Services

Compliance you can demonstrate.

External DPO services under a service contract, GDPR audits, impact assessments, breach response and training — for organisations of any size.

A compliance checklist and shield, drawn in pencil

Mission & values

What an external DPO actually does.

Mission

Identify, analyse, advise

I objectively collect information to identify processing activities, analyse and check their compliance with the GDPR, and inform, advise and issue recommendations to the controller or the processor.

Values

Expert and independent

I take particular care to provide expert and independent advice; my approach is pragmatic and involves IT security experts when needed.

Solution

A service contract

An external DPO is appointed on the basis of a service contract — the expertise and independence the GDPR requires, without adding the role to your payroll.

Scope of work

From the first register to the 3 a.m. breach.

Records of processing activities

Building and maintaining the Article 30 register, including processor mapping and data flows.

Documentation

Privacy policies & data management plans

Notices, internal policies, retention schedules and consent forms that match what you really do.

Documentation

Data protection impact assessments

Structured DPIAs for high-risk processing, with documented and proportionate mitigations.

Assessment

Security policies & digital diligence

Article 32 measures, NIS obligations and the security standard expected of your sector.

Security

Data processing & joint-controller agreements

Drafting and reviewing Article 26 and 28 contracts, and the clauses behind them.

Contracts

International data transfers

Transfer mechanisms, standard contractual clauses and transfer impact assessments.

Contracts

Data subject requests

Procedures and case-by-case handling of access, erasure, objection and portability requests.

Operations

Breach notification & incident response

72-hour assessments, notifications and the follow-up correspondence with the authority.

Operations

Cooperation with data protection authorities

Acting as your contact point, and preparing your position when a file is opened.

Representation

Cookies & online advertising

Banner and tracker review, legal bases and the ePrivacy layer on top of the GDPR.

Digital

Staff training & awareness

Tailored sessions, from board-level briefings to hands-on workshops for operational teams.

Training

Why work together

Save yourself time, effort and resources.

Cybersecurity-Law has built lasting partnerships with recognised organisations and companies in the data protection sector.

Get in touch — the first conversation costs nothing but a few minutes.

Send an e-mail Curriculum vitae