GDPR Article 37 / Named, notified, independent

A Named DPO on Record With Your Regulator in Two Weeks.

A named DPO appointed under Article 37(6), notified to your supervisory authority, and kept independent of your IT and security function, which is the part most providers get wrong.

Appointed in two weeks. From EUR 1,100 per month, fixed.

On record with the regulatorNever doubles as your security leadQuarterly exit
External Data Protection Officer service under GDPR Article 37 by Atlant Security
Alexander Sverdlov, founder of Atlant Security
Alexander SverdlovFounder, Atlant SecurityCISSP, CEH, CHFI, Mandiant

Acts as your external DPO and signs off on the decisions that carry real liability.

Connect on LinkedIn

Why Companies Appoint an External DPO

A customer, tender or regulator asked who your DPO is

GDPR Article 37 makes the appointment mandatory for public bodies and for any organisation whose core activities involve large-scale monitoring or large-scale special-category data. Several member states lower the threshold further. If you cannot name a person, the conversation stalls there.

The person you named is also running IT or security

Article 38(6) requires the DPO not to determine the purposes and means of processing. Supervisory authorities have fined companies precisely because the DPO sat inside IT security. An appointment that fails the independence test is not an appointment.

A full-time DPO is a salary for a part-time need

A qualified in-house DPO costs EUR 80,000 to 150,000 a year for a function most mid-size companies need a few days a month. An external DPO under Article 37(6) is explicitly permitted, and the appointment is notified to the supervisory authority in exactly the same way.

When a DPO appointment is mandatoryGDPR Article 37(1), plus stricter national thresholdsPublic authoritiesEvery public body and authority, without exceptionLarge-scale monitoringRegular, systematic monitoring of people as a core activitySpecial-category dataHealth, biometric, criminal-conviction data at scaleNational lawGermany: 20+ staff in automated processing. Others vary.
Where none of these apply, many companies still appoint one because customers and tenders ask for a name.
Internal DPO or external appointmentIN-HOUSE DPOEXTERNAL DPO, ARTICLE 37(6)Legal basisEmployment contractService contract, expressly permittedNotificationFiled with the supervisory authorityFiled identicallyCostEUR 80,000 to 150,000 a yearFixed monthly feeIndependenceReports to management, employed by itNo other role inside the organisation
Article 37(6) puts the two on the same legal footing. Only the cost and the independence differ.

What the DPO Actually Does

Articles 38 and 39 define the position and the tasks. The DPO informs and advises, monitors compliance, consults on impact assessments, cooperates with the supervisory authority and acts as its contact point, and reports directly to the highest level of management. The tasks are the deliverables of the seat, not a quantity of consulting hours.

Advise and monitor
Inform the organisation of its GDPR obligations and monitor compliance against them
DPIAs
Consult on and document Data Protection Impact Assessments for high-risk processing
Data subject requests
Handle access, erasure and objection requests within statutory deadlines
Supervisory authority
Act as the named contact point for the regulator and cooperate with it
Records of processing
Keep the Article 30 register current as systems and vendors change
Breach coordination
Assess incidents and drive the 72-hour notification decision
What the DPO does, month to monthGDPR Articles 38 and 39Advise and monitorInform the business, monitor complianceagainst the regulationDPIAsConsult on and document impact assessmentsfor high-risk processingData subject requestsAccess, erasure and objection inside thestatutory monthArticle 30 registerKept current as systems and vendors changeAuthority contactNamed point of contact, cooperates with theregulatorBreach decisionsAssess incidents, drive the 72-hournotification call
The tasks are the deliverable of the seat, not a quantity of consulting hours.
The 72-hour breach clockHour 0AwarenessThe organisation becomesaware of a breachHours 0-24AssessmentScope, data categories,risk to individualsHour 72Notify the authorityArticle 33, or record whynotWithout delayNotify individualsArticle 34, where risk ishigh
The DPO drives the notification decision and documents the reasoning either way.
Article 38(6): the conflict ruleCompatible with the DPO seatAdvising on privacy programme designReviewing vendors and international transfersTraining staff and answering questionsReporting to the highest management levelA disqualifying conflictHead of IT or security for the same clientAnyone deciding purposes and means of processingThe person who built the controls being monitoredA role that reports into the function being audited
Supervisory authorities have fined companies for placing the DPO inside IT security. We hold the DPO seat or a security seat for a client, never both.

The Conflict Rule Most Providers Ignore

Article 38(6) allows the DPO to have other tasks, provided they do not result in a conflict of interests. Deciding how personal data is processed is such a conflict, and IT and security leadership decide exactly that. A Polish supervisory authority fined a bank because its DPO sat inside the IT security team.

This is why we treat the DPO seat and any security seat as mutually exclusive for the same client, and put that rule in the appointment letter. If you already use us for a security audit or a virtual CISO, we will tell you plainly that the DPO has to be someone else, and help you structure it.

An appointment that would not survive a regulator asking one question is worse than no appointment, because it signals you knew the rule.

Who Needs a DPO?

SaaS and technology companies processing customer personal data at scale
Fintech, payments and lending firms with regular, systematic monitoring
Healthtech and any business handling health, biometric or other special-category data
HR-tech, recruitment and marketing platforms profiling individuals

Compared With the Usual Arrangement

Atlant SecurityTypical arrangement
IndependenceWe hold the DPO seat only, never a security or IT seat for the same clientThe IT manager or an MSP consultant wearing a second hat
On recordNamed, notified to the supervisory authority, published on your privacy pageA privacy@ mailbox and nobody accountable
Technical depthA security practitioner who can read the architecture behind the DPIAA legal generalist who cannot assess the technical controls
PricingPublished fixed monthly fee, 12-month term, quarterly exitHourly billing or an unstated retainer

How the Appointment Works

1

Designation check and scoping

We confirm whether Article 37 or national law makes the appointment mandatory for you, map your processing, and agree the scope and monthly hours in writing.

2

Appointment pack

Appointment letter, independence and conflict statement, reporting line to top management, and the published contact details GDPR requires.

3

Notification

We notify the supervisory authority, the Commission for Personal Data Protection in Bulgaria or your national authority elsewhere, so the appointment is on record.

4

Monthly operation

DPIAs, data subject requests, register upkeep, vendor reviews, staff questions and a quarterly report to management. Breach support is on the same line.

From designation check to a DPO on record1Designation checkWhether Article 37 or nationallaw binds you; scope and hoursagreed in writing2Appointment packLetter, independencestatement, reporting line,published contact details3NotificationFiled with your supervisoryauthority so the appointmentis on record4Monthly operationDPIAs, requests, register,vendor reviews, quarterlymanagement report
Typically two weeks from the first call to a DPO on record with the regulator.
What you receive every monthNamed appointmentOn record with the authority and publishedon your privacy pageRequest handlingEvery data subject request logged andanswered in timeDPIA sign-offDocumented consultation for high-riskprocessingLive Article 30 registerUpdated as systems and processors changeVendor reviewsNew processors and transfers assessed beforego-liveQuarterly reportWritten to the highest level of management
Fixed monthly fee, 12-month term, quarterly exit, with the hour band written into the contract.

Pricing

Only one in nineteen external DPO providers publishes a price. We do. Fixed monthly fee, 12-month term, quarterly exit, hour band and overage rate written into the contract.

Most common

Standard DPO Seat

One legal entity, routine processing, up to roughly 500 staff.

From EUR 1,100per month
  • Named DPO, notified to the supervisory authority
  • Data subject request handling
  • DPIA consultation and sign-off
  • Article 30 records kept current
  • Breach assessment and 72-hour support
  • Quarterly management report
Get Your Designation Check

Extended DPO Seat

Groups, multi-entity structures, high request volumes or special-category data at scale.

From EUR 2,700per month
  • Everything in the Standard seat
  • Multiple entities and supervisory authorities
  • Vendor and international transfer reviews
  • Privacy programme roadmap and training
  • Monthly management reporting
  • Priority response on incidents
Get Your Designation Check

Put a Real Name on the Appointment

A free designation check tells you whether the appointment is mandatory for you and what it would take. Two weeks later the DPO is on record.

Book the Designation Check

Get Your Designation Check

External DPO FAQ

When is appointing a DPO mandatory?
Under GDPR Article 37 the appointment is mandatory for public authorities and bodies, for organisations whose core activities consist of regular and systematic monitoring of data subjects on a large scale, and for those whose core activities consist of large-scale processing of special-category or criminal-conviction data. National law can go further: Germany, for example, requires one where at least 20 people are regularly involved in automated processing. Where it is not mandatory, many companies still appoint one voluntarily because customers and tenders ask.
Can the DPO be external?
Yes. Article 37(6) states the DPO may fulfil the tasks on the basis of a service contract. The appointment is notified to the supervisory authority in the same way as an internal one, and the same independence, resourcing and reporting-line requirements apply.
Why can the DPO not also be our security lead?
Article 38(6) requires that any other tasks and duties do not result in a conflict of interests. A person who decides how personal data is processed, which is what IT and security leadership does, cannot independently monitor that processing. Supervisory authorities have issued fines on exactly this point. That is why we never hold a DPO seat and a security seat for the same client, and we say so in the appointment letter.
What does the DPO do month to month?
Monitors compliance and advises the business, consults on and documents DPIAs, handles data subject requests within the one-month deadline, keeps the Article 30 records of processing current, reviews new vendors and transfers, answers staff questions, acts as the contact point for the supervisory authority, and reports to management quarterly. When an incident happens, the DPO assesses it and drives the 72-hour notification decision.
How much does it cost?
The Standard seat is from EUR 1,100 per month for a single legal entity with routine processing. The Extended seat is from EUR 2,700 per month for groups, multi-entity structures, high request volumes or special-category data at scale. Both are fixed monthly fees on a 12-month term with quarterly exit, and the hour band and overage rate are stated in the contract.
Which supervisory authority is notified?
The authority of the member state where your main establishment is. For Bulgarian entities that is the Commission for Personal Data Protection. For companies established elsewhere in the EU or the UK we notify the relevant national authority, and for non-EU companies with an EU representative we align the appointment with that arrangement.
Do you also handle security work for DPO clients?
No, by design. If you need a security audit or a virtual CISO as well, we will be transparent that one person cannot hold both seats for you and will structure the engagement so the DPO stays independent, or recommend a second provider for one of the two.
How quickly can the appointment be in place?
Typically two weeks from the scoping call: the designation check and appointment pack take the first week, notification and onboarding the second.

Related Services