Entry 02
Internal or external DPO: what the service contract has to carry
The legal basis for the entire DPO-as-a-service market is one sentence. Everything that determines whether a particular outsourced appointment is sound sits elsewhere, in the position and task provisions that a commercial services agreement was never designed to accommodate.
What Article 37(6) actually permits
The provision reads in full: "The data protection officer may be a staff member of the controller or processor, or fulfil the tasks on the basis of a service contract." That is the whole of it. There is no accreditation requirement, no registration of providers, no restriction on the type of entity that may hold the role, and no rule that the officer must be a natural person on your payroll.
The Article 29 Working Party fills in the shape. The function can be exercised on the basis of a service contract concluded with an individual or with an organisation outside the controller's or processor's organisation. Where an organisation holds it, two conditions follow immediately. Each member of that organisation exercising the functions of an officer has to fulfil all applicable requirements of Section 4 of the Regulation, including the absence of a conflict of interests. And each such member has to be protected by those same provisions, meaning no unfair termination of the service contract for activities as an officer, and no unfair dismissal of any individual member of the organisation carrying out the tasks.
The upside the guidance identifies is real: individual skills and strengths can be combined so that several individuals, working in a team, may more efficiently serve their clients. A three-person practice covering law, information security and sector knowledge can cover ground that one in-house appointee cannot. But that team structure is also where the arrangement most often becomes untraceable, which is why the guidance immediately adds a governance rule.
The named lead contact
For the sake of legal clarity and good organisation, and to prevent conflicts of interests for the team members, the Working Party recommends a clear allocation of tasks within the team and the assignment of a single individual as lead contact and person in charge for each client. It adds that it would generally be useful to specify these points in the service contract itself.
Ask for the name before you sign, and put it in the contract. There are three practical reasons. Your supervisory authority will want to reach a person, not a mailbox. Your staff and your data subjects need somebody identifiable to raise things with, which is difficult if every response arrives from a shared address. And the conflict analysis under Article 38(6) is performed on a person and their other roles; you cannot run it against an organisation chart you have never seen.
Lithuania's supervisory authority makes the same point from the filing side: where the designated officer is an employee of another legal entity, the notification has to state the name of that legal entity as well as the officer's own name. The identity of the individual is not optional information.
The contract problem: instructions
Article 38(3) requires that the officer "does not receive any instructions regarding the exercise of those tasks". The Working Party expands it: officers must not be instructed how to deal with a matter, for example what result should be achieved, how to investigate a complaint, or whether to consult the supervisory authority, and they must not be instructed to take a certain view of an issue related to data protection law.
A services agreement is, structurally, an instrument for giving instructions. Scope, deliverables, acceptance criteria, escalation paths and sign-off are what such agreements are for. Every one of those clauses is a candidate for an indirect instruction on the exercise of the tasks. A clause requiring your approval before the officer contacts the authority is an obvious breach. A clause capping the number of review hours in a way that predetermines what can be reviewed is a less obvious one.
The European Data Protection Board flagged the sharpest version of this in its 2024 report on the coordinated enforcement action. Controllers and processors using an external officer, it wrote, will need to be very mindful of the contractual relationship to ensure that it does not entail, either directly or indirectly, instructions as to how to carry out the officer's tasks. One supervisory authority encountered a data processing agreement between an organisation and its external officer, and pointed out that considering the officer as a data processor could lead to a breach of the independence requirements under Article 38(3).
Resourcing, and the question nobody asks
Article 38(2) obliges the controller and processor to support the officer by providing the resources necessary to carry out the tasks, access to personal data and processing operations, and the means to maintain expert knowledge. The Working Party's list is concrete: active support from senior management, at board level; sufficient time; adequate financial resources, infrastructure and staff; official communication of the designation to all staff; access to human resources, legal, IT and security; and continuous training. It adds a scaling rule: the more complex or sensitive the processing operations, the more resources the function needs.
Two items on that list are frequently missing from an outsourced arrangement. The first is time, and specifically a stated amount of it. Where the role is not performed full time, the guidance treats it as good practice to establish a percentage of time for the function, to determine the time needed, to fix the priority the duties carry, and for the officer or the organisation to draw up a work plan. A retainer expressed only in euros per month tells you nothing about any of that.
The second is the client load, and this is the question the Board put directly to buyers. Several supervisory authorities raised the concern that external officers acting for multiple controllers or processors may end up spreading themselves too thinly, representing too many clients and so being unable to spend appropriate time on each one. The recommendation is addressed to you: in some cases when employing an external officer, this may require controllers and processors to verify how many clients that officer has, to ensure they have sufficient time and capacity to fulfil the relevant obligations.
| Finding | Value | Source in the report |
|---|---|---|
| Officers who were staff members of the organisation | 70% | Section 3.1 |
| Officers working on the role full time (median across Member States) | 45.8% | Question 18 |
| Officers shared among several organisations (median) | 34.0% | Question 5 |
| Officers with an allocated budget who manage it independently (median) | 47.0% | Question 24 |
| Respondents saying the officer was consulted 100% of the time (median) | 22.5% | Question 27 |
| Supervisory authorities reporting likely conflicts or independence risks | 15 | Section 4.5 |
Location, language and reachability
The Working Party recommends that the officer be located within the European Union, whether or not the controller or processor is established in the Union. It leaves a narrow exception where the controller has no Union establishment and the officer could work more effectively from outside, but the default is clear.
Language is the requirement that catches distributed providers. The officer, with the help of a team if necessary, must be in a position to communicate efficiently with data subjects and to cooperate with the supervisory authorities concerned, and that communication must take place in the language or languages used by those authorities and those data subjects. Estonia's Data Protection Inspectorate puts it in plain terms in its own guidance: communication with the authority, the public and data subjects is expected in Estonian, and its proceedings are conducted in Estonian.
Reachability is a separate obligation. Article 37(7) requires the contact details to be published and communicated to the supervisory authority, and the objective, in the Working Party's words, is to ensure that data subjects both inside and outside the organisation, and the supervisory authorities, can easily and directly contact the officer without having to contact another part of the organisation. A postal address, a dedicated telephone number, a dedicated email address, a hotline or a contact form addressed to the officer will all do. A shared support queue will not.
Continuity and a deputy
The Regulation does not require a deputy, and the Board says so expressly. It also says why one is usually needed anyway: several supervisory authorities highlighted a lack of human resources and expressed concern about the absence of deputy officers, both for compliance today, because an officer expected to perform more work than they can handle will neglect something, and for long-term compliance, because leave, illness, resignation and burnout all happen.
Finland's Data Protection Ombudsman states the operational reason more sharply than the Board does: the officer should have a deputy, because personal data breach notifications and the fulfilment of data subject rights may not be delayed by the officer's absence. A seventy-two hour breach clock does not pause for annual leave. A provider organisation is well placed to solve this, and it is a fair question to ask how they do.
What you still have to supply
Outsourcing the officer does not outsource the obligations around the officer. Article 38(1) requires that the officer be involved, properly and in a timely manner, in all issues relating to the protection of personal data. The Working Party's checklist for that is: invite the officer to senior and middle management meetings regularly; have the officer present where decisions with data protection implications are taken; pass on all relevant information in time for advice to be useful; give the officer's opinion due weight and document the reasons where it is not followed; and consult the officer promptly once a breach or another incident has occurred.
None of those are things a provider can arrange for itself. They are governance changes inside your organisation, and if you do not make them, you will have bought a name for the privacy notice and very little else. This is also where the two models genuinely diverge: an internal officer is in the building when a decision is taken, and an external one is in the building when you invite them.
Choosing between the two
| Criterion | Internal staff member | External on a service contract |
|---|---|---|
| Legal basis | Article 37(6), first alternative | Article 37(6), second alternative. Identical standing. |
| Independence risk | Conflict with another internal role, particularly a senior or IT position | Conflict with other services the provider sells you, and contractual instructions |
| Protection against removal | Article 38(3) plus national employment law, which in several Member States is stricter | Article 38(3) applied to contract termination, so the term and notice clauses do the work |
| Knowledge of the organisation | High, and immediate | Has to be built and maintained, and is lost if the account team changes |
| Breadth of expertise | Limited to one person unless you build a team | A team can combine legal, sector and technical knowledge |
| Continuity | Depends on one person, unless a deputy is appointed | Provider can cover absence, if you ask how and check it is real |
| Availability at decision time | Present by default | Present only if your governance invites them |
| Contract risk | Employment contract, well understood | Wrong instrument, most commonly a processing agreement, breaks independence |
What drives the price, since nobody publishes one
This site quotes no figures, because none could be verified against a primary source. What can be stated is what the Regulation makes expensive: the sensitivity and complexity of the processing, since the resource obligation in Article 38(2) scales with them; the number of establishments and Member States involved, because the language and accessibility obligations multiply; whether the officer also has to serve a group of undertakings under Article 37(2), which requires easy accessibility from each establishment; the volume of data subject requests and complaints routed through the officer under Article 38(4); and whether the organisation runs regular impact assessments on which the officer has to advise.
When you compare quotations, compare the amount of time each provider commits, the named individual behind it, and their client load. A cheaper retainer that buys four hours a month from someone carrying forty clients is not the same product as a more expensive one that buys a named officer with a stated work plan.
The conflict question, which is the other half of choosing a provider, is worked through in the conflict-of-interest entry. Once you have chosen, notifying the supervisory authority is the last step, and it is national.
Sources
- Regulation (EU) 2016/679 (General Data Protection Regulation) Article 37(2), (6) and (7) on group appointments, the service contract and contact details; Article 38(1) to (4) on involvement, resources, instructions and data subject contact.
- Guidelines on Data Protection Officers (DPOs), WP 243 rev.01 Section 2.5 on the service contract and the lead contact, section 2.4 on location, section 2.3 on accessibility and language, sections 3.1 to 3.3 on involvement, resources and instructions.
- 2023 Coordinated Enforcement Action: Designation and Position of Data Protection Officers Section 3.1 and questions 5, 18, 24 and 27 on resourcing; section 3.2 on client load and deputies; section 4.5 on the contractual set-up and the processing-agreement finding.
- Data protection officers: instructions for organisations and managers The deputy recommendation, and the statement that officers are not personally responsible for infringements.
- Data protection officer: information for organisations The Estonian-language expectation for communication with the authority, the public and data subjects.
- How to inform the State Data Protection Inspectorate about the Data protection officer of your organization Requirement to name the employing legal entity where the designated officer is external. Archived capture of the authority's page.
Queries
Queries
Related questions
Can a company be our Data Protection Officer, or does it have to be a person?
A company can. The Working Party confirms the service contract may be concluded with an individual or with an organisation, and that a team inside that organisation may carry out the tasks. It recommends assigning a single individual as lead contact and person in charge for each client, and specifying that in the contract.
Our provider sent a data processing agreement for the DPO engagement. Is that normal?
It is common, and it is a problem. One supervisory authority in the 2023 coordinated action found exactly that arrangement and pointed out that treating the officer as a data processor could breach the independence requirements in Article 38(3), because a processor acts on documented instructions and an officer must receive none on the exercise of the tasks.
How many clients should an external DPO have?
No number is fixed anywhere. The European Data Protection Board recommends that controllers and processors verify how many clients the officer has, to satisfy themselves that the officer has sufficient time and capacity. Treat an unwillingness to answer the question as the answer.
Does the DPO have to be in the same country as us?
Not the same country, but the Working Party recommends the officer be located within the European Union, and requires that communication take place in the language or languages used by the supervisory authority and the data subjects concerned. In practice that language requirement determines the answer more often than geography does.
Is an external DPO protected from being dropped for giving unwelcome advice?
Yes. Article 38(3) prohibits dismissal or penalty for performing the tasks, and the Working Party applies it to the service contract, ruling out unfair termination for activities as an officer as well as unfair dismissal of any individual carrying out the tasks. It also observes that the more stable the contract and the stronger the guarantees against unfair termination, the more likely the officer is to act independently.
Cluster
Keep reading
More entries in this register
-
Do you need a Data Protection Officer?
Three cases, no headcount threshold, and two words that decide almost every borderline call. The Article 37(1) test worked through with the Working Party's own examples.
Open entry -
DPO conflict of interest: where the line actually falls
The Court of Justice has given the test, the Working Party has named the positions, and supervisory authorities have found the failure modes. Including the ones that only appear when the officer is external.
Open entry -
Notifying your DPO to the supervisory authority
One sentence of European law, four completely different national filings. Latvia runs an examination, Estonia uses the business register, Finland publishes a warning, and Lithuania wants the employer named.
Open entry