Home/Services/Outsourced DPO

The technical DPO: a Data Protection Officer who understands your stack

Most outsourced DPOs (Data Protection Officers) come from law firms and don't know what your tag manager, your CDP or your consent platform actually does with personal data. We come from the other side: fifteen years inside the marketing and SaaS data stack. We cover your GDPR obligation, we're the face in front of the AEPD (Spain's data protection authority) and, above all, we make compliance work for your sales: pass your customer's questionnaire, sign the DPA, close the deal. What exactly is a technical DPO? →

Two options

Choose based on who is asking you for guarantees

Both are monthly retainers with no lock-in and a fixed price, agreed in writing before we start, based on your company's size and processing. No lock-in: if we don't add value one month, you leave.

DPO for SMEs

For SMEs that must appoint a DPO, or that want GDPR handled without pulling anyone off the team.

  • Appointment and notification of the DPO to the AEPD
  • Record of processing activities kept up to date
  • Handling data subjects' rights requests
  • Point of contact for the AEPD and for anyone who complains
  • Data breaches: we lead the response and the 72-hour notification
  • Data protection impact assessments (DPIAs) when a processing activity requires one
  • Annual review of policies, notices and processor contracts
Request a quote

DPO for SaaS and scale-ups

For software companies and scale-ups whose large customers ask for guarantees before signing.

  • Everything in DPO for SMEs
  • Your customers' security and privacy questionnaires: we answer them with you, backed by evidence
  • DPAs and processing annexes: review and negotiation of the technical side
  • Sub-processor register and management (your supplier list, always defensible)
  • International transfers: data map, standard contractual clauses and transfer impact assessment
  • Trust-centre documentation (policies, controls, standard answers)
  • An approach aligned with ISO 27001, so you don't redo the work when the audit comes
Request a quote
What your DPO does

Day-to-day GDPR, handled by someone who also understands the technology

We take on the DPO role

We act as your outsourced Data Protection Officer and notify the appointment to the AEPD, as GDPR requires.

Record of processing kept current

We keep the record of processing activities up to date and check that it reflects what your company actually does.

Data subjects' rights

We handle access, erasure and portability requests following the procedure and deadlines the law sets.

Point of contact

We're the contact for the AEPD and for anyone who complains. Your team stops having to answer questions it can't.

Data breaches

If there is an incident, we lead the response and the notification within the 72-hour window, with the technical side covered.

Impact assessments

We carry out DPIAs when a processing activity requires one, so you can launch new projects without legal surprises.

What's not included
  • Legal defence in enforcement proceedings or litigation (we refer you to a law firm and work alongside it).
  • Making the decisions about your processing: the DPO advises and supervises; your company decides (Art. 38 GDPR).
  • Implementing technical controls in your systems: that is Ongoing support; the DPO defines what is needed and verifies it gets done.
  • ISO 27001 or ENS (Spain's National Security Framework, mandatory for public-sector suppliers) certification audits: we prepare you for them; an accredited third party issues them.
How it works
Deliverable
Appointment notified to the AEPD, record of processing, quarterly compliance report and, on the SaaS tier, the pack of answers and evidence for questionnaires and DPAs.
Duration
Monthly retainer, no lock-in. Onboarding in the first 2–4 weeks (processing inventory, appointment, first plan).
Independence
We advise and supervise; the decisions about your processing stay yours. GDPR requires it, and it is how we avoid conflicts of interest.
Next step
Tell us what you're being asked for (a customer, a tender, an audit) and within 48 hours we tell you which option fits and what you're missing.
Do you have to appoint a DPO?

Many companies are required to and don't know it; others do it because their customers ask

Article 34 of Spain's data protection act (LOPDGDD) requires quite a few types of organisation to appoint a Data Protection Officer: professional bodies, schools, financial and insurance entities, healthcare providers, anyone processing at large scale or handling sensitive data, and more. If you're not sure whether you fall under it, that's the first question we answer, free.

And more and more software companies appoint a DPO without being required to, because their customers ask about it in the questionnaire and because having someone who answers with judgement shortens the path to signature. There, the DPO isn't a compliance cost: it's part of the sales process.

Don't let GDPR be what holds up your next contract

Tell us what you're being asked for and what your company looks like. We tell you whether you need a DPO, which option fits and what you're missing to answer with confidence.