Business handshake, data protection for companies

External data protection officer for companies in Germany, 1,800 EUR per year

A company must designate a data protection officer when its core activities consist of regular and systematic monitoring of data subjects on a large scale or of large-scale processing of special categories of data (Art. 37(1) GDPR). In Germany the duty goes further. Under § 38 BDSG every company that regularly employs at least 20 persons in the automated processing of personal data must have a data protection officer, as must every company that carries out processing subject to a data protection impact assessment, regardless of size. For foreign companies with a German subsidiary or branch this is frequently the first German obligation they encounter. We take on the role as external data protection officer for an annual flat fee of 1,800 EUR.

What the annual fee covers

The designation and its notification to the competent supervisory authority, the ongoing advice to management and staff, the review of the record of processing activities and of the technical and organisational measures, the annual training of staff, the handling of data subject requests and of data breach notifications within the 72-hour deadline of Art. 33 GDPR, and the role of contact person for the supervisory authority and for data subjects. We review and answer the inquiries that your own customers’ data protection officers send you, which in business-to-business relationships are frequent. The contract runs for one year and renews for a further year unless terminated three months before expiry.

Smaller companies and groups

Companies below the threshold of 20 employees may appoint a data protection officer voluntarily, and some do because their customers expect it. For them and for non-profit organisations we offer reduced terms on request. For companies with more than 250 employees or several entities we quote individually on the basis of the expected workload.

Why an attorney as data protection officer

An external data protection officer who is an attorney is bound by professional secrecy and is independent of the IT department and the management, which is what Art. 38(3) GDPR requires. The supervisory authority deals with a counterpart who knows how an inquiry is answered. And if a matter turns into a proceeding before the authority, the same person can represent you.

Prices are net attorney fees. For business clients outside Germany no German VAT is added.

How to instruct us

Send us the details through the form below. You will receive our confirmation and, where required, our questions in English within one working day. We correspond in English throughout the mandate.

The German-language description of this offer, written for clients in Germany, Austria and Switzerland, is available at Externer Datenschutzbeauftragter. Please note that this link takes you to our German website matutis.de. You do not have to use it, everything you need to instruct us for the appointment as external data protection officer is on this page, and you are welcome to write to us in English at any time.

    Your data will only be used to process your inquiry. Further information on the processing of personal data can be found in our privacy policy.