Compliance & Governance

DPO – Data Protection Officer

An outsourced data protection officer under Articles 37 to 39 of the GDPR: independent, continuous oversight that informs the board, monitors compliance and liaises with the Italian Data Protection Authority (Garante) and with data subjects, without adding to the internal workload.

What we do

Our areas of work

Designation and notification to the Garante

We assess whether designation is mandatory (Article 37) or advisable, prepare the designation letter setting out the tasks and the safeguards for independence, and handle, on the controller’s behalf, notification of the DPO’s contact details to the Garante (Article 37(7)).

Information and advice to the board

We provide written opinions on new processing activities, projects and supplier contracts, and answer queries from the business functions, setting out the risks, the legal bases and the appropriate measures (Article 39(1)(a)).

Monitoring compliance with the GDPR

We schedule periodic checks on the record of processing activities, privacy notices, appointments of processors and authorised staff, security measures and retention periods; we document the findings and track the corrective actions with the function heads.

Advice on impact assessments

We take part in DPIAs (Article 35) with a reasoned opinion on necessity, methodology and mitigating measures, and we monitor their performance as required by Article 39(1)(c).

Data breaches and data subject requests

We act as the contact point for data subjects and support the controller in assessing breaches, in notifying the Garante where the conditions are met (Article 33: where feasible, within 72 hours) and in responding to requests from data subjects exercising their rights.

Relations with the Garante and annual report

We cooperate with the supervisory authority in the event of requests, complaints or inspections, and we present the board with an annual report on the work carried out, the risks identified and the priorities for the year ahead.

The regulatory framework

Regulation (EU) 2016/679 devotes three articles to the data protection officer (DPO). Article 37 establishes when designation is mandatory. There are three cases: public authorities and bodies; regular and systematic monitoring of data subjects on a large scale as a core activity; and large-scale processing, again as a core activity, of special categories of data (Article 9) or of data relating to criminal convictions and offences (Article 10). Article 38 defines the DPO’s position: timely involvement in all matters relating to personal data, adequate resources, no instructions regarding the performance of the tasks, no dismissal or penalty for performing them, direct reporting to the highest management level, a duty of secrecy and the absence of any conflict of interest. Article 39 lists the tasks: to inform and advise, to monitor compliance with the Regulation, to provide advice on impact assessments, to cooperate with the supervisory authority and to act as its contact point.

The DPO’s contact details must be published and notified to the Garante through its dedicated online procedure, and they appear in privacy notices, in the record of processing activities and in breach notifications. The WP243 Guidelines of the Article 29 Working Party, endorsed by the EDPB, together with the Garante’s FAQs, clarify the notions of “large scale”, “core activities” and “regular and systematic monitoring”. Article 37(6) expressly provides that the DPO may be an external party fulfilling the tasks under a service contract; WP243 recommends that, where that party is a company, a single lead contact be identified for the client.

For the business, the stakes are real. Failure to designate a DPO where one is required, or a purely formal appointment of a DPO who lacks resources or is in a conflict of interest, is among the infringements punishable by fines of up to €10 million or 2% of total worldwide annual turnover (Article 83(4)). The designation and position of DPOs have also been the subject of a coordinated enforcement action by the European data protection authorities.

Our approach

Appointing a DPO is not a formality to be filed away: it establishes a function that has to be involved whenever the business takes decisions about data. We therefore build the service as continuous support for management and the operational functions, with an activity plan agreed at the outset and reviewed every year.

Everything we do is recorded in a DPO activity log: opinions given, consultations received, checks carried out, findings and corrective actions. It is the tool that allows the controller to demonstrate, in the event of an inspection or a complaint, that the function was involved and that the choices made were properly considered, even where the board chose not to follow a recommendation.

The service combines legal and technical expertise. We read supplier contracts and the clauses on international data transfers, and we are equally able to assess logs, configurations and security measures, and to deal with IT directly. Where the business has a 231 Model under Italian Legislative Decree 231/2001, falls within the scope of NIS2 (Italian Legislative Decree 138/2024) or operates an ISO/IEC 27001:2022 management system, we coordinate the work of the DPO with those bodies and requirements: information flows to the Supervisory Body (OdV) on computer crime offences, a single procedure for incidents and breaches, a single supplier register.

What sets our service apart

  • Real independence: the outsourced DPO sits outside internal reporting lines, and the opinions given remain independent even when they are unwelcome.
  • Legal and technical expertise together: we read contracts and data transfer clauses, but we also assess logs, configurations and security measures, dealing with IT directly.
  • Integration with Decree 231, NIS2 and ISO/IEC 27001: we coordinate the work of the DPO with the Supervisory Body (OdV) and with management systems already in place, under a single procedure for incidents and breaches and a single supplier register.
  • Measurability: the annual plan, the activity log and the report to the board show clearly what has been done, what remains to be done and in what order of priority.

Our method

How we work

  1. Preliminary analysis

    We verify whether designation is mandatory, map the scope of the processing activities and carry out an initial review of the existing documentation; with management we define the oversight model best suited to the size of the business.

  2. Designation and start-up

    We prepare the designation letter and the service contract, draft the notification to the Garante for the controller to sign, add the DPO’s details to privacy notices and to the record of processing, and introduce the role to the function heads.

  3. Taking up the role

    We examine the record of processing, DPIAs, procedures and supplier contracts; we identify the weak points and agree an annual activity plan with priorities, owners and deadlines.

  4. Oversight and checks

    We meet the contacts in each function at an agreed frequency, issue opinions on request, carry out sample checks, support the business on data breaches and data subject requests, and train staff.

  5. Reporting and review

    We present the board with the annual report covering the work carried out, the residual risks and our recommendations; we review the plan in the light of regulatory developments and organisational change.

Benefits

What the business gains

  • Genuine independence: the DPO holds no operational role in the company, and conflicts of interest are assessed and documented at the outset
  • Legal and technical expertise in a single point of contact, with no need to train an in-house specialist and keep their skills up to date
  • Continuity of oversight: the service is not interrupted by annual leave, absence or staff turnover
  • Predictable cost, with an agreed fee proportionate to the size and the risk profile of the business
  • Documented evidence of the DPO’s work, valuable in the event of an inspection, a complaint or a request from clients and partners

Deliverables

What we deliver

  • DPO designation letter and service contract
  • Notification to the Garante, ready for the controller’s signature, with the DPO’s details added to privacy notices and to the record of processing
  • Annual DPO activity plan with a schedule of checks
  • DPO activity log: opinions, consultations, checks and findings
  • Written opinions on processing activities, DPIAs, contracts and projects
  • Reports on the periodic checks, with recommendations and the status of corrective actions
  • Written assessments of data breaches and opinions on responses to data subject requests
  • Annual report to the board and training sessions for staff

Frequently asked questions

Answers to the questions we hear most often

Are we required to appoint a DPO?

Yes, in the three cases set out in Article 37 of the GDPR: public bodies; regular and systematic monitoring on a large scale as a core activity; and large-scale processing, again as a core activity, of special categories of data or of data relating to criminal convictions and offences. The grey areas concern businesses that profile customers, track vehicle fleets or handle health data: here the tests of “large scale” and “core activities” in the WP243 Guidelines are decisive. In all other cases designation is optional, but Articles 37 to 39 apply in full to a voluntary DPO. We put the assessment in writing, including where the business decides not to appoint a DPO.

Why an outsourced DPO rather than an employee?

The DPO must not be in a position of conflict of interest: anyone who decides the purposes and means of processing cannot hold the role, and an employee designated as DPO still has to be trained, given time and resources, and protected against dismissal or penalty for performing the tasks (Article 38). An outsourced DPO is bound to the controller by a service contract rather than by a reporting line, and works with an internal point of contact: the business keeps control of its own data and gains oversight that is independent of internal dynamics.

What does the annual fee cover?

The DPO’s routine work: scheduled meetings with the contacts in each function, written opinions, sample checks, upkeep of the activity log, support on data breaches and data subject requests, relations with the Garante and the annual report. The number of days and the frequency are set out in the proposal. Remediation projects, such as building a record of processing and procedures from scratch, are quoted separately, with safeguards that keep the design of the measures separate from the monitoring of their implementation.

Is the DPO liable for fines instead of the company?

No. Responsibility for compliance remains with the controller (Articles 5(2) and 24 of the GDPR) and, within its own remit, with the processor (Article 28). The DPO informs, advises and monitors; the board decides. That is why we document opinions and recommendations: if the business chooses not to follow them, the decision and the reasons for it remain on record and defensible.

We have several companies in the group: does each one need its own DPO?

No. Article 37(2) allows a group of undertakings to appoint a single DPO, provided that the DPO is easily accessible from each establishment. We prepare the designation for each controller in the group, handle the related notifications to the Garante and structure the oversight taking account of the specific features of each company.

Let’s talk

Together, let’s build your tomorrow.

Tell us your business priorities: in a first meeting with no obligation we look at your context and propose a concrete way forward, with clear timescales and measurable results.