Selecting a DSB service provider: criteria, costs and contractual traps 2026
External data protection officer, officer-as-a-service or workspace licence: A structured comparison framework for DPO service providers with concrete criteria, realistic costs and the three most common contract cases from ten years of officer practice.
According to Art. 37 GDPR and Section 38 BDSG, companies with usually at least 20 people who constantly process personal data automatically must appoint a data protection officer. The supervisory authorities of the federal states confirmed again in the last activity reports that a significant proportion of the reported data breaches are due to structural gaps in the DSB function. Whoever chooses a DSB service provider is not deciding on a supplier issue, but rather on a function with a legally defined position, reporting line and appointment certificate. This is exactly where contracts regularly fail because they are set up like classic consulting contracts and exclude the specific obligations under Articles 38 and 39 of the GDPR. A missing appointment certificate, an unclear representation regulation or a processing directory that no one maintains are not trifles, but documented reasons for complaint in supervisory audits.
This article organises the market for DPO service providers according to four models, names the twelve selection criteria with which management and IT management can reliably compare providers, and shows the three contractual traps that supervisory authorities have repeatedly criticized in recent years. At the end, you will receive a decision path that distinguishes between the workshop model, platform model and hybrid model, as well as a realistic cost range for 2026. The article is aimed at management, data protection coordinators and IT management in medium-sized companies with 50 to 2,000 employees and at the end contains a concrete onboarding path for the first 30 days after the conclusion of the contract.
Key Takeaways
- A DPO service provider must name a specific person in accordance with Art. 37 GDPR, issue an appointment certificate and document a direct reporting line to management.
- Standard market fees for external DPOs in 2026 will be around 350 to 1,800 euros per month, depending on the depth of the processing directory, the number of locations and response time.
- The most common contract pitfalls are unclear response times, a lack of representation regulations and a scope of services that excludes the processing list from the scope.
What a DSB service provider must legally provide
A DSB service provider does not provide any kind of consulting service. He provides a person named in accordance with Articles 37 to 39 of the GDPR who carries out the tasks in accordance with Article 39 of the GDPR and reports directly to the management. This person must have specialist knowledge, act without instructions within the meaning of Article 38 (5) GDPR and must not be disadvantaged because of their activity. A service provider that only provides “advice” and does not name a specific person does not meet this requirement. The supervisory authorities regularly check exactly this point during inspections: Who is the natural person who has been appointed as data protection officer and for how long? The answer must emerge from a single document, not from an oral reconstruction.
In practice, this means four verifiable obligations: a written appointment certificate with name, order date and scope of tasks; a reporting process to the responsible supervisory authority in accordance with Article 37 (7) GDPR; a documented reporting line to top management; and traceable proof of activity in the form of audit logs, consulting documentation and data breach registers. Anyone who appoints an external data protection officer should have these four elements presented to them before concluding the contract. The appointment certificate, signed, filed, verifiable. Without these four artifacts, even a highly qualified lawyer is not a verifiable DPO within the meaning of the regulation in the event of a dispute.
At CIVAC, this is not a consulting philosophy, but a platform standard. The compliance platform and officer-as-a-service solution automatically creates these artifacts in the workspace, which can be stored in an audit folder with a time stamp and version status. This creates a verifiable status without you having to reconstruct who ordered what and when. When the supervisory authority calls, the proof is ready, and not after a week of searching through the email archive. This form of documentation reduces exam stress and makes handovers between people less frictionful.
Four market models in comparison
The DSB market is divided into four models, which differ significantly in response time, costs and depth of documentation. Firstly, the single lawyer model: a specialised lawyer takes on the DPO function, often highly competent in interpretation, but often without tools for the processing directory and with hourly rates above the flat rate. The model is suitable if you already have an internal documentation structure and only want to source the named person and legal interpretation externally. It is not suitable if you need operational support with the processing directory or if your IT landscape changes regularly.
Secondly, the law firm model: A boutique or commercial law firm with a DSB team, robust in processing, but usually without a workspace in which operational representatives work together. Thirdly, the workshop model: A specialised DSB agency, often with on-site inspections and permanent contacts, but which can only be scaled up by increasing staff if there are several locations. These agencies are well-established in the industry, but reach their limits as soon as they have more than three locations or several subsidiaries. The handover between consultants within the workshop is often the weakest link.
Fourth, the platform model: A provider like CIVAC combines named people with a workspace that holds the processing directory, TOM list, order processing register and data breach reporting path in one system. Licence the workspace for your internal representatives or have our representatives order it. Both provide the same evidence structure. Which model is right does not depend on size alone, but on the number of locations, subsidiary structure and audit frequency. A group with five subsidiaries and ISO/IEC 27001:2022 certification benefits from a platform approach because evidence can be stored in a consolidated manner. A medium-sized company with one location and no ISMS obligation can get by with the workshop model, provided the handover clause in the contract is clear and the deputy has been named.
Selection criteria: 12 questions for the provider exam
Before you hire a DPO service provider, you should have twelve questions answered in writing. These questions separate reputable providers from hourly traders and protect you from late surprises during a regulatory audit. If providers answer fewer than nine of them clearly, this is a reliable sorting signal. The questions can be divided into three blocks: technical qualifications, procedural responsiveness and contractual clarity.
Technical: Which specific person is named and with what proof of qualifications? What industry experience does one have and how many DSB mandates are handled in parallel? Who is the substitute for vacation or illness, and what are their qualifications? If the named person changes, who will take over the handover and within what period?
Procedural: Within what period will a request from a data subject be responded to in accordance with Art. 15 GDPR? How is the 72-hour period according to Art. 33 GDPR operationally secured, i.e. who can be reached at night and on weekends? Deadline begins as soon as we become aware of it. Who maintains the processing directory and in which system? How are training courses planned and verified?
Contractual: Is there an order processing contract in accordance with Art. 28 GDPR with the service provider, and if so, who is the controller and who is the processor? How is liability limited and what is the insured amount? What notice periods apply? Is there an exit clause with all documents being handed over in machine-readable form?
The answers to these twelve questions should be presented side by side in a structured comparison. You should delete providers who answer more than three questions evasively. Providers who do not want to answer the questions in writing are automatically excluded because the supervisory authority will also ask them in writing later. What you verbally accept today will become a documented defect tomorrow.
Costs 2026: Realistic ranges depending on company size
For cost planning for 2026, the market has condensed into four size bands. For companies with 20 to 50 processing people, the flat fee is typically 350 to 700 euros per month, depending on the size of the processing directory and the number of processors. For 50 to 250 people, the market ranges between 700 and 1,400 euros per month. For 250 to 1,000 people, the range is 1,400 to 3,000 euros, depending on the number of locations, industry and the presence of an ISO/IEC 27001:2022 certification, which requires the interface between the DSB and ISB.
For more than 1,000 people, a blanket statement is dubious. Here, providers calculate on a project-based basis, often with a basic flat rate plus variable components for audits, training and ad hoc inquiries. CIVAC works in a flat-rate model with a clear separation between workspace licence (operational work environment for your internal team) and officer-as-a-service (CIVAC provides the named person and a documented order date with supervisory report).
Pay attention to four cost drivers that undermine flat rates: additional locations without a volume scale, training that is not included in the basic fee, follow-up costs for data breach reports in accordance with Art. 33 GDPR and hourly rates for audits by regulatory authorities. Anyone who does not clarify these four items when concluding the contract will have to pay additional fees. Audit-proof, documented, Section 38-proof. This only applies if the costs can bear the volume.
A common fallacy: the cheapest DSB service provider is not the cheapest. In the case of a single supervisory inspection with a list of defects or a data breach with a 72-hour deadline, the additional demand may exceed the annual fee. Therefore, do not calculate the basic fee, but rather the expected total annual volume including the four variable items mentioned above.
Three contract traps that supervisory authorities objected to in 2024 and 2025
The activity reports of several state data protection authorities have identified recurring deficiencies in contracts with DPO service providers over the last two years. Three patterns appeared particularly frequently and should be specifically examined when drafting the contract because they do not appear in the associations' standard templates.
Trap 1: Unclear response time. Contracts without a defined response period to requests from data subjects and without availability regulations on weekends are problematic because the deadline according to Art. 12 GDPR runs independently of the service contract. A good contract will include a written response time of 24 to 48 hours for standard inquiries and 24-hour availability for data breach escalations. Without these clauses, the risk that a 72-hour period according to Art. 33 GDPR will expire is real and can often no longer be remedied in court.
Trap 2: Lack of representation regulations. If the named DPO is on vacation or sick, the deadline according to Art. 33 GDPR still continues. Contracts without a designated representative or escalation path will result in the 72-hour deadline passing before anyone responds. The auditor calls, the evidence is ready. This only works with representation. The contract must name the representative by name and qualifications, not refer abstractly to "qualified colleagues".
Trap 3: Processing directory outside the scope. Contracts that declare the directory as an optional additional service in accordance with Art. 30 GDPR fail to meet the legal minimum standard because the directory is the operational basis of the DSB activity. A provider who takes the directory out of scope cannot fulfil its tasks according to Art. 39 GDPR because it lacks the factual basis. Therefore, check, item by item, what is included in the scope of services and what is listed as an add-on.
Workspace versus Officer-as-a-Service: When and which model is right?
CIVAC makes a clear distinction between two reference models, and this separation is worthwhile for you as a buyer because it covers different levels of maturity. The Workspace licence addresses companies that have an internal data protection coordinator or an internal DPO and only want to use the platform with the 490 ready-to-use audit templates, the processing directory and the data breach reporting path. The order remains internal, the platform provides the evidence structure. This creates a consolidated status without having to outsource the DSB function. This variant is often the desired option, especially in regulated industries such as banking, insurance and healthcare.
The officer-as-a-service model addresses companies that do not want to or cannot develop internal DPO competence. CIVAC names a specific person, issues the appointment certificate, takes over the reporting to the supervisory authority in accordance with Art. 37 Para. 7 GDPR and maintains the reporting line to the management. Both models use the same workspace, audit trail and ISO/IEC 27001:2022 certified infrastructure with EU data residency. Licence the workspace for your internal representatives or have our representatives order it. The choice is reversible and the evidence moves with you.
It is possible to switch between the two models without any migration effort. A medium-sized company that starts today without internal expertise can take over the workspace after twelve months and appoint its own person without having to move data. A larger medium-sized company that now works in-house can appoint a CIVAC person as a deputy to close the replacement trap. This modularity is rare in the classic outsourcing market because the provider there typically sticks to a contract with a fixed personnel structure and artificially increases switching costs.
For the overview of all 25 agent roles on the CIVAC platform, we recommend taking a look at the role directory because the DPO reference is often related to ISB, AGG and whistleblower roles interlocked and synergies between the roles reduce overall costs.
Onboarding a DSB service provider: The first 30 days
The first 30 days after the conclusion of the contract decide whether the DSB service provider sets up an auditable status or whether you are still merging Excel lists after a year. A structured onboarding path consists of five steps, which should take place in the order mentioned and which are stored as a standard process in a good platform. Anyone who reverses this order risks that the formal order runs while the operational documentation is still empty.
Day 1 to 5: Appointment of the specific person, issuance of the appointment certificate, notification to the responsible supervisory authority in accordance with Art. 37 Para. 7 GDPR, publication of the contact details in accordance with Art. 13 GDPR on the website and in data protection information. These steps cannot be postponed because without a formally reported DPO, the obligation under Art. 37 GDPR remains unfulfilled and defending against fine notices also becomes more difficult.
Day 6 to 12: Inventory of the existing documents, review of the processing directory, review of the TOM list, review of all order processing contracts in accordance with Art. 28 GDPR. Day 13 to 20: Gap analysis and prioritization. Which processing operations are not in the directory? Which AVV are missing? Which TOM are not documented? Which third country transfers run without standard contractual clauses and which data protection impact assessments are overdue?
Day 21 to 27: Development of the reporting path for data breaches in accordance with Art. 33 GDPR with 72-hour routing, including accessibility matrix and escalation levels. Day 28 to 30: First line of reporting to management, written status report with list of gaps, priorities and quarterly plan, including training planning for the next six months.
Others run compliance like a filing cabinet. We run it like software. In the CIVAC workspace, these five steps are stored as a standard process, including the filing paths and reminders of the respective deadlines. So after 30 days there is a documented status, not a to-do list lying dormant in the data protection coordinator's mailbox.
Termination and change of provider: What has to happen when you separate
A DSB service provider contract ends at some point, be it through a change, through an internal setup or through the provider's insolvency. The handover decides whether you will continue working seamlessly or whether you have to start from scratch. Four handover artifacts should be contractually anchored, supplemented by a minimum period during which the old and new DPOs work in parallel.
Firstly, the complete processing list in accordance with Art. 30 GDPR in machine-readable form, ideally as CSV, XLSX or JSON, not as a PDF. Secondly, the data breach register with all incidents, reports and closures including reference to the respective supervisory authority. Thirdly, the TOM list with the version status and last check date as well as the underlying risk analysis. Fourth, the audit log of the last 24 months, including all data subject requests and their processing with response deadlines.
When switching to the CIVAC platform, these artifacts are imported and transferred to the workspace, with the import taking place under ISO/IEC 27001:2022 certified conditions. When switching away from CIVAC, all data is exported in open formats, without vendor lock-in. This is not just market standard, this is the only way in which you can ensure the continuity of your DPO function. Anyone who checks a provider should have the export option guaranteed in writing before uploading the first data set.
A clear termination clause with a three-month notice period, written handover and a defined handover time prevents the most common supervisory complaint: a gap in the reporting line because the old DPO is already gone and the new one has not yet been ordered. Experience has shown that the greatest damage occurs in this gap because there is no one formally responsible for a data breach during this time. A three to four week transition phase with double staff closes this gap and is cheaper than any fine notice.
Turn reading into an assignment
If you choose a DSB service provider, you are building a function that should last for ten years. The choice determines whether your data protection compliance rests on a person, a filing cabinet or a platform with an evidence structure. You can answer three questions today: Which of the four market models suits your location structure? Which of the twelve selection questions can you already clearly answer from your current contracts? And which of the three contractual traps is open in your existing setup, i.e. response time, representation or directory scope? If you don't have a written answer to two of these three questions, you need to take action.
CIVAC offers both: the compliance platform and the officer-as-a-service. Licence the workspace for your internal representatives or have our representatives order it. Both models use the same ISO/IEC 27001:2022 certified infrastructure, the same 490 ready-to-use audit templates and the same EU data residency. The choice does not depend on a sales decision, but on where you are today and where you want to be in twelve months. If you have internal data protection coordination, start with the workspace. If not, have CIVAC appoint the person with an appointment certificate, supervisory report and reporting line.
If you want to carry out a specific provider comparison or have an existing contract checked, write to info@civac.de or use the contact form on civac.de. You will receive a structured proposal with a named person, response time and handover plan within two working days. The CIVAC SLA of two working days replaces the classic six-week path and makes switching providers a plannable project instead of a month-long marathon. You can also find an overview of the core questions in the CIVAC FAQ. Turn reading into an assignment.
FAQ
When is a DSB service provider legally mandatory?
According to Art. 37 GDPR and Section 38 BDSG, a data protection officer must be appointed if at least 20 people regularly process personal data automatically or if the core processing requires regular and systematic monitoring. Special categories of personal data according to Art. 9 GDPR also trigger the obligation. You are free to decide whether the person is appointed internally or integrated via a DSB service provider, as long as the requirements of Article 38 are met.
How much does a DSB service provider cost in medium-sized businesses in 2026?
For companies with 50 to 250 processing people, the market ranges between 700 and 1,400 euros per month as a flat fee. Additional costs arise for multiple locations, training, data breach reports and regulatory audits. Clarify these four items in writing when concluding the contract so that the flat-rate model is sustainable and there are no surprises as soon as the first supervision request is received or a new location is added.
How does Officer-as-a-Service differ from classic DSB outsourcing?
Officer-as-a-Service combines the designated person with a platform that consolidates the processing directory, TOM list and data breach reporting path. Classic outsourcing only names the person and often works with loose documents from the client. The difference becomes visible in regulatory exams when the examiner demands the evidence structure in under ten minutes and is unwilling to wait for an Excel reconstruction.
Can a DSB service provider also cover ISO/IEC 27001:2022 certification?
The DPO is not the information security officer; both roles are separated according to GDPR and ISO/IEC 27001:2022. However, a platform provider like CIVAC can serve both functions from one system, so that the DSB processing directory and ISMS controls lie in the same evidence structure without the roles being mixed. Synergies arise in TOM, risk analysis and reporting paths, not in the designation itself.
What response time should be contractually agreed?
For standard inquiries from data subjects, a contractual response time of 24 to 48 hours is recommended because the deadline according to Art. 12 GDPR is a total of one month and the preliminary examination takes time. In the event of data breaches, the DSB service provider must ensure 24-hour availability because the 72-hour period according to Art. 33 GDPR runs from the time of knowledge and weekends count.
How do I change the DSB service provider without a compliance gap?
Agree on a handover phase of at least 30 days in which the old and new DSB work in parallel. Have the processing directory, TOM list, data breach register and audit log handed over in machine-readable form. Report the new DPO to the supervisory authority in accordance with Art. 37 Para. 7 GDPR before the old one is deregistered so that there is no gap in the reporting line.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.