Business obligations, registers and licences · Czechia and Slovakia

Outsourced data protection officer (DPO)

If your activities require a data protection officer under GDPR, you do not need to employ one. An external specialist can perform the role. First, we properly assess whether you need one at all. If you do, we take on the role: monitoring processing, advising on new projects, acting as a contact for data subjects and the authority, and handling breach notifications. A lawyer doing the work, rather than a name entered on a form.

  • Assessment of the requirement first
  • A lawyer familiar with Slovak and Czech practice
  • A monthly retainer agreed upfront
5.0 of 70 reviews on Google

What we'll do for you

An ongoing service. Following the assessment and appointment, the role is performed under a monthly retainer, with the scope agreed according to the volume of processing.

Select an item to see the details.

  • Assessing the requirement

    A written, reasoned assessment of whether your activities require a DPO under GDPR, suitable for use in a future inspection.

  • Taking on the role

    Appointment, notification of contact details to the authority, publication of contact details for data subjects and an initial review of the processing activities.

  • Ongoing oversight

    Monitoring compliance, advising on new projects and contracts, providing opinions on impact assessments and reporting regularly to management.

  • Data subjects and the authority

    We act as the contact point, handling responses to data subject requests and communications with the data protection authority.

  • Incidents

    In the event of a personal data breach, we lead the assessment, any notification to the authority within the statutory time limit and communications with affected individuals.

Deliverablean appointed data protection officer performing the role on an ongoing basis — oversight, advice, notifications and contact with the authority

How it works

Does this process fit your matter? Describe it to the attorney →

  1. Assessmentday 0

    We establish whether you need a DPO and propose the scope of the role.

  2. Appointment

    Appointment, notifications and an initial processing audit.

  3. Ongoing performanceongoing

    Oversight, advice, requests and notifications — the role is performed while you run your business.

A data protection officer is a role, not an entry on a form. The authority and data subjects expect someone who answers the phone, understands the company’s processing and can give informed answers — and, in an incident, ensures notification within the statutory time limit.

Having an external lawyer perform the role combines expertise with independence: oversight by someone outside your internal relationships, bound by professional confidentiality and equipped with legal support for difficult situations.

No-obligation enquiry

Ready to start?

Send us an enquiry. We reply within 24 hours with a price confirmation and next steps. The first 30-minute consultation is free and commits you to nothing.

  1. 1Send your enquiry via this form
  2. 2Within 24 h you get a price confirmation and plan
  3. 3We start work only after your approval
Mgr. Patrik Tulinský, LL.M. Czech and Slovak attorney · SAK 300422 · ČAK 19654

Not keen on calls or email? Message us on WhatsApp →
Prefer to book a time right away? Book a consultation →
Or email us about this matter.

For our conflict-of-interest check.
Add details such as deadline, documents and attachments (optional)
Is a deadline running?
Anything served by a court or authority gets priority.
Documents for this matter
Tick what you have at hand. We will fill in the rest together.
PDF, Word, images, ZIP… max 10 MB per file, 30 MB total.

Submitting this form does not create an engagement or attorney-client relationship. Before taking on a matter we run a conflict-of-interest check, so please do not send sensitive originals until we confirm the matter together.

What clients ask

Didn’t find your question? Ask us directly →

When must I appoint a data protection officer?

GDPR requires a DPO particularly for public authorities, large-scale regular and systematic monitoring of individuals, and large-scale processing of special categories of data, such as health data. Most ordinary businesses are not required to appoint one, but the boundaries of 'large-scale' processing are not precise and depend on the specific activity. That is exactly what our written assessment addresses.

Can an external provider act as DPO?

Yes. GDPR expressly permits a DPO to perform the role under a service contract. What matters is expertise, sufficient resources, independence and actual accessibility to data subjects and the authority. Outsourcing is especially useful for companies that cannot justify a dedicated employee for the role.

Why can our IT manager or managing director not be the DPO?

A DPO must not have a conflict of interest and cannot oversee processing decisions they make themselves. A managing director, head of IT or head of HR is therefore generally unsuitable. An external appointment addresses the conflict by placing oversight with someone who does not decide the processes being monitored.

What exactly will you do as our DPO?

Continuously monitor processing compliance with GDPR, advise on new projects and contracts, provide opinions on impact assessments, receive data subject requests, communicate with the authority and lead the incident response process. We tailor the scope and frequency to the volume of your processing and agree them in advance within the retainer.

Do you then become liable for fines instead of us?

No. Responsibility for compliance always remains with the controller — you. A DPO provides oversight and advice, not insurance. It is therefore important that the role is performed by someone who identifies problems promptly and in writing. Our opinions also provide evidence that you acted with professional care.

Legal Q&A

Common questions on this topic

Request an assessment of the DPO requirement
Contact a lawyer