Privacy

External DPO & Privacy Advisory

External data protection function and ongoing advisory for organizations that need to manage GDPR in a structured way.

Framework: GDPR · LOPDGDD Modality: Recurring service Focus: Oversight · Risk · Evidence · Advisory
Request an assessment meeting →

Data protection as an ongoing function

GDPR compliance does not end once policies are written. Processing activities, providers, technologies, contracts, campaigns, AI systems and internal processes keep changing.

That's why many organizations need a privacy function available on an ongoing basis, without necessarily hiring a full-time specialist.

How we work

01 — Onboarding

We review processing activities, documentation, risks and current status.

02 — Privacy Governance

We define responsibilities, processes, records and control mechanisms.

03 — Advisory

We provide ongoing advice on new projects, providers, processing activities or decisions.

04 — Monitoring

We monitor compliance, maintain evidence and periodically review the privacy program.

What does it include?

Depending on the contracted scope:

  • GDPR and LOPDGDD advisory.
  • Record of processing activities.
  • Review of legal bases.
  • Privacy by Design.
  • Impact assessments when applicable.
  • Rights management.
  • Incident and breach management.
  • Review of processors and contracts.
  • International transfers.
  • Training.
  • Periodic program review.
  • Support during regulatory requests.
  • DPO functions when the contracted service and the organization require it.

For which organizations?

  • Companies required to appoint a DPO.
  • Organizations with complex processing activities.
  • SaaS and technology companies.
  • Health, education and professional services.
  • Companies using AI on personal data.
  • Organizations that need specialized support without hiring a full-time internal profile.

Deliverables

  • Record of Processing Activities.
  • Legal basis analysis.
  • Impact assessments, when applicable.
  • Rights management procedure.
  • Incident and breach management procedure.
  • Periodic compliance report.

What happens next

Onboarding
Monthly retainer

Ongoing advisory and periodic review of the privacy program.

Do you need an external privacy function?

Let's define the right scope for your organization.

Request an assessment meeting →

Initial 20–30 minute meeting · No commitment