External data protection officer: costs, models and realistic budgets for 2026
External data protection officers bill depending on the risk, data types and group structure. This guide shows typical ranges, hourly rates and flat rates as well as the adjustment screws that actually move the budget.
According to Art. 37 GDPR and § 38 BDSG, the appointment of a data protection officer is mandatory for many companies in Germany as soon as at least 20 people are constantly involved in the automated processing of personal data or special categories of data are processed in accordance with Art. 9 GDPR. The question of what exactly an external data protection officer costs can only be answered seriously if the risk, data types, number of processing activities, locations and group structure are clearly recorded. Flat-rate prices from advertisements almost always miss the point because they neither accurately calculate the initial phase with setting up the directory in accordance with Art. 30 GDPR nor the incident processing with a 72-hour deadline.
This guide shows reliable price ranges for 2026, the five most important cost drivers, typical models from hourly rates to group flat rates, and the points at which companies actually lose money. You will find out when an external DPO is better than an internal order, which services must be included in the standard package and how the appointment certificate, the list of processing activities according to Art. 30 GDPR and the 72-hour reporting chain according to Art. 33 GDPR fit into a consistent operating model. At the end you will receive three price examples from practice as well as a clear decision logic for workspace, external mandate or hybrid variant, including contract modules that avoid friction in the second year of the mandate.
Key Takeaways
- External DSB flat rates for SMEs in 2026 are realistically between 350 and 1,500 euros net per month, depending on the risk profile and number of locations.
- Hourly rates for qualified external DPOs in Germany are regularly between 150 and 280 euros net, corporate mandates are higher.
- The most expensive item is not the fee, but the follow-up care in the event of data breaches, audits and inquiries from those affected if the mandate is too small.
When an external data protection officer is mandatory
The obligation to order results primarily from Section 38 BDSG in conjunction with Art. 37 GDPR. A DPO is mandatory as soon as at least 20 people are constantly involved in the automated processing of personal data. Regardless of the number of people, the obligation applies if the core activity consists of extensive, regular observation of those affected or the processing of special categories of data in accordance with Art. 9 GDPR, for example in clinics, personnel service providers, insurance brokers, in market research or with providers of tracking and adtech services. Public bodies are also subject to an independent ordering obligation in accordance with Article 37 Paragraph 1 Letter a of the GDPR.
The choice between internal and external ordering follows three hard criteria. Firstly, the availability of specialist knowledge in accordance with Article 37 (5) GDPR with demonstrable knowledge of data protection law and the relevant industry. Secondly, the independence according to Art. 38 Para. 3 GDPR, which excludes the DPO from having a say in processing operations that he is supposed to assess himself. Thirdly, the capacity for ongoing advice and for dealing with incidents and data subject inquiries within legal deadlines. In companies with fewer than around 250 employees, the external model usually predominates because the full-time costs of an internal position with proven specialist knowledge, training budget, tooling and liability coverage rarely fall below 95,000 euros per year. There is also the practical problem that internally filled DPO positions in regulated industries are often difficult to recruit and the risk of several months of vacancy after termination must be borne. CIVAC acts here as a compliance platform and officer-as-a-service and provides qualified external data protection officers including a workspace, appointment certificate and documented reporting line to the management. Licence the workspace for your internal representatives or have our representatives order it, depending on the maturity level of your organisation.
The five cost drivers for the external DSB
A reliable offer is derived from measurable factors, not from gut feeling. The five relevant drivers can be clearly named and should be documented in every serious mandate offer. Firstly, the number of employees and locations, because this scales the training, audit and inspection load. A company with three plants in different federal states generates noticeably more hours than a centralized provider through travel and on-site expenses alone. Secondly, the data risk, i.e. the proportion of special categories according to Art. 9 GDPR, employee data, applicant data, credit card information and in particular international data transfers according to Chapter V GDPR with standard contractual clauses and transfer risk assessments.
Thirdly, the number of processing activities that must be kept in the register according to Art. 30 GDPR. Experience has shown that this is where the greatest initial effort lies because many companies start with outdated or incomplete directories. Fourthly, the industry and the additional special regimes: TTDSG, Patient Data Protection Act, Social Security Code X, Money Laundering Act, professional confidentiality obligations or the NIS-2 interface noticeably increase the consulting effort. Fifth, the maturity of the existing documentation. A company without a current VVT, without a TOM concept in accordance with Art. 32 GDPR and without documented order processing contracts in accordance with Art. 28 GDPR regularly pays twice as much in the first year as in the following year. Experienced DSBs therefore calculate the initial phase separately and reduce the ongoing flat rate as soon as the basics are clear. This tiered price has proven itself in practice because it reflects the real effort between the first and the following year and provides management and the supervisory board with a comprehensible path to reducing ongoing costs. If you transparently compare what can run as standard in the workspace and what really requires individual advice, you avoid the typical logic of additional demands. The appointment certificate, signed, filed, verifiable.
Standard market ranges 2026: flat rates and hourly rates
The following ranges reflect market observations from 2026 and mandate structures in Germany. For micro-enterprises with fewer than 20 employees with a low risk profile and no special categories according to Art. 9 GDPR, flat rates are between 150 and 350 euros net per month. Classic SMEs with between 20 and 100 employees regularly earn between 350 and 900 euros net per month. Medium-sized companies with 100 to 500 employees, several locations or medium data risk pay between 900 and 2,500 euros net per month. These ranges usually include an hourly quota of between 4 and 16 hours per month as well as the ongoing maintenance of the directories.
Group structures with 500 employees or more with international transfers, joint controllerships according to Art. 26 GDPR and several companies start at around 2,500 euros net per month and, depending on the complexity, reach into the five-figure range. Hourly rates for qualified external DPOs in Germany are regularly between 150 and 280 euros net. Special topics such as international transfers, AI systems according to the EU AI Act, group BCR or DPIAs on sensitive procedures are sometimes calculated at 320 to 380 euros net. It is important that the flat rate includes a clearly defined hourly quota and that additional services are approved in writing before being commissioned. Otherwise there is a risk of additional demands at the end of the year that will exceed the budget. On the CIVAC FAQ page you will find typical contract components that reflect this logic and an overview of the mandatory checks contained in the 490 ready-to-use audit templates. Anyone who agrees on the flat rate without a clear quota will lose cost control in the second quarter. It makes sense to have a written quarterly statement with a stated remaining quota so that management and DSB can control together.
What must be included in the standard mandate
A professionally tailored DSB mandate covers seven core services that every tender and every contract should explicitly name. Firstly, the order with an appointment certificate, notification to the responsible supervisory authority and publication of the contact details in accordance with Art. 37 Para. 7 GDPR. Secondly, ongoing advice in accordance with Article 39 of the GDPR, including statements on new processing, new tools, marketing measures and HR procedures. Thirdly, the maintenance or audit of the register of processing activities in accordance with Art. 30 GDPR with regular updates and traceable versioning. Fourth, the support of inquiries from those affected in accordance with Articles 15 to 22 of the GDPR within the one-month period in accordance with Article 12 (3) of the GDPR, with an escalation path and documented response templates.
Fifth, the preparation and support of data protection impact assessments in accordance with Article 35 of the GDPR, including risk assessment, catalogue of measures and, if necessary, prior consultation with the supervisory authority in accordance with Article 36 of the GDPR. Sixth, incident management with a 72-hour reporting path in accordance with Art. 33 GDPR and notification of those affected in accordance with Art. 34 GDPR, including prepared reporting forms and a documented escalation chain. Seventh annual training for particularly exposed areas, audits of critical processors and an activity report to management with concrete recommendations for the following year. Anything beyond that, such as international transfers, contract templates for order processing, audits of service providers, AI governance or ISMS connection, should be priced as a module with its own pricing logic. If you separate this clearly in the contract, you prevent friction and create the basis for the statement: The inspector is calling, the proof is ready. In the CIVAC workspace, all seven core services are mapped as separate workflows with an audit trail so that management can see the status of each obligation at any time. This means that every question about the maturity of the data protection program can be answered within 24 hours in supervisory board meetings, without employees having to pull special ad hoc evaluations from email inboxes.
Internal vs. external DSB: full cost accounting
The decision between internal and external ordering is often reduced to a mere fee comparison. A full cost calculation over the entire life cycle of the function is correct. An internal DSB position includes salary, social security contributions, workplace costs, further training regularly amounting to 3,000 to 5,000 euros per year, specialist literature, tool licences and replacement arrangements for vacation and illness. Realistically, the full costs of an internal DPO start at around 95,000 euros per year and quickly rise to 130,000 to 160,000 euros for senior profiles from regulated industries. There are also onboarding costs, recruiting costs and the risk of keeping the position vacant for several months in the event of fluctuation.
There are also risks from a lack of independence according to Art. 38 Para. 3 GDPR if the internal DPO faces his own management in the event of a conflict. Supervisory authorities examine this constellation critically, especially if the DPO is also operationally involved in IT, HR or marketing. The European Data Protection Board has made it clear in several opinions that dual roles with decision-making authority over processing activities are generally not permitted. An external DPO is not automatically cheaper, but it relieves the company of representation issues, training burdens and liability risks from internal dual roles. At CIVAC, mandate management runs continuously in the workspace with a documented reporting line to management, with traceable tickets, versioning and an audit trail. If you are looking for a mixed form, combine an internal data protection coordinator with an external DPO who has ultimate responsibility. In many cases, the costs are reduced by 30 to 50 percent compared to a pure in-house solution, without sacrificing response speed or depth of expertise. The internal coordinator remains the contact person for departments, the external DPO assumes ultimate responsibility, reporting line and liability.
Hidden costs: incident, audit, affected person inquiry
The flat rate covers ongoing work, not emergencies. Anyone who doesn't separate this cleanly will experience an expensive surprise in the first data breach. A reportable breach in accordance with Art. 33 GDPR typically requires between 15 and 40 hours of external advice, depending on the number of those affected, types of data and ongoing clarifications with cyber insurance, forensics and the supervisory authority. Deadline begins as soon as we become aware of it. Anyone who misses the 72-hour report risks fines in accordance with Art. 83 GDPR as well as reputational damage, which is often much more financially significant than the fine itself. Experience has shown that a properly processed medium-sized data breach costs between 4,000 and 12,000 euros for pure consulting services, without forensics and without external legal briefs.
Also audits by supervisory authorities or clients, requests for information according to Art. 15 GDPR with complex data sets across multiple systems and data protection impact assessments for AI-supported processing are classic cost drivers. These services should either be included in the mandate offer with a clearly defined hourly quota or calculated in advance with a fixed daily rate. CIVAC manages incidents as structured cases in the workspace, with preservation of evidence, time stamp, four-eye approval and automatic escalation chain to management, insurance and supervisory authorities. This means that others manage compliance like a filing cabinet. We run them like software. If you think about incidents contractually in advance, you avoid fee disputes in ongoing claims and get predictable budget reserves for cyber and data protection incidents. A sensible calculation rule is to reassess 10 to 15 percent of the annual flat rate annually as a reserve for special situations. In industries with an increased probability of incidents, such as healthcare or adtech, 20 percent should be planned because data breaches there regularly involve larger groups of those affected and require parallel reports to several supervisory authorities in the EU.
Negotiation and contract drafting: what you should pay attention to
A robust DPO contract contains eight mandatory points that every legal department should check before signing. Firstly, the service catalogue with a clear distinction between flat rate and hourly service as well as a list of services that are expressly not included. Secondly, the response times, around 4 hours for data breaches, 1 working day for government inquiries and 2 working days for standard inquiries, each with a service level agreement and escalation level. Thirdly, the reporting line to the management with at least an annual activity report in accordance with Article 39 (1) (b) GDPR and a defined quarterly format. Fourthly, the representation regulation with named representative, telephone availability and SLA in the event of vacation or illness, so that deadlines according to Art. 33 GDPR are not broken.
Fifth, the liability regulation with minimum coverage for professional liability, which is standard market practice of 2 to 5 million euros per claim and insurance year. Sixth, the termination and dismissal regulations, taking into account the special protection against dismissal according to Section 38 Paragraph 2 in conjunction with Section 6 Paragraph 4 BDSG, which protects the DPO from unrelated dismissals. Seventh, data residency: for German companies, EU data residency and GDPR-compliant hosting of the workspace is a hard criterion, as the DPO itself processes personal data and is not allowed to export data breaches to third countries. Eighthly, transparency about subcontractors, tooling and any order processing in accordance with Art. 28 GDPR. If you go through these eight points before concluding the contract, you will avoid the typical conflicts in the second year of your mandate and create planning security. Audit-proof, documented, § 38 BDSG-proof. On the overview page of all officer roles you can see which additional mandates, such as information security officer or money laundering officer, can be sensibly linked to the DSB contract without creating duplicate structures. An integrated representative landscape not only reduces costs, but also prevents contradictory recommendations to management.
Price examples from practice
Example 1: Tax consulting firm with 35 employees, one location, high client density, no special categories according to Art. 9 GDPR, but strict professional confidentiality. Flat rate: 480 euros net per month, including 4 hours of advice, annual training and ordering. Hourly rate for additional work: 195 euros net. Initial audit phase in the first quarter with creation of the directory in accordance with Art. 30 GDPR, review of all order processing contracts and updating of the data protection declaration: 2,800 euros net one-off. In the second year, experience shows that the one-off expense drops to less than 500 euros net because the basics are in place.
Example 2: Medical technology manufacturer with 180 employees, two locations, processing of health data in accordance with Art. 9 GDPR and third country transfers to the USA for clinical studies and cloud services. Flat rate: 1,650 euros net per month, including 12 hours of advice, DPIA preparation and support for two audits per year. Hourly rate for additional work: 230 euros net. Initial project to update the transfer risk assessment according to Schrems II and the ECJ decision on the Data Privacy Framework: 9,500 euros net one-off. There is also a special budget of 6,000 euros net for ISMS connection to ISO/IEC 27001:2022 and interface to medical device regulation.
Example 3: Holding with three German subsidiaries, a total of 720 employees, shared data protection in accordance with Art. 26 GDPR and group-wide ISMS. Flat rate: 4,200 euros net per month for the group DPO function with a central reporting line. Three subsidiaries with their own activity report, common platform and uniform templates. Hourly rate for special advice: 280 to 320 euros net. These ranges show that it is not the number of employees alone that counts, but rather the risk density, the group structure and the interfaces to other regulatory regimes such as NIS-2 or the EU AI Act. Anyone who only links the flat rate to headcount regularly underestimates the effort required for complex data flows.
This is how you decide between workspace, external DSB and hybrid
The decision follows three questions that every management should answer in writing before advertising a mandate or position. Firstly: Does your company have internal expertise in accordance with Article 37 (5) GDPR that covers at least 0.3 to 0.5 full-time equivalents and also covers vacation and illness in replacement cases? Secondly: Is independence according to Art. 38 Para. 3 GDPR structurally ensured, without the DPO being involved in IT, HR or sales decisions in accordance with instructions and thus slipping into his own audit role? Third: Can you reliably operate professional incident management with a 72-hour reporting chain in accordance with Art. 33 GDPR, a documented reporting line and four-eye approval from on-board resources?
Anyone who answers all three questions with yes licences the CIVAC workspace and thus places directories, appointment certificates, audit templates, training logs and incident chronicles on a consistent platform with EU data residency. Anyone who answers at least one question with no will have our representatives appointed and thus gain specialist knowledge, representation, liability insurance and tooling in one package. Hybrid models combine both: internal coordinator plus external DPO with ultimate responsibility, shared workspace and shared reporting line. CIVAC offers both ways, documented in the appointment certificate and in the reporting line to management, each with clear handover logic in the event of personnel changes. Turn reading into an assignment. Write to us at info@civac.de or use the contact form on the DSB role page. You will receive a proposal with bandwidth, modules and response times within 2 working days, instead of waiting 2 to 6 weeks as with classic law firm mandates. The proposal already contains contract components, SLA definitions and an initial action plan for the initial phase.
FAQ
How much does an external data protection officer cost for an SME with 50 employees?
Realistically between 450 and 1,100 euros net per month, depending on data risk, number of locations and processing activities in accordance with Art. 30 GDPR. In addition, there are one-off initial costs for directory development, training and initial review of the order processing contracts amounting to 1,500 to 4,000 euros net. A serious quota requires a brief inventory of the procedures and data types.
Which services must be included in the flat rate?
Order, ongoing advice in accordance with Art. 39 GDPR, maintenance or review of the directory in accordance with Art. 30 GDPR, support of inquiries from those affected, annual training, activity report to the management and a clearly defined hourly quota for standard advice. Incident processing in accordance with Art. 33 GDPR and data protection impact assessments in accordance with Art. 35 GDPR should be agreed as a module with a daily rate or with a clear quota.
Is an internal DPO worth it compared to an external mandate?
In most companies with fewer than 250 employees, the external solution is more economical because the full costs of an internal position with representation, further training and tooling are rarely less than 95,000 euros per year. When the company is larger, a combination of an internal data protection coordinator and an external DPO with ultimate responsibility often makes sense because it combines speed of reaction and independence.
What fines are threatened without a proper order?
According to Art. 83 Para. 4 GDPR, fines of up to 10 million euros or 2 percent of global annual turnover are possible, whichever is higher. In practice, the supervisory authorities impose staggered fines based on severity, repetition and willingness to cooperate. In addition, there are administrative offenses in accordance with Section 130 OWiG in the event of breaches of supervisory duty by management as well as civil law claims for damages from those affected in accordance with Article 82 of the GDPR.
How quickly must a data breach be reported?
According to Art. 33 GDPR, within 72 hours of becoming aware of this to the responsible supervisory authority. If there is a high risk for those affected, there is also an immediate obligation to notify in accordance with Art. 34 GDPR. Delays significantly increase the risk of fines and should be carefully documented in the justification for the report, including the time stamp when knowledge was obtained. The clock starts on awareness.
What role does EU data residency play in the selection of the DSB tool?
Since the DPO itself processes personal data, GDPR-compliant hosting within the EU is a hard selection criterion according to Chapter V GDPR. CIVAC hosts the workspace in EU data residency and operates an ISMS according to ISO/IEC 27001:2022 with 93 controls, so that incidents, directories and appointment certificates are in a verified environment. US cloud tools without SCC and transfer risk assessment are generally not suitable for DSB tasks.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.