How to Choose an Outsourced Data Protection Officer

Choosing an outsourced Data Protection Officer (DPO) is not just a compliance decision. It’s one about how your organisation manages risk, accountability and regulatory exposure. I have been an outsourced and in-house DPO, and looked for an outsourced DPO. This post shares both my learnings from the process and some general insider tips.

@anniespratt on Unsplash

When Do You Need to Appoint a DPO?

Article 37 of the UK GDPR requires you to appoint a DPO if:

  • You’re a public authority/body (e.g. council) but not courts acting in their judicial capacity.

  • The essence of your data processing includes large scale, regular monitoring of people (employee monitoring surveillance provider, credit scoring, adtech).

  • The essence of your data processing is based on special category data (e.g., health, biometrics) or criminal offence data (HR analytics provider, criminal background checking services).

In any other scenario, you may choose to voluntarily appoint a DPO. In that case, the same responsibilities will apply to them even though the law doesn’t say you must have them.

Alternatively, you can appoint a “data protection lead”, “data protection manager” or the like – someone who will look after your GDPR compliance but won’t hold the statutory title.

When External DPO Services Make Sense

When you think of the data protection role you want to fill, keep in mind you want it embedded in your organisation, workflows and processes for it to work and fulfil the job you want it to. This applies to both a hired and outsourced person.

I have seen organisations struggle most with structuring a data protection team.

Read what an effective GDPR team looks like.

In practice, if you are legally required to have a DPO, they should be either:

  • In-house, to ensure no risks are missed and can support the privacy and wider team with activities and their compliance.

  • Outsourced, provided that they have regular contact with the internal team and relevant stakeholders. Having them just on paper but not speaking to them regularly, or only engaging with them when serious risks arise, will not be enough.

From experience, a combination of internal and external support is optimal. An internal data protection lead can manage day-to-day activities and stay close to the business, while an outsourced DPO provides independent oversight and senior advice.

Even when a DPO is not legally required, many organisations appoint one voluntarily.

  • SMEs without in-house privacy expertise

  • Organisations with limited processing risk but regulatory exposure

  • Companies needing independent oversight

  • Organisations going through rapid growth or digital transformation

What a Good External DPO Should Do

There is a wide range of outsourced DPO providers in the UK, which makes it increasingly important for organisations to understand what good looks like.

The DPO’s key functions include (Article 39):

  • Monitoring compliance with UK GDPR and related laws

  • Raising potential issues and risks

  • Acting as a contact point with regulators

  • Supporting data subject rights

  • Independent oversight of your activities

If these function are not somehow referenced in the provider’s terms and conditions, this should raise questions.

A DPO should not simply produce policies either – the role involves ongoing advice, challenge (you) and oversight.

Outsourced DPO Red Flags

Think twice before committing if the outsourced DPO’s provider pitch looks something like:

  • A statement that says “you will be compliant in X days”.

  • No significant data protection exposure, but knowledge of data security, legal (all useful but insufficient).

  • You can’t tell who the team is and who your DPO might be – who is working there?

  • They give you some policy templates and leave it you to it.

  • Where services are priced significantly below market expectations, it is worth understanding how ongoing oversight and availability are delivered in practice.

If your chosen provider raises red flags, it doesn’t necessarily mean there is something wrong with the service. However, it does mean you must ask them more questions while you’re discussing your requirements to double check they are appropriate.

What to Look Out for in an Outsourced DPO Provider

Knowledge

While there is no specific list of requirements for a DPOs’ CV, one thing is clear: they need to have the relevant knowledge and experience to be able to advise on your specific processing.

In simple words, an outsourced DPO who specialises in public sector data use, or supports the creative industries, may not be the best choice for an organisation that works in the adtech industry. There is a mismatch between their expertise and the data use they will be advising on.

This does not mean they will be a poor DPO, but you should keep in mind you may be their first client outside of their usual expertise and be aware of the risks this may bring.

Experience

The DPO is a senior role, so you should have someone who has had experience with real GDPR implementation, regulatory engagement, and incident response.

Knowing the theory, having all certifications but no practical experience or such that is limited to data subject access requests is unlikely to suffice.

Independence

The DPO must be able to challenge internal decisions internally. The organisation is partly responsible for this, in the sense that the internal team shouldn’t penalise the DPO for doing their work when, for example, a stakeholder doesn’t like the advice.

If you decide to outsource the privacy function to your main IT provider, for example, this could be a conflict of interest regardless of the discount you may receive for them.

Time Allocation

Where does your money go? This is a service, after all, so you have the right to check whether the SLAs work for you, if there are available, along with out-of-office responses and urgent enquiries.

I discuss various pricing models below. Don’t shy away from financial questions, specifically how time is allocated to you as a client, what happens if you go through a quiet time, are there any hidden fees, etc.

Questions to Ask when Researching Outsourced DPOs

You can choose some of these questions and ask them to the different providers you speak to, so you can compare them objectively:

  1. Do we always have the same point of contact? – Sometimes you deal with account managers before you reach an actual consultant.

  2. Who will actually act as our DPO? – Many firms sell the service but assign junior consultants.

  3. Can we choose our DPO? – It is often an internal decision who your DPO is but you may be able to influence that if you have seen the team and prefer someone specific.

  4. How many organisations does one DPO support? – This helps to understand how much attention you get.

  5. Is your service reactive or proactive? – This tells you how much they depend on engagement from the organisation, i.e., if they improve compliance in the background even when it’s quiet, or if they are mostly involved when there is a lot of active work that needs actioning.

  6. (If the service is hours based) Do the hours expire at the end of the month if unused? – This can feel a bit like clock watching, so up to you whether you can accept it.

  7. (If the service is hours based, follow up from #6) Do the unused hours roll over and for how long / can we bank them for a busy period? – If it were me, I would prefer that the hours didn’t expire because I think it’s better value; but again, it would be up to you to decide.

  8. Can the DPO come to the office occasionally? – If you do want them to come in and meet the team or attend meetings. bear in mind this will be expensed in most situations or may be charged on a per-day fee.

  9. What are the fees for work not included or if we run out of hours? – This will tell you both what is out of scope and how much you may need to invest additionally.

A good outsourced DPO provider should welcome every one of these questions.

Typical DPO Services Pricing Models

The list below are some example of pricing models.

Organisations should be cautious of providers offering purely reactive or extremely low-cost services, as these rarely deliver the level of oversight required under the UK GDPR. The price should reflect the level of risk management and expertise you're receiving.

Monthly Retainer

  • Fixed monthly fee

  • Includes a defined level of support (hours, meetings, advice, activity)

  • Includes ongoing DPO designation and availability

  • It works well for organisations needing continuous advice and oversight.

Tiered Subscription

  • Predefined packages with increasing levels of service

  • Gives buyers a clear scope and easy comparison

  • There is a risk of the service becoming inflexible depending on the tiers.

Time-based (hourly/day based)

  • Charged per hour or per day, totalling at £X per month

  • Gives buyers flexibility and expertise

  • There is a risk of focus being on time spent rather than value delivered.

Final Words Before You Buy

Having an outsourced DPO is a wise move, especially if you are required to have one but can’t afford to have an employee and a support team. In either capacity, the DPO is your trusted advisor, so you should do just that – trust them.

Before you entrust them with the personal data you process, you should check that they can do the job, just like you’d interview a candidate before you hire them. It has to be a good fit.

Only because you have an outsourced DPO, it does not mean that you can’t have or add an internal data protection role (as long as you don’t call them DPO). This creates a stronger governance structure, enabling organisations to make more efficient, informed and defensible decisions about use of personal data.


Previous
Previous

Data Protection Impact Assessments Explained Simply

Next
Next

Ideal Data Protection Team for an Effective Privacy Function