Data protection advice: What managing directors really need to pay attention to in 2026
Data protection consulting in 2026 is not a one-time audit, but an ongoing operational process. Anyone who only books consultants as appraisers pays twice. Read about what level of performance really counts and how consulting can be translated into a verifiable workspace.
Since the GDPR came into force on May 25, 2018, data protection is no longer a one-off compliance exercise, but rather an ongoing issue with significant liability risk for management. Art. 83 GDPR allows fines of up to 20 million euros or 4% of global group sales, and in 2025 the German supervisory authorities have noticeably shortened the inspection intervals and expanded the sampling quota. Anyone who purchases data protection advice in this situation is rarely looking for a theoretical report or a colorful series of slides. What is required is a service that documents the order, directory in accordance with Art. 30 GDPR, reporting channels, training plan and order processing in such a way that the supervisory authority does not stumble in the sample and the management can prove in the board meeting who is taking on which measure and by when.
This article shows what data protection consulting has to do in 2026, which price models are realistic, what the difference is between hourly fees and operational anchoring and how Consultant output can be translated into a testable workspace. For this purpose, CIVAC operates a Compliance Platform and Officer-as-a-Service: You licence the workspace for your internal representatives, or you have CIVAC appoint the external representatives. Both models end with the same file, the same evidence and the same reporting line to management: appointment certificate, signed, neatly filed, verifiable at any time.
Key Takeaways
- Data protection advice without an appointment certificate and a list in accordance with Art. 30 GDPR is not usable evidence in the supervisory procedure.
- External advice is typically priced according to the number of employees and risk class and is between 380 and 1,800 euros per month in 2026.
- The deadline according to Art. 33 GDPR is 72 hours from the time of knowledge, not from the internal escalation to the management.
What data protection consulting must do in 2026
Data protection consulting today describes much more than the creation of a data protection declaration for the website or a one-off awareness training for the workforce. Since 2024, the German supervisory authorities have been increasingly checking the operational implementation, i.e. whether processing directories are currently maintained, whether order processing has been concluded in accordance with Art. 28 GDPR with all eight minimum contents and whether the reporting obligation in accordance with Art. 33 GDPR has actually been operationalized within 72 hours of becoming aware of it. A reliable consultation therefore covers at least five core areas: the appointment of the data protection officer with a proper reporting line, ongoing directory maintenance, the technical and organisational measures in accordance with Art. 32 GDPR, the processing of the rights of those affected and the data breach reporting path with an escalation matrix.
Anyone who commissions a data protection consultancy will, in the best case, receive a prioritised action plan, an appointment proposal for the role of the representative and an audit schedule of twelve months. In the worst case scenario, the client receives 80 PDF pages with no link to day-to-day operations and no clear responsibilities. The difference between the two worlds only becomes apparent in an emergency: the inspector calls, the proof is ready, or not. CIVAC stores consulting results directly in the workspace and links each measure with the owner, deadline and evidence. In the background there are 490 ready-to-use audit templates and 93 controls according to ISO/IEC 27001:2022. If you are already looking for an external data protection officer, you will find the appointment certificates, the reporting line and the representation regulations in a consistent package. Advice becomes a resource, not a file on a shelf. It is precisely this interlinking that makes the difference between an expensive compliance project with a final report and a long-term routine that can be verified without any effort as soon as the supervisory authority wants to see concrete evidence. 80 PDF pages become 80 trackable tasks with owner, deadline and audit trail.
Internal or external advice: the honest decision matrix
The decision between internal and external data protection consulting is rarely a question of pride, but rather a question of hourly calculation and staffing levels. Section 38 BDSG requires a data protection officer as soon as at least 20 people are constantly involved in the automated processing of personal data. From this threshold onwards, the task of placing the order arises regardless of whether the person is employed internally or commissioned externally. Both variants require specialist knowledge, independence, freedom from instructions in the matter and a direct reporting line to the management. The supervisory authorities examine each of these requirements individually.
Internally, the close connection to the departments, the knowledge of internal processes and the immediate availability are convincing. Externally, the separation from the line, the extensive transfer of liability and the ongoing market monitoring by a consulting firm that manages twenty or more mandates in parallel are convincing. In practice, the deciding factor is the staffing level: If you can't or don't want to finance full-time data protection, you buy hours from an external consultant and forego the personal corridor in day-to-day business. However, those who employ internal staff absolutely need a platform so that the appointment certificate, directory in accordance with Art. 30 GDPR, proof of training and reporting path are stored in an audit-proof manner. CIVAC offers both options in parallel: Licence the workspace for your internal representatives, or have our representatives order it. If you want to clarify detailed questions, you will find the most common threshold values and ordering variants in a compact overview in the CIVAC-FAQ. Others run compliance like a filing cabinet. We run it like software. The decision must therefore be made based less on gut feeling than on the basis of the files: Who will act as a substitute during vacation, who will document the reports to the management, who will deliver the complete file status to the supervisory authority within 72 hours?
Costs and pricing models: what you realistically plan for
The prices for data protection consulting in Germany will fluctuate significantly in 2026 because the depth of services is not standardised and the market is served equally by individual law firms, consulting firms and platform providers. Realistically, three price levels can be distinguished. The hourly fee is between 140 and 280 euros net, suitable for specific individual questions, unsuitable for ongoing support. Monthly flat rates are between 380 and 720 euros net for smaller companies with up to 50 employees, and between 950 and 1,800 euros net for medium-sized companies with 200 to 800 employees. Project flat rates for initial implementations range between 4,500 and 18,000 euros net, depending on data depth, number of locations and processing risk.
The enormous price range is explained less by the hourly level than by the scope of the templates supplied, by the availability of the right to information processing in accordance with Art. 15 GDPR and by the agreed service level for data breach reports. CIVAC works with clearly defined service levels: The order is typically placed within 2 working days instead of the classic 2 to 6 weeks, the 72-hour reporting path is stored in the workspace and the reporting line to management is clearly documented. Anyone who obtains comparison offers should ask about the appointment certificate and the question about the number of audit templates provided. Providers without these documents sell consultation time, not compliance. CIVAC operates its compliance platform and Officer-as-a-Service with EU data residency and ISO 27001:2022 ISMS, so the advisory relationship itself does not create additional third country risks. Others run compliance like a filing cabinet. We run it like software. The transparent pricing logic protects against hidden hourly invoices and ensures that the data protection budget is included in the management's annual planning in a predictable manner, without subsequent special reports.
Audit templates, directory and reporting path: the mandatory program
The GDPR formulates a series of obligations that are regularly queried in the supervisory process and without which any advice quickly degenerates into theory. The list of processing activities in accordance with Art. 30 GDPR is the central evidence: It must record the person responsible, the purpose, the categories of data subjects, the recipients, any third-country transfers, the deletion periods and the technical-organisational measures. Without an up-to-date list, data protection advice is hardly reliable, because in the event of a dispute, the supervisory authority first checks this document and compares it with the actual processing in the specialist departments.
The reporting path according to Art. 33 GDPR requires a report to the responsible supervisory authority within 72 hours of becoming aware of the data breach. Deadline begins as soon as we become aware of it. In practice, operational implementation rarely fails due to legal understanding, but rather due to a lack of templates, an unclear escalation matrix and a lack of practice. CIVAC delivers the reporting path template, directory template and order processing template as an integral part of the 490 ready-to-use audit templates. Anyone who also interlinks the data protection officer with the information security officer also covers the NIS 2 interface, so that the 24-hour early warning and the 72-hour follow-up report run in a uniform escalation path. Advice without templates produces output that is of no use in day-to-day business. Templates without advice create form wars without control. Audit-proof, documented, Section 38-proof only emerges from the combination of both worlds, supplemented by a central platform that makes responsibilities visible. The audit templates also significantly reduce the preparation time for external audits because the directory, order processing and reporting path are in a single source of truth and do not have to be reconstructed in four different repositories before the supervisor can even appear.
Order and reporting line: the silent risk
One of the most common complaints in data protection audits in 2025 did not concern the data protection declaration or the cookie banners, but rather the appointment of the data protection officer itself. Section 38 BDSG requires the appointment in written or electronic form, Art. 38 GDPR also requires the publication of contact details and notification to the responsible supervisory authority. In practice, the appointment certificate with the date, signature and attachments to the reporting line is surprisingly often missing. Anyone who does not document properly here invites a fine that can hardly be refuted without a legal dispute and which also gives rise to the suspicion of further defects.
The reporting line to the management is the second hidden risk item. According to Art. 38 Para. 3 GDPR, the data protection officer reports directly to the highest management level, without instructions on the matter. In group structures, this line is regularly broken, for example because the representative is part of the compliance team and the compliance team reports to group compliance. CIVAC documents the reporting line as an attachment to the appointment certificate and keeps a report log in the workspace so that the supervisory authority can immediately trace the correct line in an emergency. The appointment certificate, signed, filed, verifiable. These six words explain why proper data protection advice begins with the order and not with the data protection declaration. The platform ensures that every change to the reporting line is logged in an audit-proof manner and that orders are accompanied by clear representation regulations. This ends the most common complaint before it can even arise. Anyone who fills the appointment internally can use the same mechanism and receives the same evidence as an externally appointed representative, without losing separation from the line.
Third country and order processing: the underestimated positions
The ECJ's Schrems II ruling of July 16, 2020 did not abolish the standard contractual clauses, but rather added an independent obligation to review them. Anyone who transfers personal data to third countries, for example to cloud providers in the United States, must document a transfer impact assessment and check whether the level of protection in the third country is sufficient in the specific individual case. The EU-US Data Privacy Framework of July 10, 2023 relieves the burden on certain certified recipients, but does not replace the standard contractual clauses in the 2021 version or the order processing contracts according to Art. 28 GDPR. This separation is often overlooked in practice.
In practice, order processing is the second lens of supervision. Every external service provider that processes personal data in accordance with instructions, such as the email provider, the payroll provider, the HR cloud provider or the CRM provider, must receive a contract with the eight minimum contents in accordance with Art. 28 Para. 3 GDPR. CIVAC maintains a central order processing list in the workspace and provides a standardised template that integrates the TOM system, subcontractor list and third country information. EU data residency is consistently ensured for CIVAC itself, so that the client data does not trigger any additional Schrems II questions in the advisory relationship. Anyone who does not systematically maintain third country and order processing risks a finding in every supervisory sample, which can lead to fines, official requirements and, last but not least, reputational damage in the supply chain. A clean list protects against exactly these procedures. For each listed service provider, CIVAC keeps the signed order processing agreement, the last TOM attachment and the date of the last effectiveness test available in the workspace and links each third-country transfer with a documented transfer impact assessment, which can be passed on to the supervisory authority as a PDF export at the push of a button, without additional work on the DSB side or long lead times for ad-hoc research.
If there is a fire: data breach and 72-hour deadline
In the event of a data breach, it is not the consultant who wrote a report six months ago that counts, but rather the process that is starting now. Art. 33 GDPR sets a reporting deadline of 72 hours from becoming aware of the violation of personal data protection. The clock starts on awareness. Anyone who maintains an internal escalation period of four days will have missed the deadline before they notice it and will already be fighting a losing battle in the subsequent proceedings.
The operational path consists of four steps: the structured initial recording with a time stamp, the risk assessment according to the criteria of the supervisory authorities, the report to the supervisory authority and, if necessary, the notification of those affected in accordance with Art. 34 GDPR. CIVAC stores each of these steps as a template and workflow in the workspace so that the initial recording is structured and the risk can be classified according to the criteria of the data protection conference. In conjunction with the NIS 2 reporting path, which requires 24-hour early warning and 72-hour follow-up reporting, a consolidated escalation path is created that serves both sets of rules at the same time and does not open any gaps. More about the interlinking of the paths can be found in the CIVAC overview of NIS 2 implementation in Germany. The auditor calls, the evidence is ready. The individual steps are logged in the workspace with a time stamp, responsible persons and attachments, so that the subsequent processing by the board of directors and the supervisory board can take place without subsequent reconstruction and the 72-hour deadline is clearly adhered to. The incident becomes a dossier that is still used in the audit two years later.
Training, effectiveness testing and annual audit
Data protection advice does not end with the order or the first directory. Art. 39 Paragraph 1 Letter b GDPR expressly requires awareness-raising and training of employees involved in processing operations. The supervisory authorities typically expect mandatory annual training with proof of participation, supplemented by target group-specific in-depth training, for example in HR, IT, marketing and sales. Anyone who only uses training as a one-off onboarding module overlooks the obligation to repeat it annually and does not provide current evidence in the audit. This causes the entire compliance argument to falter because the representative cannot prove his awareness-raising mandate.
The effectiveness test of the technical-organisational measures is the second annual routine. Art. 32 Paragraph 1 Letter d GDPR requires a documented procedure for regular review, assessment and evaluation of the effectiveness of these measures. In practice, this means an annual TOM review with documented results, which is ideally linked to the ISO/IEC 27001 ISMS so that findings are collected once and used in both worlds. CIVAC bundles training certificates, TOM reviews and annual audits in the workspace so that the three routines are visible in a dashboard and deadlines are automatically tracked. If you don't maintain this centrally, in an emergency you'll have to search four Outlook folders and three SharePoint libraries for the document that should actually be just a click away. The annual routine is the simplest way to keep an advisory relationship alive while at the same time providing the regulatory authorities with the required evidence. This shifts the discussion with management away from ad hoc crises towards a plannable annual routine with clear milestones, fixed reporting dates and a database that does not have to be collected during the audit, but is updated daily.
Advice as a resource: how to translate recommendations into routine
A data protection consultation only has an operational impact when its recommendations become a recurring process. This is rarely achieved through a PDF with 80 measures without a responsible person, but rather through a platform that links each measure with the owner, deadline, status and evidence. CIVAC operates this platform as a compliance platform and officer-as-a-service. The 490 ready-to-use audit templates, the 93 controls according to ISO/IEC 27001:2022 and the NIS-2 reporting path are anchored directly in the workspace, so that advice does not end in a report, but rather results in a task list with clear responsible persons and traceable progress.
The model is deliberately designed in two stages. Licence the workspace for your internal representatives, or have our representatives order it. Both paths ultimately lead to the same file: appointment certificate, signed, filed, verifiable. If you would like to transfer your data protection advice into a verifiable workspace now, write to info@civac.de or use the contact form on civac.de. Turn reading into an assignment. The initial discussions typically last 30 minutes, the onboarding takes 2 working days and ends with a signed appointment certificate and active workspace access, in which the directory, reporting path, training plan and audit plan are live from day 1. This means that consulting is no longer a one-off knowledge impulse, but a recurring operational process with an audit trail and EU data residency. The monthly reporting to the management takes place from the same workspace, so that the board meeting can work with current figures, open findings and planned steps. Once you work like this, you rarely go back to the PDF stack. The typical first reaction of the auditors is recognition for the clean file management, the typical first reaction of the departments is relief about clearly assigned tasks instead of diffuse compliance emails.
FAQ
At what number of employees do you have to appoint a data protection officer?
According to Section 38 BDSG, you must appoint a data protection officer as soon as at least 20 people are constantly involved in the automated processing of personal data. Regardless, the obligation applies if you process extensive special categories of data or if a data protection impact assessment is required.
How much does an external data protection consultation cost in Germany in 2026?
Monthly flat rates for smaller companies with up to 50 employees are between 380 and 720 euros net. Medium-sized companies with 200 to 800 employees typically pay between 950 and 1,800 euros net per month. Hourly fees range between 140 and 280 euros net per hour of consultation.
What is the deadline for reporting a data breach according to the GDPR?
Art. 33 GDPR requires a report to the responsible supervisory authority within 72 hours of becoming aware of the violation. The clock starts on awareness.
What documents does the data protection officer have to keep?
At least the appointment certificate, the list of processing activities in accordance with Art. 30 GDPR, the order processing contracts in accordance with Art. 28 GDPR, the technical-organisational measures, the reporting path and the training and audit evidence. CIVAC bundles all of these documents in a structured manner in the workspace.
Can the data protection officer perform additional compliance functions?
Yes, but only if there is no conflict of interest. According to the supervisory authorities, a dual role as IT manager or HR manager is clearly problematic. CIVAC clearly separates the function and offers integration with the information security officer as an integrated model with a clear separation of roles.
How long does initial implementation typically take?
The formal order is placed at CIVAC within 2 working days instead of the classic 2 to 6 weeks on the market. The initial implementation with directory, templates, training plan and audit roadmap takes between 4 and 10 weeks, depending on the depth of data. The workspace can be used productively from day 1.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.