Outsourced DPO · GDPR Articles 37 to 39
Outsourced DPO: your external data protection officer, without hiring.
Looking for an external DPO? The GDPR itself provides for it: the data protection officer may fulfil the tasks on the basis of a service contract. Luxgap, a Luxembourg firm, takes on that role for your organisation, with lawyers, cybersecurity engineers and developers behind a single point of contact. We work in Luxembourg and the neighbouring countries (Belgium, France, Germany).
In-house or external DPO: what is the difference?
On the substance, none: the GDPR gives the officer the same tasks whether they are a staff member or work under a service contract (Article 37(6)). The difference is practical. An in-house DPO has to be recruited, trained and replaced when they leave, and their other duties must not create a conflict of interests (Article 38(6)). An outsourced DPO comes with a team: lawyers for the analysis, cybersecurity engineers for the technical questions, developers for the tooling.
For a mandate in Luxembourg, see also our DPO in Luxembourg page.
For a mandate in Luxembourg, see also our DPO in Luxembourg page.
Is my organisation required to appoint a DPO?
Yes, in the three cases set out in Article 37(1) GDPR: the processing is carried out by a public authority or body (courts acting in their judicial capacity excepted); your core activities require regular and systematic monitoring of data subjects on a large scale; or your core activities consist of large-scale processing of sensitive data or data relating to criminal convictions and offences (Articles 9 and 10). The duty applies to controllers and processors alike, and Union or Member State law can extend it to other cases (paragraph 4).
Outside those cases you may appoint a DPO voluntarily, who is then subject to the same rules (Articles 38 and 39).
Outside those cases you may appoint a DPO voluntarily, who is then subject to the same rules (Articles 38 and 39).
How do you appoint an external DPO and notify the CNPD?
The appointment rests on a service contract: you entrust the DPO role to Luxgap (Article 37(6)). The GDPR then asks for two steps: publish the DPO's contact details, including in the information given to data subjects (Article 13), and communicate them to the supervisory authority, which in Luxembourg is the CNPD (Article 37(7)). We prepare both with you.
The DPO is chosen for their professional qualities and expert knowledge of data protection law and practice (Article 37(5)). An entity established in another Member State communicates the details to that country's authority, for example the APD in Belgium or the CNIL in France.
The DPO is chosen for their professional qualities and expert knowledge of data protection law and practice (Article 37(5)). An entity established in another Member State communicates the details to that country's authority, for example the APD in Belgium or the CNIL in France.
What does an outsourced DPO actually do?
The minimum tasks are set by Article 39 GDPR: inform and advise management and employees; monitor compliance, including the assignment of responsibilities, awareness-raising and training of staff, and audits; provide advice, where requested, on impact assessments and monitor their performance; cooperate with the CNPD and act as its contact point.
Under a Luxgap mandate this covers, in practice, the records of processing (Article 30), impact assessments (Article 35), the procedure for data subject requests, data breach handling, with notification to the CNPD in principle within 72 hours where the breach is likely to result in a risk (Article 33), the review of processor contracts (Article 28) and training for your teams. The mandate is described step by step on our outsourced DPO mandate page.
Under a Luxgap mandate this covers, in practice, the records of processing (Article 30), impact assessments (Article 35), the procedure for data subject requests, data breach handling, with notification to the CNPD in principle within 72 hours where the breach is likely to result in a risk (Article 33), the review of processor contracts (Article 28) and training for your teams. The mandate is described step by step on our outsourced DPO mandate page.
Is the outsourced DPO responsible for compliance?
No. The controller remains responsible for compliance and must be able to demonstrate it (Article 24). The DPO advises and monitors; the decisions stay with you.
In return, Article 38 protects the role: the DPO is involved properly and in a timely manner in all data protection issues, is given the necessary resources, receives no instructions regarding the exercise of the tasks, cannot be dismissed or penalised for performing them, and reports directly to the highest management level.
In return, Article 38 protects the role: the DPO is involved properly and in a timely manner in all data protection issues, is given the necessary resources, receives no instructions regarding the exercise of the tasks, cannot be dismissed or penalised for performing them, and reports directly to the highest management level.
How much does an outsourced DPO cost?
It depends on your scope: number of entities and staff, volume and sensitivity of the processing, the state of your records at the start, and the on-site presence you expect. Pricing is quote-based: you configure the quote online, item by item, and receive a proposal within 24 business hours.
Build my quote →
Build my quote →
Let's talk about your situation.
Quote within 24 business hours. No commitment, no sales pressure.