GDPR expressly provides that the DPO may be a member of the organisation’s staff or perform their tasks on the basis of a service contract. The CNIL also confirms that a DPO may be external and, under certain conditions, shared across several organisations. See what a shared external DPO is.
Expertise available quickly
Immediate access to DPO expertise, without a recruitment delay or an internal upskilling period.
Independence
Generally a clearer separation from determining the purposes and means of processing: conflicts of interest still need to be analysed, including for an external or shared DPO.
Continuity
The mission remains covered in case of absence, with a replacement arrangement around the named DPO.
No recruitment
No dedicated headcount and no salary cost: the DPO function is entrusted under a service contract.
Cost matched to the need
A monthly fee sized to the actual processing volume, rather than a fixed recruitment cost.
Access to several areas of expertise
The named DPO is supported by a back office (documentation, monitoring, continuity) rather than a single isolated skill set.
Shared DPO
What is a shared external DPO?
The same DPO may, under certain conditions, perform the role for several organisations. This arrangement makes it possible to share specialised expertise while maintaining the accessibility, resources and absence of conflicts of interest required to perform the function. The CNIL confirms that sharing a DPO is possible under conditions. A shared DPO is a form of outsourced DPO.
Accessibility
A shared DPO must remain easily reachable from each organisation: data subjects, the supervisory authority and internal teams.
Resources
They must have the time, means and organisation needed to perform their tasks for all of the organisations concerned.
No conflict of interest
Sharing a DPO does not remove the need to analyse conflicts of interest. Each designation remains nominative and specific to the organisation.
The CNIL states that a DPO, internal or external, may be designated for several organisations under certain conditions. It has also published a method for identifying conflicts of interest, including for shared DPOs.
External DPO and the CNIL
How to designate your external DPO with the CNIL?
Designating an external DPO with the CNIL follows a clear process. The organisation remains the designating body; we prepare the file and support the formality on the online service.
01
Choosing the DPO
Skills, independence and absence of conflict of interest — to be verified, including for an external DPO.
02
Service contract
Definition of the scope and of the resources, set out in the letter of engagement.
03
Designation with the CNIL
Submitting the designation via the online service provided for that purpose.
04
Publication of contact details
The GDPR notably requires the DPO’s contact details to be published and communicated to the supervisory authority.
05
Mission launch
Initial review, roadmap and ongoing steering.
The designation is nominative. Before submission to the CNIL online service, you know the person who will actually perform the role. See who will perform the DPO function.
What the DPO service includes
What does your outsourced DPO actually do?
This structure reflects the tasks set out in GDPR Articles 38 and 39: information and advice, monitoring compliance, DPIAs, cooperation with the supervisory authority and acting as a point of contact. The exact scope of each package is set out in the pricing and the letter of engagement.
Governance & documentation
- records of processing;
- documentation;
- policies;
- procedures;
- evidence tracking.
Operational advice
- new projects;
- tools;
- contracts;
- marketing;
- HR;
- processors.
Compliance monitoring
- reviews;
- audits;
- gap tracking;
- action plan.
DPIA
- identifying when a DPIA is needed;
- methodological advice;
- DPO opinion.
Data subject rights
- organising procedures;
- support on complex requests.
Personal data breaches
- qualification;
- support;
- documentation;
- help with notification if needed.
Awareness
- teams;
- business owners;
- management.
Relations with the CNIL
- point of contact;
- support for exchanges.
What you get in the first 30 days
The first steps of your DPO support
A structured start to move from designation to operational steering within a month.
Week 1
Designation and scoping
- letter of engagement;
- collection of the necessary information;
- designation with the CNIL;
- identification of internal contacts;
- opening of the communication channel.
Week 2
Initial review
- records of processing;
- documents;
- processors;
- rights;
- security;
- sensitive processing;
- DPIAs;
- incident history.
Week 3
Prioritisation
- identification of the main gaps;
- initial action plan;
- definition of urgencies;
- organisation of internal responsibilities.
Week 4
Steering setup
- first meeting with management;
- annual calendar;
- scheduling of actions;
- definition of reporting.
The DPO then becomes the ongoing owner of the framework, not a one-off audit assignment.
The exact timetable depends on maturity, the number of processing activities and the availability of documents.
Steering cadence
How does your DPO steer compliance throughout the year?
The monthly subscription funds a governance function that is actually steered — not merely a presence “just in case”.
Ongoing
- team questions;
- new projects;
- incidents;
- contracts.
Monthly
- request tracking;
- action plan;
- new processing activities.
Quarterly
- KPIs;
- risk review;
- roadmap progress.
Annually
- DPO annual review;
- priorities;
- control programme;
- awareness;
- plan update.
The exact frequency of review meetings depends on the package. See outsourced DPO pricing.
In-house or outsourced
In-house DPO or outsourced DPO: which option should you choose?
Two possible models — the right choice depends on your organisation, not only on company size.
| Criterion | In-house DPO | Outsourced DPO |
|---|---|---|
| Recruitment | needed if a dedicated role | no |
| Integration in the organisation | very strong | strong if the mission is well scoped |
| Independence | to be organised | generally easier to preserve |
| Conflicts of interest | to be monitored | also to be verified |
| Availability | depends on the role | depends on the package / SLA |
| Skills | depends on the profile | specialisation possible |
| Cost | salary + charges | subscription / service fee |
| Continuity | depends on one person | provider’s organisation |
An external DPO is not automatically independent, nor free of conflicts of interest. Even an external DPO must be assessed in light of their other tasks and relationships. The CNIL has published a method for identifying conflicts of interest, including for shared DPOs. The right choice also depends on processing volume, sensitivity and internal resources.
Outsourced DPO vs GDPR consultant
What is the difference between a GDPR consultant and an outsourced DPO?
A DPO subscription is not “a few hours of advice”. A formally designated DPO performs a function set out in the GDPR, over time.
GDPR consultant
They generally work on a defined assignment: audit, documentation, compliance implementation or a specific project.
Outsourced DPO
They formally perform the DPO function, in line with independence requirements and the tasks set out in the GDPR, and the role is ongoing.
A formally designated DPO benefits from a specific status and safeguards set out in Articles 37 to 39 of the GDPR. A GDPR consultant may prepare or support a project; that role alone does not mean they perform the DPO function.
Who is actually your DPO?
Who will perform the DPO role for your organisation?
The designation is nominative. Before signing, you know the person who will perform the role — not merely an anonymous “certified expert”.
Named DPO, designated individually
An identified person, not a black box
You are not designating Complianz System as a black box: before signing, you know who will actually perform the DPO function, as well as the operational framework of the engagement.
Receive the designated DPO profileBefore signing, you know:
- Identity and profile of the designated person Name and profile of the person who will be declared to the CNIL for your organisation.
- Experience Background, types of organisations supported and level of experience in data protection.
- Skills Skills brought to the mission (advice, monitoring, DPIAs, data subject rights, relations with the authority).
- Any competence certification If the designated person holds one: exact title, certifying body and, where applicable, the CNIL accreditation number of the certifier — on documentary evidence. The CNIL does not accredit the DPO personally, but the certifying body.
- Continuity contact Replacement arrangement to maintain DPO availability in case of absence.
- Access arrangements Channels and conditions for exchanging with the named DPO (review meetings, urgencies, documentation).
- Scope Mission scope set out in the letter of engagement, aligned with the selected package.
- Time included Volume of support included in the package, before any possible overage.
- Response times Contractual first-response and handling times, according to the package.
A competence certification is not required to act as DPO, and the CNIL does not itself certify the officer: it accredits certifying bodies. We do not use the wording “CNIL-certified DPO”. When a certification is presented, it is only for the person actually assigned, as “DPO holding a competence certification issued by a body accredited by the CNIL”, on verifiable documents provided before designation.
DPO independence
An independent DPO, yet integrated into your organisation
The DPO must be able to perform their role without a conflict of interest, while having the access and resources they need. This is assessed case by case, including for an external or shared DPO.
Access to management
The DPO can escalate risks and recommendations to the appropriate decision-making level.
No conflict of interest
Even an external DPO must be assessed in light of their other tasks and relationships. They must not themselves determine the purposes or means of the processing they monitor.
Access to information
Teams provide the documents, projects and incidents needed for the DPO to perform their role.
Adequate resources
The level of service must be consistent with the size, structure and complexity of the organisation.
Involved early enough in projects
The DPO must be involved in a timely manner in matters relating to the protection of personal data.
No instructions on their conclusions
The GDPR provides that the DPO does not receive instructions regarding the exercise of their tasks.
The CNIL stresses independence, the identification of conflicts of interest — including for shared DPOs — and the allocation of sufficient resources to the DPO.
Outsourced DPO pricing
How much does an outsourced DPO cost?
The fee depends mainly on the number of processing activities, the size of the organisation, the sensitivity of the data, the number of entities, the support frequency and the DPO time required. No minimum contract term.
Essential DPO
from €290 excl. VAT / month
For organisations with low GDPR activity. Range €290 to €490 excl. VAT/month depending on volume.
- Designation with the CNIL
- Named DPO contact
- 4 hours / quarter of DPO time included
- Advice
- Annual review
- Documentation follow-up
Steering DPO
from €590 excl. VAT / month
For regular steering. Range €590 to €890 excl. VAT/month depending on volume.
- 6 hours / month of DPO time included
- Higher availability
- Regular reviews
- Roadmap steering
- DPIA support
- Awareness
- Reporting
Reinforced DPO
from €990 excl. VAT / month
Complex organisations, multiple entities, sensitive data. Range €990 to €1,490 excl. VAT/month.
- 12 hours / month of DPO time included
- Complex organisations
- Multiple entities
- Sensitive data
- Numerous projects
- Higher assistance volume
Package comparison matrix
| Criterion | Essential | Steering | Reinforced |
|---|---|---|---|
| Indicative fee | from €290 excl. VAT/month | from €590 excl. VAT/month | from €990 excl. VAT/month |
| DPO time included | 4 h / quarter | 6 h / month | 12 h / month |
| Consumption | Quarterly allowance | Monthly allowance | Monthly allowance |
| Number of entities | 1 | Up to 3 | Up to 5 |
| Processing activities | Up to 15 | Up to 40 | Unlimited* |
| Meeting frequency | Quarterly | Monthly | Monthly + committee |
| Rights requests included | 4 / month | 8 / month | Unlimited* |
| Awareness | Extra | 1 session / year | Recurring sessions |
| DPIA | Extra | Advice included | Advice + closer follow-up |
Hours are a DPO availability allowance (advice, reviews, documentation, incidents). They are consumed within the period (quarter or month) and are not carried over. Overage is quoted separately. * Within a reasonable volume defined in the letter of engagement.
The entry price of €290 excl. VAT/month corresponds to the Essential DPO package (low GDPR activity, 4 h / quarter). Steering DPO starts at €590 excl. VAT/month (6 h / month) and Reinforced DPO at €990 excl. VAT/month (12 h / month). Indicative pricing excl. VAT — no minimum contract term. A tailored quote is provided within 24 hours.
What the DPO does not do
The DPO advises and monitors — they do not decide in the organisation’s place
A clear scope, without misleading promises. The DPO informs, advises and monitors; the organisation remains responsible for its processing and the decisions it takes.
They are not the controller
Responsibility for processing choices remains with the organisation.
They do not decide on purposes and means
Otherwise they could become judge and party and create a conflict of interest. The CNIL states that a DPO must not hold a role that leads them to determine the purposes and means of the processing they are then required to monitor.
They do not guarantee “100% compliance”
They advise, monitor, alert and support; the organisation itself must implement the necessary decisions.
They are not a mere documentation provider
To actually fulfil their role, they must be involved early enough in personal-data matters and have the information and resources they need.
What does DPO stand for?
DPO stands for Data Protection Officer. In French, the equivalent is délégué à la protection des données (DPD). The DPO supports the organisation in applying the GDPR and the rules on personal data protection. See also DPO meaning, definition and role.
What is a DPO?
A DPO is the Data Protection Officer designated by an organisation. They inform, advise and monitor compliance with the applicable framework, and act in particular as a contact point for the supervisory authority and for data subjects.
What is the role of a DPO?
The DPO’s role is to support the organisation: advice, compliance monitoring, opinions on DPIAs, cooperation with the supervisory authority and contact point. They are not the controller and do not determine the purposes and means of processing. See the DPO role and what the DPO does not do.
What are the DPO’s tasks?
The DPO’s minimum tasks are set out in particular in Articles 38 and 39 of the GDPR: information and advice, monitoring compliance, advice on DPIAs, cooperation with the supervisory authority and acting as a contact point. Operational detail is in what your outsourced DPO actually does.
In which organisations is a DPO mandatory?
Under Article 37 of the GDPR, designation is in particular mandatory:
- for public authorities and bodies;
- where core activities require regular and systematic monitoring of individuals at large scale;
- where core activities consist of large-scale processing of sensitive data or data relating to criminal offences.
Does an SME have to have a DPO?
Not automatically. The obligation does not depend on company size, but on the criteria in Article 37. An SME may still designate a DPO voluntarily to structure and steer compliance. For an indicative range, use the package estimator.
Can you outsource your DPO?
Yes. The GDPR expressly allows an external service: the DPO may be a staff member or perform their tasks under a service contract (Article 37.6). See Can you outsource the DPO function?.
Must an external DPO be declared to the CNIL?
The formal designation is communicated to the supervisory authority. The designating organisation submits it via the CNIL online service. The DPO’s contact details are also published so they can be reached easily. See how to designate your external DPO with the CNIL.
Does the CNIL choose my DPO?
No. The organisation chooses and designates its DPO. The CNIL receives the communication of that designation; it does not choose the officer in the organisation’s place.
Do you need a certification to become a DPO?
No. A skills certification is not mandatory to perform the DPO function. Where a certification exists, it is issued by a certification body accredited by the CNIL, not by the CNIL itself.
What is the difference between an in-house and an external DPO?
An in-house DPO is an employee of the organisation. An external DPO performs the same function under a service contract. Independence, resources and the absence of conflicts of interest apply in both cases. See the in-house / outsourced comparison and the distinction with a GDPR consultant.
What is a shared DPO?
The same DPO may, under certain conditions, perform the role for several organisations. This arrangement makes it possible to share specialised expertise while maintaining accessibility, resources and the absence of conflicts of interest. The CNIL confirms that sharing a DPO is possible under conditions. See what a shared external DPO is.
What is the fee for an outsourced DPO?
The fee depends mainly on the number of processing activities, organisation size, data sensitivity, number of entities and the DPO time required. Essential DPO starts from €290/month excl. VAT (4 h / quarter), Steering DPO at €590 excl. VAT/month (6 h / month) and Reinforced DPO at €990 excl. VAT/month (12 h / month). See outsourced DPO pricing.
How many DPO hours are needed per month?
It depends on processing volume, projects and incoming requests. Packages include 4 h / quarter (Essential DPO), 6 h / month (Steering DPO) or 12 h / month (Reinforced DPO). These hours are a period allowance and do not roll over. The package estimator gives an indicative range.
Is the DPO liable if the organisation is not GDPR-compliant?
No. The DPO performs an advisory and monitoring function. Their presence does not transfer the controller’s organisational responsibilities to the DPO. The organisation remains responsible for its processing and the decisions it takes. See what the DPO does not do.
Can a DPO hold other roles?
Yes, only if they do not create a conflict of interest. A DPO must not hold a position that leads them to determine the purposes and means of the processing they would then have to monitor. See DPO independence.
Can the DPO be a lawyer?
Yes, depending on the context, like other external professionals, provided in particular that the requirements of the function are met and conflicts of interest are avoided. The CNIL accepts an external DPO, whether a natural or legal person.
Ready to designate your outsourced DPO?
We fulfil your DPO role from €290/month, with a named designation and competence evidence shared before engagement. DPO designation with the CNIL in under 5 days. First conversation free, no obligation.