Your External Data Protection Officer
When it comes to the complex topic of data protection, seek advice from an experienced external data protection officer. Our experts will help your organization to pragmatically address the challenges of the GDPR.
Non-binding · 15 minutes · Free






✓ ISO 9001 certified
✓ on the market since 2003 ✓ from Berlin, Operating worldwideWhat is a
external Data protection officer?
An external data protection officer or external data protection officer is responsible in a company or organization for supporting compliance with data protection laws. The tasks of the data protection officer or data protection officers include, among other things, advising and training employees on data protection issues, monitoring data processing processes, collaborating with data protection supervisory authorities, and conducting data protection impact assessments. The data protection officer acts as the point of contact for all data protection issues and helps ensure the protection of personal data of customers and other data subjects and thereby strengthen their trust. The data protection officer plays an important role in the company when it comes to minimizing data protection risks and strengthening the trust of customers and business partners.

Jan Käding

Senior Consultant
mip Consult GmbH
What our external data protection officers are known for
We are an experienced team that interdisciplinary is set up and Expertise also in the areas related to data protection, such as IT consulting, information security, corporate advisory (especially process consulting) and legal advice (e.g. in competition law related to data protection).
As certified external data protection officers, we combine the necessary theoretical knowledge with years of practical experience. Furthermore, we place great emphasis on our ongoing training.
Non-binding · 15 minutes · free of charge
Internal vs. external data protection officer
What are the 5 most important differences?
Internal and external data protection officers each have their own advantages and disadvantages, as well as differences in terms of their role, responsibilities, and approach. Here are some of them: Important differences:
An external data protection officer or external data protection officer is particularly beneficial for companies that:
Special expertise on demand
They draw on the expertise of experienced data protection specialists without having to build up their own expertise.
Lack of internal resources
They do not have the internal capacity or expertise to permanently cover data protection.
Flexible instead of permanent employment
You need flexibility and do not want to finance a fixed part-time or full-time position for data protection.
Experience from many industries
You benefit from external insights and best practices to continuously improve your data protection practices.
Neutral and independent
They want a neutral body that advises them impartially and is free from any internal conflicts of interest.
We offer advice from professionally trained external data protection officers, supported by a team of IT experts and lawyers specializing in data protection. Our practice-oriented data protection officers are on hand to help you minimize data protection risks and keep your business processes and, above all, your costs in mind. With our data protection advisory service, you can be sure that everything is in order!
Why is it important for a company to have a data protection officer?
The appointment of a data protection officer is important for several reasons:
Legal obligation
In many cases, the appointment of a data protection officer is legally required. For example, in Germany, pursuant to § 38 BDSG (GERMAN FEDERAL DATA PROTECTION ACT), a data protection officer or a data protection officer must be appointed if at least 20 people are regularly engaged in the automated processing of personal data. Furthermore, a data protection officer or a data protection officer helps ensure that organizations comply with legal requirements, thereby reducing the risk of fines or legal consequences.
Expertise
A data protection officer or a data protection officer offers specialized knowledge in all topics related to data protection and can advise organizations on compliance with data protection laws.
Protection of privacy
Data protection officers monitor that the personal data of customers, employees, and other stakeholders are protected. By implementing appropriate data protection measures and policies, the privacy of the affected parties is ensured and trust in the company is strengthened.
Risk minimization
Data privacy violations can have significant consequences, such as high fines, reputational damage, or claims for damages. By proactively monitoring and advising, a data privacy officer or data privacy officer helps to prevent data privacy violations and minimize the associated risks.
Building trust
The presence of a data protection officer signals to customers and business partners that the company takes data protection seriously.
Competitive advantage
Companies that ensure effective data protection can position themselves as trustworthy and responsible organizations. This can give them a competitive advantage and set them apart from their competitors, especially in industries where data protection plays a particularly important role, such as in healthcare or the financial sector.
Training and awareness-raising
The data protection officer can train employees and raise awareness about data protection issues.
Interface with supervisory authorities
The data protection officer acts as a contact person for data protection supervisory authorities and facilitates communication.
Our packages for your
External Data Protection Officer
In all packages
Multilingual support
Personal contact person
TÜV-certified experts & specialized lawyers
Additional services
Lawyers of Eggert & Partner Lawyers · Service in Germany · All prices are net excluding VAT.
Here's how to start your
Data protection advice with us
We look forward to working with you. Please do not hesitate to contact us.
Step 01
Analysis
We understand the current situation, the risks
and goals – both technically and
organisational.
Step 02
Consulting
Pragmatic roadmap with clear
Priorities instead
over-sized concepts.
Step 03
Implementation
Implementation by our team or in collaboration with your specialist departments.
Step 04
Further development
Long-term support, audits
and continuous improvement.

Your external data protection officer
Non-binding · 15 minutes · Free
Frequently asked questions
When must a company appoint a data protection officer?
A company in Germany must appoint a data protection officer if at least 20 people are permanently employed in the automated processing of personal data (§ 38 GDPR, paragraph 1 BDSG (GERMAN FEDERAL DATA PROTECTION ACT)). Regardless of the number of employees, the obligation exists under Art. 37 if the core activity involves extensive, regular, and systematic monitoring of individuals or special categories of personal data – such as health data – are processed on a large scale. Even if a data protection impact assessment is required or data is processed commercially for transmission, the appointment is also mandatory. Whether the task is internally staffed or assigned to an external data protection officer is a matter of discretion for the company.
What is the difference between an internal and an external data protection officer?
An internal data protection officer is an employee of the company, an external data protection officer is a contracted service provider; the statutory duties under Art. 39 GDPR are identical in both cases. The difference lies in workload, liability, and independence. Internal data protection officers must be professionally trained and regularly retrained; they BDSG (GERMAN FEDERAL DATA PROTECTION ACT) enjoy special protection against termination pursuant to § 38, paragraph 2, in BDSG (GERMAN FEDERAL DATA PROTECTION ACT) conjunction with § 6, paragraph 4; and they are not allowed to hold management positions in IT, personnel, or marketing due to possible conflicts of interest. An external data protection officer brings with them the necessary qualifications, are contractually liable, bear their own professional liability, and assess processing without being bound by internal hierarchies. For small and medium-sized companies without their own data protection resources, the external solution is therefore usually more cost-effective and legally secure.
How much does an external data protection officer cost?
An external data protection officer for sofortdatenschutz.de costs from 120 € net per month in the Light package and from 450 € net per month in the Pro package, depending on company size and scope of services. At the start, a one-time needs analysis is included: 450 € net for Light, 1,500 € net for Pro. For corporate structures or special industry requirements, the mip Consult GmbH individual offers are created. For comparison: An internally appointed data protection officer incurs costs for training, further education, specialist literature, and representation in addition to the proportional personnel costs – costs that are already included in the monthly fixed price of an external service provider.
What specific tasks does an external data protection officer perform?
An external data protection officer assumes all the tasks prescribed by Article 39 GDPR: He advises management and employees on GDPR their data protection obligations, monitors compliance within the BDSG (GERMAN FEDERAL DATA PROTECTION ACT) company, trains employees, accompanies data protection impact assessments, and is the point of contact for the supervisory authority as well as for those affected. At .de sofortdatenschutz, the designation to the supervisory authority is reported, the contact details of the data protection officer are published in the company’s privacy policy, and an interdisciplinary team of TÜV-certified data protection officers, IT experts, and lawyers is available for inquiries. The responsibility for data processing remains with the company; the data protection officer controls and advises, but does not decide on behalf of the management.







