Required by regulation
Data protection (GDPR)
The data protection officer role as a standing external service — records of processing, impact assessments, breach handling and training, run to one method in every country your group operates in.
We take on the data protection officer role as a standing service, not as a one-off documentation review. It applies to organisations that must appoint a DPO and to those that appointed one voluntarily — a voluntary appointment is bound by the same independence rules as a mandatory one.
We also take on single situations without the standing role: a request or a complaint arrives and there is neither the capacity nor the distance to handle it internally.
What you get
A named contact point for data subjects and for the supervisory authority — written into your documentation and reachable when someone gets in touch.
Data subject requests handled within the statutory period, including the assessment of whether and how far each request is granted.
A record of processing activities that matches the systems you actually run, not the ones you ran when it was first written.
A data protection impact assessment where one is needed, with the material management needs in order to decide.
A documented position on a complaint or an inspection, built on what actually happened.
A written report for management: what was resolved, what remains open, and what we recommend for the next period.
The data protection officer as an external role
The obligations the regulation places on the role belong to the person, not to the contract: independence, no conflict of interest, reporting to the highest level of management, and no instructions on how the task is carried out.
An external officer meets them more easily than an internal one who also runs the systems being assessed. It is worth saying plainly: the role is easier to keep independent when it is not also responsible for what it reviews.
Records of processing activities
Article 30 asks for a record that describes reality. Most records we are handed describe the intention at the time of the rollout — a CRM that has since been replaced, a payroll provider that has since changed, a cloud region that has since moved.
We walk the systems with the people who run them, write the record against what we find, and list the gaps between what is processed and what is documented, in the order in which they matter.
Data protection impact assessment
Not every processing operation needs one. Where it does, the assessment has to reach a conclusion that management can sign: what the risk is, what reduces it, and what remains after that.
We prepare it as a decision document, not as a form to be filed.
When a personal data breach happens
Article 33 allows at most 72 hours from becoming aware of a breach to notify the supervisory authority. The clock starts at awareness, not at the end of the investigation — so the first hours decide whether the notification describes something or guesses at it.
We establish what happened, assess whether the breach has to be notified at all, and prepare the notification and the internal record. Where the risk to the people affected is high, we prepare the communication to them as well.
Training of authorised persons
The controller has to make sure that everyone who processes personal data under its authority does so on its instructions — and be able to show that they were instructed. The second half is the harder one: an attendance sheet from a meeting does not carry the same weight as a record tied to a named person.
What you get: an e-learning course for authorised persons that ends in a final test, and a completion record for each person.
How it runs: the course is available continuously, not in scheduled sessions. A new employee is trained when they join, not when the next group fills up. Starting the course and seeing who has completed it stays in the hands of a manager in your organisation.
Representation before the supervisory authority
On the basis of a power of attorney we represent the client in communication with the supervisory authority and in handling complaints from data subjects. The scope of the representation is agreed case by case. This is not legal advice and it is not representation by an attorney.
For groups operating in several countries
One regulation, one documentation structure. Article 37(2) allows a group of undertakings to appoint a single data protection officer, provided that the officer is easily accessible from each establishment — so this is not a workaround, it is an arrangement the regulation provides for.
In practice it means records, impact assessments and processor contracts built on one template across countries; documentation in the local language and under the local implementing law, because the regulation is shared and the implementing acts are not; and one report for the management of the group instead of one per country.
The IOSEC group has operated since 2010 and works in 8 European countries, with 17 260 clients across the group. Where the group has no presence of its own, the work is delivered through a partner under the same method.
Where our work ends
We provide professional advice and the data protection officer role. This is not legal advice and not representation by an attorney.
Where we designed and implemented a system, the same client does not receive the audit of that system from us.
Certification against ISO/IEC 27001 is issued by an accredited certification body, never by an adviser.
Legal position verified as of 19 September 2026.
How we help
Packages, scope and indicative price
Most providers do not publish prices. We at least state a range — so that you know whether we are talking about the same budget at all.
Data protection officer as a standing service
A contact point for data subjects and for the supervisory authority, continuous monitoring of compliance, documentation kept up to date, and a written report for management.
Indicatively from 200 € per month, excluding VAT. The final price depends on the scope and we agree it in advance.One situation taken over
A single data subject request or a complaint handled end to end, including establishing what happened and preparing the position.
Price by agreement. It depends on what the request or complaint concerns and how many systems and records have to be gone through. We agree the scope and the price before we start.Data protection officer for a group
One role across the establishments of the group, a shared procedure and documentation aligned with the national rules of each country.
Price by agreement. It depends on the number of establishments, the number of countries and the scope of the shared documentation. We agree the scope and the price in advance.Initial data protection audit
A record of processing activities that matches reality, a list of the gaps between what is processed and what is documented, and a plan to close them in order of risk.
Indicatively from 1 200 € one-off, excluding VAT. The final price depends on the size of the organisation, the number of sites and on what you already have in place. We give an exact quotation after an initial assessment.Tell us what you are dealing with
Thirty minutes with a consultant who knows your sector. The outcome is a one-page summary with a recommended next step and an indicative scope — we send it to you even if we do not end up working together.