Key Takeaways
- The external data protection officer is expressly provided for in Art. 37(6) GDPR. The role may be fulfilled on the basis of a service contract and does not have to be filled by your own staff member.
- Qualifying an internal data protection officer costs EUR 3,000 to 5,000 once, with mandatory further training at around EUR 1,500 per year. On top of that come EUR 600 to 1,000 in monthly salary uplift and 30 to 40 percent of one person's working time.
- External mandates are mostly billed as a monthly retainer, with a market range of EUR 30 to 800 depending on company size (German-speaking market, as of August 2026).
- Art. 38(3) GDPR prohibits instructions to the data protection officer and protects the role against dismissal. Internally this collides with the reporting line; externally the conflict never arises.
- Management, IT leadership, HR leadership, and administrators cannot hold the role because of the conflict of interest under Art. 38(6) GDPR. In teams under 250 people, the internal route often fails on exactly that.
The benefits of an external data protection officer come down to four things: expertise that is available immediately, cost you can calculate in advance, independence from the reporting line, and an effort level that scales with demand. Art. 37(6) GDPR treats both routes as legally equivalent. Whether the role is filled by a staff member or fulfilled under a service contract is a commercial decision, not a legal one. This article sets out where the external route performs better in practice, and where it does not.
Four benefits of an external data protection officer
1. Expertise you would otherwise have to build in-house
Art. 37(5) GDPR requires appointment on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices. In practice, legal knowledge alone is not enough. Anyone running a GDPR privacy program also has to read IT architectures, assess risk, and understand business processes. That combination is hard to hire and hard to build internally as a side responsibility.
An external mandate is usually carried by an established team rather than one individual. Case law, supervisory authority guidance, and enforcement practice get tracked continuously there, because several mandates depend on it. Art. 38(2) GDPR obliges the controller to provide the resources needed to maintain the data protection officer's expert knowledge. With an internal appointment that is a recurring budget line; with an external mandate it is part of the price.
The difference usually shows up under pressure. After a personal data breach, you have 72 hours to get the Art. 33 GDPR notification right. Anyone running that process for the first time loses exactly the time the deadline does not give you.
2. Cost you can calculate in advance
The cost of an internal data protection officer is rarely in the salary. Qualification costs EUR 3,000 to 5,000 once, mandatory further training around EUR 1,500 per year, and the salary uplift for the added responsibility EUR 600 to 1,000 per month. On top of that, 30 to 40 percent of that person's working time goes missing from the job they were hired to do. Filling the role internally does not buy a new function; it gives away part of an existing one.
An external mandate, by contrast, is priced before you sign. Monthly retainers in the German-speaking market, which is Europe's most developed market for this service, run from EUR 30 for very small companies on long contracts to EUR 800 in the mid-market, and hourly mandates sit between EUR 100 and EUR 200. One common misconception is that the retainer is the total price. Initial audits, processor agreement reviews, data protection impact assessments, and on-site meetings are billed separately by many providers. Which blocks are included and what they cost is set out in our breakdown of what an external data protection officer costs.
A worked example. A SaaS company with 60 employees appoints its Head of Legal Operations internally. Year one brings EUR 4,000 in qualification, EUR 1,500 in further training, and EUR 9,600 in salary uplift, so EUR 15,100 before a single processing activity has been documented. An external mandate of the same size sits at around EUR 500 per month, so EUR 6,000 a year, plus a one-off build-up.
3. Independence without a conflict of interest
Art. 38(3) GDPR is explicit on this point. The data protection officer receives no instructions regarding the exercise of those tasks, cannot be dismissed or penalized for performing them, and reports directly to the highest management level. Art. 38(6) adds that other tasks are permitted only so long as they do not result in a conflict of interests.
That is hard to build cleanly in-house. Management, IT leadership, and HR leadership decide on exactly the processing the data protection officer is supposed to review, and administrators implement it. All four are therefore ruled out. In teams under 250 people, what is often left is an appointment that is formally permissible but not the strongest available on the merits. Outsourcing the role sidesteps the question, because there is no second role inside the company to collide with.
There is a second point on lock-in, and it is specific to German law. Where the appointment is mandatory, an internal data protection officer has special protection against dismissal under Section 6(4) in conjunction with Section 38(2) of the German Federal Data Protection Act (BDSG), lasting until one year after the role ends. An external mandate ends with the contract term.
4. Flexibility when demand fluctuates
Privacy workload is not constant. A product launch, a new analytics tool, a change of hosting provider, or a data protection impact assessment under Art. 35 GDPR create peaks with quiet stretches in between. An internal role is sized for the average and therefore fits neither state well.
An external mandate can be sized to demand. As the company grows, scope grows with it, without a hiring round. If ISO 27001, NIS2, or the EU AI Act come later, the documentation and the point of contact stay the same. If the person covering you is unavailable, the provider's team steps in, where internally cover has to be arranged first.
Internal or external data protection officer: where the difference lies
Both routes are legally equivalent. The difference is in the employment terms and what follows from them.
One thing outsourcing does not move: responsibility for GDPR compliance stays with the controller. The data protection officer monitors and advises. They do not decide, and they do not carry liability in place of the company. A mandate buys expertise and independence, not indemnity.
What does an external data protection officer do?
The tasks of an external data protection officer are the same as an internal one's. Art. 39 GDPR names five: informing and advising the company and its staff, monitoring compliance with data protection law including awareness raising and training, advising on the data protection impact assessment under Art. 35 and monitoring its performance, cooperating with the supervisory authority, and acting as its point of contact.
Day to day, that means three things above all. They run and maintain the documentation: the record of processing activities, the technical and organizational measures, deletion concepts, and processor agreements. They develop policies for the lawful collection, processing, storage, and deletion of data, and update them when processes, technology, or the law change. And they are the point of contact outward: for the supervisory authority, for data subjects, and for their requests for access, deletion, rectification, portability, and restriction of processing.
Then there is the work on the organization itself. Employee data protection training is the part most likely to slip and the fastest to show up in an audit. After a change in the law or new guidance, the level of knowledge inside the company has to be brought up with it, or the policies apply to nobody.
Kertos as your external data protection officer
Kertos provides the external data protection officer as a named certified expert, combined with the platform where the documentation is produced. The mandate covers appointment and notification to the supervisory authority including the appointment certificate, a structured kick-off that reviews your existing privacy documentation and website settings, and ongoing support.
What separates this from a classic consulting mandate is how much work stays with you. The AI agent KAIA and over 100 integrations handle inventory, evidence collection, and documentation, while the certified expert makes the calls that need real expertise. Customers cut manual compliance effort by around 80 percent and compliance cost by up to 60 percent compared with traditional consulting.
"Amazing support after the purchase; we booked the DPO and he already helped us so much, always fast to answer or hop on a call."
Philipp H., Co-Founder, B2B SaaS, G2
"We particularly appreciate the integrated DPO service, it's like having a data protection expert on board without the extra overhead."
Verified User, Renewables & Environment, G2
To find out how a mandate would be scoped for your company, request a quote. We work through the requirements and show you the platform against your own processes.
Frequently asked questions
What are the benefits of an external data protection officer?
Expertise that is available immediately, cost you can calculate in advance, independence without a conflict of interest, and an effort level that scales with demand. In smaller companies the strongest single factor is usually independence, because management, IT leadership, HR leadership, and administrators cannot hold the role under Art. 38(6) GDPR.
Is an external data protection officer cheaper than an internal one?
Usually yes. An internal data protection officer costs EUR 3,000 to 5,000 in qualification, around EUR 1,500 a year in further training, and EUR 600 to 1,000 a month in salary uplift, plus 30 to 40 percent of their working time. External monthly retainers run from EUR 30 to 800 depending on company size.
Can a data protection officer be external at all?
Yes. Art. 37(6) GDPR expressly provides that the data protection officer may be a staff member or fulfil the tasks on the basis of a service contract. Both routes are legally equivalent.
Who inside a company cannot be the data protection officer?
Under Art. 38(6) GDPR the role must not result in a conflict of interests. That rules out anyone who decides on the purposes and means of processing or implements it, in practice above all management, IT leadership, HR leadership, and administrators.
Is an external data protection officer liable for data protection breaches?
No. Responsibility for GDPR compliance stays with the controller, meaning the company. The data protection officer monitors and advises under Art. 39 GDPR. They make no processing decisions and do not take the company's place.





