Choose based on who is asking you for guarantees
Both are monthly retainers with no lock-in and a fixed price, agreed in writing before we start, based on your company's size and processing. No lock-in: if we don't add value one month, you leave.
DPO for SMEs
For SMEs that must appoint a DPO, or that want GDPR handled without pulling anyone off the team.
- ✓Appointment and notification of the DPO to the AEPD
- ✓Record of processing activities kept up to date
- ✓Handling data subjects' rights requests
- ✓Point of contact for the AEPD and for anyone who complains
- ✓Data breaches: we lead the response and the 72-hour notification
- ✓Data protection impact assessments (DPIAs) when a processing activity requires one
- ✓Annual review of policies, notices and processor contracts
DPO for SaaS and scale-ups
For software companies and scale-ups whose large customers ask for guarantees before signing.
- ✓Everything in DPO for SMEs
- ✓Your customers' security and privacy questionnaires: we answer them with you, backed by evidence
- ✓DPAs and processing annexes: review and negotiation of the technical side
- ✓Sub-processor register and management (your supplier list, always defensible)
- ✓International transfers: data map, standard contractual clauses and transfer impact assessment
- ✓Trust-centre documentation (policies, controls, standard answers)
- ✓An approach aligned with ISO 27001, so you don't redo the work when the audit comes
Day-to-day GDPR, handled by someone who also understands the technology
We take on the DPO role
We act as your outsourced Data Protection Officer and notify the appointment to the AEPD, as GDPR requires.
Record of processing kept current
We keep the record of processing activities up to date and check that it reflects what your company actually does.
Data subjects' rights
We handle access, erasure and portability requests following the procedure and deadlines the law sets.
Point of contact
We're the contact for the AEPD and for anyone who complains. Your team stops having to answer questions it can't.
Data breaches
If there is an incident, we lead the response and the notification within the 72-hour window, with the technical side covered.
Impact assessments
We carry out DPIAs when a processing activity requires one, so you can launch new projects without legal surprises.
- —Legal defence in enforcement proceedings or litigation (we refer you to a law firm and work alongside it).
- —Making the decisions about your processing: the DPO advises and supervises; your company decides (Art. 38 GDPR).
- —Implementing technical controls in your systems: that is Ongoing support; the DPO defines what is needed and verifies it gets done.
- —ISO 27001 or ENS (Spain's National Security Framework, mandatory for public-sector suppliers) certification audits: we prepare you for them; an accredited third party issues them.
- Deliverable
- Appointment notified to the AEPD, record of processing, quarterly compliance report and, on the SaaS tier, the pack of answers and evidence for questionnaires and DPAs.
- Duration
- Monthly retainer, no lock-in. Onboarding in the first 2–4 weeks (processing inventory, appointment, first plan).
- Independence
- We advise and supervise; the decisions about your processing stay yours. GDPR requires it, and it is how we avoid conflicts of interest.
- Next step
- Tell us what you're being asked for (a customer, a tender, an audit) and within 48 hours we tell you which option fits and what you're missing.
Many companies are required to and don't know it; others do it because their customers ask
Article 34 of Spain's data protection act (LOPDGDD) requires quite a few types of organisation to appoint a Data Protection Officer: professional bodies, schools, financial and insurance entities, healthcare providers, anyone processing at large scale or handling sensitive data, and more. If you're not sure whether you fall under it, that's the first question we answer, free.
And more and more software companies appoint a DPO without being required to, because their customers ask about it in the questionnaire and because having someone who answers with judgement shortens the path to signature. There, the DPO isn't a compliance cost: it's part of the sales process.
Don't let GDPR be what holds up your next contract
Tell us what you're being asked for and what your company looks like. We tell you whether you need a DPO, which option fits and what you're missing to answer with confidence.