Business obligations, registers and licences · Czechia and Slovakia
Outsourced data protection officer (DPO)
If your activities require a data protection officer under GDPR, you do not need to employ one. An external specialist can perform the role. First, we properly assess whether you need one at all. If you do, we take on the role: monitoring processing, advising on new projects, acting as a contact for data subjects and the authority, and handling breach notifications. A lawyer doing the work, rather than a name entered on a form.
- Assessment of the requirement first
- A lawyer familiar with Slovak and Czech practice
- A monthly retainer agreed upfront
What we'll do for you
An ongoing service. Following the assessment and appointment, the role is performed under a monthly retainer, with the scope agreed according to the volume of processing.
Select an item to see the details.
-
Assessing the requirement
A written, reasoned assessment of whether your activities require a DPO under GDPR, suitable for use in a future inspection.
-
Taking on the role
Appointment, notification of contact details to the authority, publication of contact details for data subjects and an initial review of the processing activities.
-
Ongoing oversight
Monitoring compliance, advising on new projects and contracts, providing opinions on impact assessments and reporting regularly to management.
-
Data subjects and the authority
We act as the contact point, handling responses to data subject requests and communications with the data protection authority.
-
Incidents
In the event of a personal data breach, we lead the assessment, any notification to the authority within the statutory time limit and communications with affected individuals.
Deliverablean appointed data protection officer performing the role on an ongoing basis — oversight, advice, notifications and contact with the authority
How it works
Does this process fit your matter? Describe it to the attorney →
- Assessmentday 0
We establish whether you need a DPO and propose the scope of the role.
- Appointment
Appointment, notifications and an initial processing audit.
- Ongoing performanceongoing
Oversight, advice, requests and notifications — the role is performed while you run your business.
A data protection officer is a role, not an entry on a form. The authority and data subjects expect someone who answers the phone, understands the company’s processing and can give informed answers — and, in an incident, ensures notification within the statutory time limit.
Having an external lawyer perform the role combines expertise with independence: oversight by someone outside your internal relationships, bound by professional confidentiality and equipped with legal support for difficult situations.
No-obligation enquiry
Ready to start?
Send us an enquiry. We reply within 24 hours with a price confirmation and next steps. The first 30-minute consultation is free and commits you to nothing.
- 1Send your enquiry via this form
- 2Within 24 h you get a price confirmation and plan
- 3We start work only after your approval
Not keen on calls or email? Message us on WhatsApp →
Prefer to book a time right away? Book a consultation →
Or email us about this matter.
What clients ask
Didn’t find your question? Ask us directly →
When must I appoint a data protection officer?
GDPR requires a DPO particularly for public authorities, large-scale regular and systematic monitoring of individuals, and large-scale processing of special categories of data, such as health data. Most ordinary businesses are not required to appoint one, but the boundaries of 'large-scale' processing are not precise and depend on the specific activity. That is exactly what our written assessment addresses.
Can an external provider act as DPO?
Yes. GDPR expressly permits a DPO to perform the role under a service contract. What matters is expertise, sufficient resources, independence and actual accessibility to data subjects and the authority. Outsourcing is especially useful for companies that cannot justify a dedicated employee for the role.
Why can our IT manager or managing director not be the DPO?
A DPO must not have a conflict of interest and cannot oversee processing decisions they make themselves. A managing director, head of IT or head of HR is therefore generally unsuitable. An external appointment addresses the conflict by placing oversight with someone who does not decide the processes being monitored.
What exactly will you do as our DPO?
Continuously monitor processing compliance with GDPR, advise on new projects and contracts, provide opinions on impact assessments, receive data subject requests, communicate with the authority and lead the incident response process. We tailor the scope and frequency to the volume of your processing and agree them in advance within the retainer.
Do you then become liable for fines instead of us?
No. Responsibility for compliance always remains with the controller — you. A DPO provides oversight and advice, not insurance. It is therefore important that the role is performed by someone who identifies problems promptly and in writing. Our opinions also provide evidence that you acted with professional care.
Legal Q&A
Common questions on this topic
-
What must we do to make shop and workplace CCTV lawful?
CCTV is lawful when its legal basis is documented in advance, generally legitimate interests under Article 6(1)(f) GDPR, and everyone entering the monitored area receives the required information. A balancing test comparing your interests with the privacy intrusion must exist before cameras start operating. At work, Section 13(4) of the Labour Code additionally requires prior consultation with employee representatives on the monitoring mechanism and notification to employees.
Read the answer -
How does the authority calculate a fine for a GDPR breach?
The EDPB methodology in Guidelines 04/2022 uses five steps: identify the processing operations, set a starting amount based on the infringement category, severity and the undertaking's turnover, adjust for aggravating and mitigating factors, check the statutory ceiling, and assess effectiveness and proportionality. Ceilings are EUR 10 or 20 million, or 2% or 4% of worldwide turnover for undertakings. Turnover means the whole group, rather than only the company at fault. Arguments can address severity, remediation and enhanced cooperation; mandatory notification itself is neutral. Inability to pay is considered only exceptionally.
Read the answer -
Who is a beneficial owner, and how are they identified?
A beneficial owner is always an individual, never a company. In a company, this particularly includes anyone with a direct or indirect interest of at least 25% in voting rights or registered capital, the right to appoint or remove statutory or supervisory bodies, control by other means, or entitlement to at least 25% of the economic benefit. If no such individual can be identified, senior management, meaning the statutory body, is treated as the beneficial owner.
Read the answer
Further reading
AML amendment: goAML registration by 30 November 2026 and stricter beneficial owner verification
AML amendment Act No. 73/2026 Z. z. has applied since 1 June 2026. Obliged entities must register in the Financial Intelligence Unit’s goAML system by 30 November 2026 and must not rely solely on the register of legal entities when verifying beneficial owners.
Read more →
Conflicts of interest in public procurement: when bidders risk exclusion
A former employee on the contracting authority’s side, a designer included in the bid or personal links to the committee: Public Procurement Office guidance No. 3/2026 explains which connections create conflicts and when exclusion follows. Potential influence, disclosure and mitigation are decisive.
Read more →
MiCA CASP authorisation: preparing your application to NBS
Crypto-asset services in the EU require CASP authorisation, and Slovakia’s transitional period for former crypto trade licences ended on 30 December 2025. Delegated Regulation (EU) 2025/305 defines the NBS application requirements, and subsequent changes restart assessment.
Read more →