What does an external data protection officer cost?
Key Takeaways
- External data protection officers in Germany are mostly billed as a monthly retainer. The market range runs from around EUR 30 per month for very small companies on long contracts to EUR 800 per month in the mid-market (as of August 2026).
- Hourly mandates sit between EUR 100 and EUR 200 per hour, with a market average of about EUR 150.
- The retainer is rarely the total price. Initial audits, processor agreement reviews, data protection impact assessments, deletion concepts, employee training and on-site meetings are billed separately by many providers.
- An internal DPO usually costs more: EUR 3,000 to 5,000 for the qualification, around EUR 1,500 per year for mandatory further training, EUR 600 to 1,000 in monthly salary uplift, and 30 to 40 percent of one person's working time.
Quoted prices for an external data protection officer range from EUR 30 to several hundred euros per month, and the offers behind them are barely comparable. The reason is that the retainer only covers part of the work. To plan the cost realistically, look at three blocks separately: the ongoing mandate, the one-off build-up work, and the effort that stays with your own team.
What does an external data protection officer cost per month?
The ranges below reflect the German market for external DPO mandates (as of August 2026, net prices).
| Company size | Typical monthly retainer | Usually included |
|---|---|---|
| up to 20 employees | EUR 30 to 150 | appointment and notification to the supervisory authority, software access, online training |
| 20 to 50 employees | EUR 150 to 350 | plus an advisory hour allowance and maintenance of the record of processing activities |
| 50 to 250 employees | EUR 350 to 800 | plus on-site meetings, management reporting, DPIAs |
| over 250 employees | individual, usually a framework agreement | group structures, multiple legal entities, dedicated contact |
The lowest entry prices are almost always tied to a 24 or 36 month term. The same provider often charges 50 percent more on a one-year term. Offers below roughly EUR 100 per month also tend to cap the number of processing activities, contracts or support hours.
What do audits, qualification and add-on services cost?
| Cost block | Typical market price |
|---|---|
| Hourly rate, external DPO | EUR 100 to 200, average around EUR 150 |
| Initial audit or gap analysis | day rate of EUR 1,000 to 1,500, 1 to 5 days depending on size |
| Initial build-up of the privacy management system | from around EUR 3,000 one-off |
| Qualification of an internal DPO | EUR 3,000 to 5,000 one-off |
| Mandatory further training for an internal DPO | around EUR 1,500 per year |
| Salary uplift for the internal DPO role | EUR 600 to 1,000 per month |
| Employee data protection training | from around EUR 12 per person per year |
Is an internal data protection officer cheaper?
On the numbers, almost never. On top of qualification and further training comes the salary claim for the added responsibility, plus 30 to 40 percent of working time lost to the person's actual role. Where the appointment is mandatory, an internal DPO also has special protection against dismissal under Section 38(2) in conjunction with Section 6(4) of the German Federal Data Protection Act (BDSG), lasting until one year after the role ends. Liability stays with the company either way. In teams under 250 people, the internal route often fails on conflict of interest: management, IT leadership, HR leadership and administrators cannot hold the role.
On the obligation itself: in Germany a data protection officer must be appointed as soon as at least 20 people are constantly engaged in the automated processing of personal data (Section 38(1) BDSG), and irrespective of headcount where processing requires a DPIA or involves special categories of data as a core activity. The Minister-Presidents' Conference has asked the federal government to repeal Section 38(1) BDSG by 31 December 2026 and limit the obligation to Art. 37 GDPR. Until then the 20-person threshold applies unchanged (verified: 3 August 2026).
Why does the monthly retainer say little about total cost?
Hourly billing and modular price lists move cost to where it is hard to plan. A mandate with a EUR 100 base fee can end up more expensive over two years than one at EUR 500 flat, once processing activities, processor agreement reviews, phone calls and the audit are charged individually. Check before you sign:
- How many processing activities and processor agreements are included, and what does each additional one cost?
- Are data subject requests, breach notifications and correspondence with authorities covered?
- Is the initial audit billed separately, and at what day rate?
- Is there a support allowance, and what happens once it is used up?
- What contract term does the entry price assume?
- Does the documentation work end up back with your team anyway?
What does the Kertos external data protection officer cost?
Kertos does not bill by the hour and does not publish an entry price, because the effort depends on company size, data categories, tool landscape and the state of your existing documentation. You get a fixed annual budget based on a scoping exercise, with no per-request charges. The Kertos DPO mandate covers the appointment and notification to the supervisory authority including the appointment certificate, a structured kick-off that reviews your existing GDPR documentation and website settings, ongoing support from a named certified expert, and access to the platform with data discovery, RoPA, TOMs, DPIAs, vendor management, data subject requests, incident management and employee training.
What separates this from a classic consulting mandate is how much work stays with you. The AI agent KAIA and over 100 integrations handle inventory, evidence collection and documentation, while the certified expert makes the calls that need real expertise. Customers cut manual compliance effort by around 80 percent and compliance cost by up to 60 percent compared with traditional consulting. If ISO 27001, NIS2 or the EU AI Act come later, the documentation and the contact person stay the same.
What do customers say about the Kertos external DPO?
"The combination of automating our compliance and acting as our DPO is unique mix, making Kertos the most suitable solution for any European startup."
Maurice S., Co-Founder and CEO, G2
"We particularly appreciate the integrated DPO service, it's like having a data protection expert on board without the extra overhead."
Verified User, Renewables & Environment, G2
"Amazing support after the purchase; we booked the DPO and he already helped us so much, always fast to answer or hop on a call."
Philipp H., Co-Founder, B2B SaaS, G2
Kertos supports European tech companies with a 100 percent audit pass rate and 98 percent customer satisfaction. AskUI reached ISO 27001 in 8 to 10 weeks, with no external consultants. To find out what an external data protection officer would cost for your company, request a quote. For the background on the role itself, read what an external data protection officer actually does.
Discover our Resources
Find useful whitepapers, videos, and practical tools to help you efficiently achieve your compliance goals.


