External Data Protection Officer: Provider Models Compared
Key takeaways
- The market for external data protection officers splits into four provider models: a law firm or independent consultant, a general consultancy with a pool of DPOs, a US compliance platform that sells software only, and a European platform with named certified experts.
- The appointment under Art. 37 GDPR is always held by a person or a service provider, never by software. A platform without named experts can carry your evidence; it cannot be your DPO.
- One question decides the selection: should your documentation be produced for you, or only reviewed? Law firms and classic consultancies mostly review and advise; platform models generate the evidence as the business runs.
- A law firm is the better fit for litigation, a supervisory-authority procedure, or a group structure with joint controllership. An independent local consultant is the better fit where on-site presence and sector knowledge decide the outcome, for example in medical practices or in businesses with public footfall.
- Kertos sits in the fourth model. The AI agent KAIA and more than 100 integrations carry the documentation; a named certified expert holds the appointment. Hosting and jurisdiction stay in Europe.
Providers of external DPO services cannot sensibly be ranked against each other, because they sell different things. What can be compared is the model behind them. What a mandate costs per month is the last question, not the first; the market ranges and the individual cost blocks are in our overview of what an external DPO costs.
Which provider models exist for an external DPO?
Law firm or independent consultant. One person holds the appointment and brings legal depth. Billing is mostly hourly or by the day. Your documentation is produced in-house and reviewed by the firm.
General consultancy with a pool of DPOs. A team covers several mandates, so cover during leave or absence is organized. The named contact can change over the life of the mandate; the tools in use are usually templates and spreadsheets rather than a system.
US compliance platform. The focus is evidence for controls across many frameworks, with broad integration depth into common cloud services. The DPO role is a role held by a person, and in this model it is usually covered through a partner or not offered at all. Check that in the proposal rather than assuming it.
European platform with named certified experts. Software and mandate come from one provider. The expert is named and reported to the supervisory authority as the contact; the evidence is generated inside the system that also holds your processing activities and your vendors.
How do you tell which provider model fits you?
By seven criteria that rarely appear in a proposal comparison, even though they determine the effort of the first year.
| Criterion | Law firm or independent consultant | General consultancy with DPO pool | US compliance platform | European platform with named experts |
|---|---|---|---|---|
| Who holds the Art. 37 GDPR appointment | the engaged person | the provider, with a changing person day to day | usually not part of the offering, check partner coverage | a named certified expert employed by the provider |
| Documentation | you produce it, the firm reviews it | templates are supplied, filling them in stays with you | generated in the tool, the assessment stays with you | generated in the system, the expert does the assessment |
| Audit or supervisory-authority inquiry | strong representation, evidence has to be assembled | support within the mandate, evidence depends on your upkeep | evidence is exportable, correspondence stays with you | evidence is already there, the named expert handles correspondence |
| Response time and cover | depends on one person, absence is a risk | cover is organized, response time to be fixed in contract | product support, no professional opinion | cover within the expert team, one standing contact |
| Scope | almost everything billed by effort | retainer plus add-ons such as initial audit, DPA review, and DPIA | license per user or per framework, advice priced separately | mandate and platform in one scope, add-ons clearly bounded |
| Where the data sits | with the consultant, often email and cloud folders | with the provider, tooling differs per mandate | EU data residency available, the parent company is subject to US law | European hosting, European entity, and European jurisdiction |
| Language and jurisdiction | your own, local law | your own, local law | product and support in English, vendor jurisdiction United States | your supervisory authority's language, EU law, platform multilingual |
An eighth criterion is not in the table, because it attaches to the person rather than to the model: the qualification of whoever is actually appointed. Internationally, the IAPP certifications are the recognized proof, above all CIPP/E for European data protection law and CIPM for privacy program management. In the German market a TÜV examination often carries more weight with buyers outside the profession, so a German-speaking prospect may ask for that instead. A law degree is a further signal, but it does not replace the data protection practice that Art. 37(5) GDPR also requires.
What does a US compliance platform do, and what does it not do?
It produces evidence across many frameworks at once, and it does that well. If your company belongs to a US group, needs a SOC 2 report, and has already filled the DPO role internally, that is a workable choice.
Two things change the calculation once a European mandate is added. First, the appointment under Art. 37 GDPR is not a function software can perform. Art. 37(7) GDPR requires you to publish the DPO's contact details and communicate them to the supervisory authority, and a reachable person has to sit behind them, including for requests from data subjects in their own language.
Second, data residency is not data sovereignty. A hosting location in the EU says nothing about which law the parent company answers to. Where that parent sits in the United States, US law can open access to data processed by a European subsidiary. For your own vendor assessment that means you have to document the chain, however convincing the hosting statement in the proposal reads.
If you are only looking for software and the mandate stays internal, the comparison is a different one. We cover that separately in our overview of data privacy software and its vendors.
When is a law firm or a local consultant the better choice?
A law firm when the weight of your need is legal rather than organizational. Live litigation, a procedure opened by a supervisory authority, a group structure with joint controllership under Art. 26 GDPR, or employee data protection with works council involvement: in those situations legal representation is worth more than a well-kept record.
A local consultant when on-site presence and sector knowledge decide the outcome. In medical practices bound by professional secrecy, in law firms, in trades with public footfall, and in production environments, the site visit is a real part of the work and hard to replace remotely.
These cases are not the majority and they do not rule out a platform model. They only change the order of the decision: if legal representation comes first, do not start with the tooling question.
Why combine software with named experts?
Because data protection fails on documentation, not on expertise. The effort does not sit in one-off advice. It sits in keeping the record of processing activities current, tracking data processing agreements, evidencing retention periods, and being able to produce training records when someone asks two years later.
In the first three models that work is yours, or it is an add-on. The consultant assesses a state of affairs you had to describe to them first. Between two appointments the company changes and the documentation does not; at audit, that is exactly the gap that shows.
The combination reverses the order. The evidence is generated as a by-product of the business running, because the systems are connected, and the expert works from a current picture rather than from a briefing. What is left for them is the work that requires expertise: assessing a data processing agreement, deciding whether a DPIA is needed, and writing the response to a supervisory authority.
One point does not shift in any model. Responsibility for GDPR compliance stays with the controller. The DPO monitors and advises under Art. 39 GDPR; they do not decide and they do not carry liability in place of the company. Appointing a DPO buys expertise and independence, not an indemnity. Why an external appointment is legally equivalent to an internal one, and where it performs better, is set out in our article on the benefits of an external data protection officer.
Where does Kertos sit in this comparison?
Kertos is the European platform with named certified experts, and it suits companies that need both a defensible set of documentation and a person who holds the appointment. The typical fit is a tech company between 20 and 250 employees serving at least one framework besides the GDPR, most often ISO 27001, NIS2, a SOC 2 report, or the EU AI Act.
The external data protection officer service from Kertos covers the appointment including notification to the supervisory authority and the appointment certificate, a kick-off that reviews your existing documentation and website settings, and ongoing support from one standing contact. The platform brings together your record of processing activities, vendor assessment, data subject requests, and employee training. The AI agent KAIA and more than 100 integrations take over inventory and evidence collection, which is why customers reduce manual compliance effort by around 80 percent. The audit pass rate is 100 percent, and AskUI reached ISO 27001 certification in 8 to 10 weeks without external consultants.
Whoever holds your mandate is fixed before you sign and is named. Qualifications are distributed across the expert team and not everyone holds every credential; the team includes the IAPP certifications CIPP/E and CIPM, TÜV-examined data protection officers, and law degrees. Professional liability insurance is in place for the mandates.
Kertos is not the right choice if what you primarily need is legal representation in a live procedure, or if regular on-site visits are the core of the service. In both cases the first two models fit better.
To see how a mandate would be scoped for your company, we will walk through it against your own processes in a no-obligation demo.
Frequently asked questions
Which external DPO provider is the right one?
That is decided by the model, not by the provider. If you need legal representation, a law firm is right. If you need on-site presence, a local consultant. If you do not want to maintain the documentation yourself and still want a named person, a platform with its own certified experts is the fitting model. Compare proposals along the seven criteria in the table above rather than along the monthly retainer.
Can software be the data protection officer?
No. Art. 37 GDPR requires a designated party whose contact details you publish and communicate to the supervisory authority, and under Art. 38(3) GDPR that party has to work independently, free from instructions, and report to the highest management level. Software can carry the evidence and shorten the work considerably; it cannot fill the role.
How do I recognize a credible external DPO provider?
By four checkable points. First, the qualification of the person actually appointed, not that of the company. Where the function is carried by a team, the service contract should name one person as lead contact, as the guidelines on data protection officers endorsed by the European Data Protection Board set out. Second, professional liability insurance, with its existence and scope confirmed to you in writing. Third, response times fixed in the contract and cover that is organized. Fourth, a clear list of what the retainer includes and what is billed by effort, in particular the initial audit, data processing agreement reviews, and DPIAs.
Law firm or service provider: which is better as an external DPO?
Both are equally permissible under Art. 37(6) GDPR, but they solve different problems. The law firm is stronger wherever legal questions, procedures, and liability are at stake. The service provider is stronger in continuous operation, because cover, documentation, and recurring tasks are organized. Companies with an ongoing compliance workload and no acute legal question are usually better served by the service provider model.
Can I change my external data protection officer?
Yes. You revoke the appointment, appoint the successor, and communicate the changed contact details to the supervisory authority. The practical effort is not in the change itself but in the handover: agree before signing in what format you get your record, contracts, and evidence out. A provider that keeps your documentation only inside its own tool, with no export, makes leaving expensive.
Legal status: 27 August 2026. This article frames provider models for a selection decision and is intended as professional orientation. It is not legal advice for an individual case; the specific shape of a mandate should be agreed with a data protection officer or a lawyer.
Discover our Resources
Find useful whitepapers, videos, and practical tools to help you efficiently achieve your compliance goals.


