GDPR Article 37 / Named, notified, independent

External Data Protection Officer (DPO) Service

A named DPO appointed under Article 37(6), notified to your supervisory authority, and kept independent of your IT and security function, which is the part most providers get wrong.

Appointed in two weeks. From $1,200 per month, fixed.

On record with the regulatorNever doubles as your security leadQuarterly exit
External Data Protection Officer service under GDPR Article 37 by Atlant Security

Why Companies Appoint an External DPO

A customer, tender or regulator asked who your DPO is

GDPR Article 37 makes the appointment mandatory for public bodies and for any organisation whose core activities involve large-scale monitoring or large-scale special-category data. Several member states lower the threshold further. If you cannot name a person, the conversation stalls there.

The person you named is also running IT or security

Article 38(6) requires the DPO not to determine the purposes and means of processing. Supervisory authorities have fined companies precisely because the DPO sat inside IT security. An appointment that fails the independence test is not an appointment.

A full-time DPO is a salary for a part-time need

A qualified in-house DPO costs EUR 80,000 to 150,000 a year for a function most mid-size companies need a few days a month. An external DPO under Article 37(6) is explicitly permitted, and the appointment is notified to the supervisory authority in exactly the same way.

When appointing a Data Protection Officer is mandatory under GDPR Article 37 and national law
GDPR Article 37 makes the DPO appointment mandatory for many organisations

What the DPO Actually Does

Articles 38 and 39 define the position and the tasks. The DPO informs and advises, monitors compliance, consults on impact assessments, cooperates with the supervisory authority and acts as its contact point, and reports directly to the highest level of management. The tasks are the deliverables of the seat, not a quantity of consulting hours.

Advise and monitor
Inform the organisation of its GDPR obligations and monitor compliance against them
DPIAs
Consult on and document Data Protection Impact Assessments for high-risk processing
Data subject requests
Handle access, erasure and objection requests within statutory deadlines
Supervisory authority
Act as the named contact point for the regulator and cooperate with it
Records of processing
Keep the Article 30 register current as systems and vendors change
Breach coordination
Assess incidents and drive the 72-hour notification decision
The tasks of an external DPO under GDPR Articles 38 and 39
The 72-hour GDPR breach notification window coordinated by the DPO
GDPR Article 38(6) conflict rule: the DPO must not also run IT or security

The Conflict Rule Most Providers Ignore

Article 38(6) allows the DPO to have other tasks, provided they do not result in a conflict of interests. Deciding how personal data is processed is such a conflict, and IT and security leadership decide exactly that. A Polish supervisory authority fined a bank because its DPO sat inside the IT security team.

This is why we treat the DPO seat and any security seat as mutually exclusive for the same client, and put that rule in the appointment letter. If you already use us for a security audit or a virtual CISO, we will tell you plainly that the DPO has to be someone else, and help you structure it.

An appointment that would not survive a regulator asking one question is worse than no appointment, because it signals you knew the rule.

Who Needs a DPO?

SaaS and technology companies processing customer personal data at scale
Fintech, payments and lending firms with regular, systematic monitoring
Healthtech and any business handling health, biometric or other special-category data
HR-tech, recruitment and marketing platforms profiling individuals

Compared With the Usual Arrangement

Atlant SecurityTypical arrangement
IndependenceWe hold the DPO seat only, never a security or IT seat for the same clientThe IT manager or an MSP consultant wearing a second hat
On recordNamed, notified to the supervisory authority, published on your privacy pageA privacy@ mailbox and nobody accountable
Technical depthA security practitioner who can read the architecture behind the DPIAA legal generalist who cannot assess the technical controls
PricingPublished fixed monthly fee, 12-month term, quarterly exitHourly billing or an unstated retainer

How the Appointment Works

1

Designation check and scoping

We confirm whether Article 37 or national law makes the appointment mandatory for you, map your processing, and agree the scope and monthly hours in writing.

2

Appointment pack

Appointment letter, independence and conflict statement, reporting line to top management, and the published contact details GDPR requires.

3

Notification

We notify the supervisory authority, the Commission for Personal Data Protection in Bulgaria or your national authority elsewhere, so the appointment is on record.

4

Monthly operation

DPIAs, data subject requests, register upkeep, vendor reviews, staff questions and a quarterly report to management. Breach support is on the same line.

How the external DPO appointment works in four steps
What you receive every month from the external DPO service

Pricing

Only one in nineteen external DPO providers publishes a price. We do. Fixed monthly fee, 12-month term, quarterly exit, hour band and overage rate written into the contract.

Most common

Standard DPO Seat

One legal entity, routine processing, up to roughly 500 staff.

$1,200per month
  • Named DPO, notified to the supervisory authority
  • Data subject request handling
  • DPIA consultation and sign-off
  • Article 30 records kept current
  • Breach assessment and 72-hour support
  • Quarterly management report
Book Free Designation Check

Extended DPO Seat

Groups, multi-entity structures, high request volumes or special-category data at scale.

$2,900per month
  • Everything in the Standard seat
  • Multiple entities and supervisory authorities
  • Vendor and international transfer reviews
  • Privacy programme roadmap and training
  • Monthly management reporting
  • Priority response on incidents
Book Free Designation Check

Put a Real Name on the Appointment

A free designation check tells you whether the appointment is mandatory for you and what it would take. Two weeks later the DPO is on record.

Book the Designation Check

Schedule Your Free Designation Check

External DPO FAQ

When is appointing a DPO mandatory?
Under GDPR Article 37 the appointment is mandatory for public authorities and bodies, for organisations whose core activities consist of regular and systematic monitoring of data subjects on a large scale, and for those whose core activities consist of large-scale processing of special-category or criminal-conviction data. National law can go further: Germany, for example, requires one where at least 20 people are regularly involved in automated processing. Where it is not mandatory, many companies still appoint one voluntarily because customers and tenders ask.
Can the DPO be external?
Yes. Article 37(6) states the DPO may fulfil the tasks on the basis of a service contract. The appointment is notified to the supervisory authority in the same way as an internal one, and the same independence, resourcing and reporting-line requirements apply.
Why can the DPO not also be our security lead?
Article 38(6) requires that any other tasks and duties do not result in a conflict of interests. A person who decides how personal data is processed, which is what IT and security leadership does, cannot independently monitor that processing. Supervisory authorities have issued fines on exactly this point. That is why we never hold a DPO seat and a security seat for the same client, and we say so in the appointment letter.
What does the DPO do month to month?
Monitors compliance and advises the business, consults on and documents DPIAs, handles data subject requests within the one-month deadline, keeps the Article 30 records of processing current, reviews new vendors and transfers, answers staff questions, acts as the contact point for the supervisory authority, and reports to management quarterly. When an incident happens, the DPO assesses it and drives the 72-hour notification decision.
How much does it cost?
The Standard seat is $1,200 per month for a single legal entity with routine processing. The Extended seat is $2,900 per month for groups, multi-entity structures, high request volumes or special-category data at scale. Both are fixed monthly fees on a 12-month term with quarterly exit, and the hour band and overage rate are stated in the contract.
Which supervisory authority is notified?
The authority of the member state where your main establishment is. For Bulgarian entities that is the Commission for Personal Data Protection. For companies established elsewhere in the EU or the UK we notify the relevant national authority, and for non-EU companies with an EU representative we align the appointment with that arrangement.
Do you also handle security work for DPO clients?
No, by design. If you need a security audit or a virtual CISO as well, we will be transparent that one person cannot hold both seats for you and will structure the engagement so the DPO stays independent, or recommend a second provider for one of the two.
How quickly can the appointment be in place?
Typically two weeks from the scoping call: the designation check and appointment pack take the first week, notification and onboarding the second.

Related Services