77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
External DPO: Order, obligations and costs within a verifiable framework
Data Protection & Privacy

External DPO: Order, obligations and costs within a verifiable framework

9 July 202612 min readBy Lena Vogt
CIVAC

An external DPO relieves management and IT if the order is clearly documented and the tasks specified in Art. 39 GDPR are carried out. This article shows the scope of obligations, the cost framework and the difference between a filing cabinet and an audit-proof platform.

An external data protection officer is expressly permitted according to Article 37 (6) GDPR and is often even mandatory in German companies with more than 20 people who regularly process personal data automatically according to Section 38 BDSG. However, practice shows that ordering alone is not enough. During audits, supervisory authorities require the appointment certificate, a documented task profile, a direct reporting path to management and complete proof that the DPO was actually active. Without these four elements, the mandate collapses in the first serious examination, regardless of whether the person appointed is technically qualified or not.

This article classifies the function, quantifies the realistic cost framework for small, medium and large companies and describes the interfaces to IT security, human resources and marketing. He explains why an external DPO reduces the personal liability of management in accordance with Section 43 BDSG and Section 130 OWiG without abolishing it, and what requirements Art. 38 GDPR places on independence and freedom from instructions. At the end there is a clear decision-making aid: internal representative in the licensed workspace or appointed external DPO. CIVAC delivers both from a single source, without you having to choose between filing cabinet and platform. Anyone who is still unsure after reading this article will at least have the terms to distinguish a reliable offer from an unsustainable one, and that is more than half the battle in a fragmented market.

Key Takeaways

  • External DPOs are permissible according to Art. 37 Para. 6 GDPR and are often mandatory for more than 20 people who process data automatically according to Section 38 BDSG.
  • The appointment document must be in writing, specify a reporting channel to management and be archived for at least three years after the end of the mandate.
  • Realistic costs are between 250 and 2,500 euros per month, depending on the number of employees, processing activities and industry.

When an external DPO is mandatory and when it is recommended

In Art. 37 Para. 1, the GDPR names three situations in which a data protection officer must be appointed: public bodies, companies with core activities in the extensive, regular and systematic observation of those affected, and companies that process special data categories on a large scale in accordance with Art. 9 GDPR. Germany tightens these requirements in Section 38 BDSG: As soon as at least 20 people in a company are constantly involved in the automated processing of personal data, a DPO must be appointed. In practice, the 20-person threshold is almost always reached because human resources administration, sales and accounting are already included. Seasonal workers and working students count if they regularly access processing.

The order is also recommended if order processing takes place outside the EEA, if marketing automation and cookie banners are used or if the company works with health insurance companies, clinics or public clients. The use of AI-supported HR tools, applicant management systems with scoring and the increasing use of third-country services for communication and analysis also increase the need for protection. In all of these cases, an external DPO is the more resource-saving option because no internal person has to be released and trained. The supervisory authorities expressly accept external orders; The Bavarian State Commissioner for Data Protection even points out in her notes that external mandates can often more easily ensure the independence required in Art. 38 GDPR because there is no employment contractual commitment that conflicts with the freedom to issue instructions. CIVAC appoints the external data protection officer within two working days, including the appointment certificate, task profile and connection to the reporting line to management. The inventory of processing activities is carried out in parallel and reduces the risk that a supervisory authority will complain about the missing VVT during an initial inspection.

Tasks according to Art. 39 GDPR and their operational translation

Art. 39 GDPR lists five core tasks: informing and advising those responsible, monitoring compliance with the GDPR, training staff, advising in connection with data protection impact assessments and cooperation with the supervisory authority. These five tasks must be translated into comprehensible artifacts in operational reality, otherwise the mandate remains an assertion. Information becomes recorded consultation appointments, monitoring becomes a register of processing activities in accordance with Art. 30 GDPR, training on tracked participation rates, DPIA becomes a documented assessment with a risk matrix and cooperation with authorities becomes verifiable correspondence. Each of these translations creates a verifiable document, and without this document the legal protection of the order expires.

In practice, this means: an external DPO who only submits a quarterly report fulfils the tasks formally, but not in terms of content. Supervisory authorities are increasingly paying attention to whether consultations have taken place before the introduction of new processing operations, whether the VVT ​​is alive or frozen and whether reporting obligations under Art. 33 GDPR are complied with within the 72-hour period. Examiners specifically ask: When did the last training take place, who took part, and is there evidence of the assessment of new processing activities in the last twelve months. CIVAC stores templates in the workspace for each of these tasks, including consultation protocols, VVT templates, a DPIA module with threshold analysis and a reporting path for data breaches. The auditor calls, the evidence is ready. This applies both to the mode in which you licence the workspace for your internal representative and when our representatives are appointed. The five task points from Article 39 are therefore not just abstract duties, but are operationally instrumented.

Appointment certificate, independence and reporting path

The written order is mandatory according to Section 38 Paragraph 2 BDSG in conjunction with Section 6 Paragraph 4 BDSG. It must specify the name of the DPO, the date, the scope of the tasks and the reporting channel. The appointment certificate is signed by management, reported to the supervisory authority and communicated internally to all employees. For external mandates, a service contract complements the order and regulates remuneration, availability and confidentiality. Order processing according to Art. 28 GDPR is not necessary because the DPO does not carry out any independent processing within the meaning of the GDPR; The supervisory authorities of Bavaria and Baden-Wuerttemberg have confirmed this in several statements. This also means: A classic AVV with the external DPO service provider is not only unnecessary, but can further dilute independence if it grants the right to issue instructions.

Art. 38 Para. 3 GDPR expressly prohibits instructions to the DPO regarding the fulfilment of his duties. He reports directly to the highest management level, i.e. the management or the board of directors. This requirement is easier to comply with for external mandates because there is no employment contractual dependency. A professional or disciplinary instruction may not be exercised, and dismissal is only permitted under the conditions of Section 38 Paragraph 2 in conjunction with Section 6 Paragraph 4 BDSG. CIVAC documents the reporting line in the workspace, stores the appointment certificate in version form and ensures that if the DPO changes, the handover is fully recorded. The appointment certificate, signed, filed, verifiable. This is the difference between a desk DPO and an audit-integrated mandate. Anyone who does not put the reporting line in writing runs the risk of losing proof of the formally correct order during an audit, and this also means that the protection of the management, which was actually the very reason for the order, is lost.

Cost framework: What an external DPO realistically costs

The market for external DPOs is heterogeneous. The number of employees in combination with the type of processing provides a reliable orientation. For companies with up to 50 employees without special data categories, monthly flat rates range between 250 and 600 euros. For 50 to 250 employees, the range is between 600 and 1,400 euros. Corporations and highly regulated industries such as banks, insurance companies or healthcare pay between 1,400 and 2,500 euros per month, and more in individual cases. Hourly-based models calculate between 150 and 280 euros per hour, which quickly exceeds the flat rate when maintaining a VVT with 80 processing activities. In addition, there are special fees for data breach processing, requests for information in accordance with Art. 15 GDPR and inquiries from authorities, which are excluded from many standard contracts.

This range is explained by the depth of the tasks. An external DPO who only provides advice is cheaper than one who maintains the VVT, carries out training and takes over the 72-hour reporting in the event of a data breach. Therefore, check the list of services line by line: How many hours per month are included, how much does an additional hour cost, is on-site training included in the price, who pays for the additional work in the event of a data breach. In the offer, CIVAC transparently breaks down which tasks are included and shows the ratio of consultation time to platform usage. The SLA is two working days for the order, while classic providers are two to six weeks. The average workload per representative is reduced because recurring tasks are processed in standardised templates instead of individually for each mandate. Others run compliance like a filing cabinet. We run it like software. The effect can be measured in hours per quarter and therefore in euros.

Liability of the management and protective effect of the external DPO

The appointment of a DPO does not relieve the management of its responsibility according to Art. 24 GDPR. However, it shifts the operational audit obligation and ensures that data protection decisions have been discussed in a documented manner. This is the decisive lever in the fine procedure: According to Art. 83 Para. 2 GDPR, supervisory authorities weigh, among other things, the degree of responsibility, measures taken to reduce damage and cooperation. A documented consultation protocol in which the external DPO has warned against risky processing can make the difference between a warning and a high fine. Fines of up to 20 million euros or 4 percent of group sales are set out in Article 83 Para. 5 GDPR and are increasingly being exhausted in EU-wide supervisory practice.

In addition, there is Section 130 OWiG: A violation of the supervisory obligation can be punished personally with fines of up to one million euros against the management. Anyone who appoints an external DPO and implements his instructions in a documented manner also documents the fulfilment of the supervisory obligation. The clock starts on awareness. In terms of insurance law, this is relevant for D&O policies, which in recent years have increasingly provided deductibles and exclusions for data protection violations if there was no documented advice from the DSB. CIVAC combines this early detection system with audit templates, which are kept versioned in the workspace, and a reporting line that makes every indication traceable. The personal protective effect for managers and board members does not arise from the mere formal order, but from the verifiable process behind it, and this process must be organizationally and technically reproducible so that it still applies in five years.

Selection criteria: What makes a suitable external DPO

The GDPR formulates the requirement for professional qualifications and specialist knowledge in Article 37 Paragraph 5. Supervisory authorities and professional associations fill out what this means in concrete terms: verifiable further training, ideally certification according to the TUEV, DEKRA or Udis standard, at least two years of relevant practice and industry knowledge. Anyone looking for an external DPO should be able to see a CV, certificates of further training from the last three years and references from their own industry. A DPO without documented further training in 2025/2026 is a risk because case law and supervisory practice are evolving quickly. Topics such as AI regulation, third country transfers according to the EU-US Data Privacy Framework and biometric procedures require current knowledge that is no longer reliable after 18 months.

Otherwise, operationally crucial are: availability within 24 hours, a written escalation policy for data breaches, a clear model for remuneration for special operations such as requests from authorities or data breaches and sufficient professional liability insurance Coverage amount. At least one million euros of cover is standard in the market; in regulated industries it should be two to five million. Also check how many mandates the DSB handles at the same time: Anyone who manages more than 40 mandates rarely has enough time to support each one with the necessary depth. CIVAC publishes these parameters transparently in the offer because they are relevant to the test. The dual-model approach allows two options: Licence the workspace for your internal representatives, or have our representatives order it. In both cases, the selection criteria are documented identically because the examining eye does not distinguish between internal and external, but rather between detectable and undetectable. A interlocking with NIS 2 requirements has been considered and not a follow-up project.

Interfaces to IT security, ISMS and whistleblower protection

Data protection is not an isolated issue. The interface to information security is laid out in Art. 32 GDPR, which requires appropriate technical and organisational measures. In companies with an information security officer or an ISO/IEC 27001:2022 certified ISMS, the DPO must coordinate the protective measures with the ISB without compromising independence in accordance with Art. 38 GDPR. CIVAC maps the points of contact in the platform: which processing activity is assigned to which asset, which measure from Annex A of ISO 27001:2022 covers which GDPR risk, and who is authorised to escalate in the event of a data breach. The 93 controls from Annex A largely correspond to the TOM categories from Art. 32 GDPR, so that a data set that has been maintained once serves both checks.

The interface to whistleblower protection according to the HinSchG is also relevant: incoming reports can contain personal data, the processing of which must be accompanied in a legally compliant manner. The external DPO advises the internal reporting office without operating it. The same applies to the Supply Chain Due Diligence Act: data processing along the supply chain, such as supplier questionnaires or audit reports, belongs to the VVT. The EU whistleblower directive also requires confidential processing, which must be coordinated with data protection. These cross-connections are mapped in the CIVAC workspace using a uniform data model, so that representatives from different disciplines look at the same processing data set. The workspace manages 25 officer roles and 490 audit templates, reducing duplication between DPO, ISB and compliance officer. Anyone who only sets up these interfaces after a regulatory complaint has to pay for the integration twice: once as a fine, once as a retrofit. The unified platform avoids both posts. In practical terms, this means that a data breach reaches the ISB, the DPO and, in an emergency, the management at the same time, that the advisory protocol of one role serves as evidence for the other and that supervisory authorities, which increasingly examine the GDPR and NIS-2 together, find a consistent data set instead of three diverging lists.

Change and handover: When the external DPO is reappointed

Changing an external DSB is more common than expected. Mandates are terminated because the service was not satisfactory, because clients grow into a new size class or because supervisory authorities have objected to the qualifications of the previous DPO. The handover is regulatory sensitive: the list of processing activities, the DPIA files, the consultation protocols, the training certificates and the correspondence with the supervisory authority must be handed over in full. If an outgoing DPO deletes data before the handover is complete, a compliance vacuum is created that will be noticed in the next audit. Supervisory authorities regularly interpret gaps in the audit trail to the disadvantage of the person responsible because the burden of proof according to Article 5 Para. 2 GDPR lies with the responsible body, not with the authority.

CIVAC carries out the handover as a structured process: The new DPO receives access to the versioned VVT, the appointment certificate is reissued, the old version is archived, and a handover protocol is signed by both sides. The system stores the change in an unchangeable audit log, which can be verified later. Anyone who makes the switch without a platform runs the risk that versions will be lost or that the supervisory authority will see two appointment certificates without transitional regulations when asked. The data model differentiates between active and archived orders and makes every change visible with a time stamp and person responsible. This discipline is what distinguishes a proper transition from a messy one, and it is the prerequisite for ensuring that a company's compliance history does not jump back to zero every three years. It is also the basis for insurers to recognise the continuity of the compliance function in the event of a D&O claim, instead of viewing a gap as a breach of obligation.

Next steps: How to integrate the external DPO in a verifiable way

If you use an external DPO, you have two options. The first: You appoint an external person who works without a platform and are responsible for ensuring that the appointment certificate, VVT, training certificates and reporting line remain in a condition that passes any audit. The second: You use a compliance platform that stores these artifacts in a standardised manner, version them and make them auditable at the push of a button. CIVAC is a compliance platform and officer-as-a-service. Licence the workspace for your internal representatives, or have our representatives order it. In both models you receive the appointment certificate, task profile, reporting path, VVT template, DPIA module, reporting path for data breaches and audit log from a single source. We make the choice between the two models together after taking stock, not in advance.

The start is sober. An initial inventory clarifies: How many people work with personal data, are there special data categories, which processors are in use, when was the last training session, and is there a VVT in a readable form. From this inventory, an order proposal is created within two working days, which specifically states the areas of responsibility, the service level, the remuneration and the reporting path. Turn reading into a mandate.: Write to info@civac.de or use the contact form. We clarify the scope of duties, cost framework and schedule in a 30-minute conversation and then send a draft contract with a transparent list of services. Audit-proof, documented, § 38 BDSG-proof. An external DPO doesn't need to deliver more, but it doesn't need to deliver any less either. The next regulator that calls will know your answer because it comes from a system and not a memory. Internal stakeholders, from the board of directors to the IT lead, will also quickly notice the difference between an ad hoc response and reproducible information, and it is precisely this difference that decides whether data protection is perceived as a brake on the company or as a resilient foundation.

FAQ

When is an external DPO mandatory?

As soon as at least 20 people in a company are constantly involved in the automated processing of personal data, Section 38 BDSG requires the order. According to Article 37 Paragraph 1 of the GDPR, the DSB is also mandatory for extensive, regular monitoring of those affected and for large-scale processing of special data categories in accordance with Article 9 of the GDPR. The external variant is expressly permitted under Article 37 Paragraph 6 of the GDPR and is widely used in practice because it facilitates independence.

How much does an external DPO cost per month?

Realistic flat rates are between 250 and 2,500 euros per month. Companies with up to 50 employees pay 250 to 600 euros, up to 250 employees pay 600 to 1,400 euros, regulated industries and corporations pay 1,400 to 2,500 euros. Hourly models calculate at 150 to 280 euros per hour, which is usually more expensive than the flat rate for ongoing mandates. Check special fees for data breaches, requests for information and inquiries from authorities before concluding the contract.

Does an appointment certificate always have to be in writing?

Yes. Section 38 Paragraph 2 BDSG in conjunction with Section 6 Paragraph 4 BDSG requires a written order. It must contain the name, date, scope of tasks and reporting channel, be signed by management and reported internally and to the responsible supervisory authority. CIVAC provides the appointment certificate in the workspace, archives it in version form and ensures that any subsequent changes can be documented with a time stamp and the responsible person.

What liability risks remain with management?

Responsibility according to Art. 24 GDPR remains with the management. It is operationally shifted to the DSB, who only advises, not decides. Violations of the duty of supervision according to Section 130 OWiG can be punished personally with up to one million euros against managing directors. Documented advice from the DSB is a central source of relief in fine proceedings and in D&O claims cases.

How quickly can an external DSB be ordered?

Classic providers need two to six weeks for the contract, appointment certificate and inventory. CIVAC works with a service level agreement of two working days until the appointment certificate is signed and connected to the workspace. The inventory of the processing activities follows in the first 30 days after the order and is a prerequisite for reliable advice.

What happens when the external DSB changes?

The list of processing activities, DPIA files, training certificates and correspondence with the supervisory authority are handed over in full. CIVAC carries out the handover as a versioned process in the workspace, stores a handover protocol signed by both sides and ensures that the compliance history is continued without any gaps. The burden of proof in accordance with Article 5 Para. 2 GDPR therefore remains fulfillable.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles