GDPR Compliance
& Virtual DPO

Practical GDPR compliance and Data Protection Officer as a service — data mapping, DPIAs, records of processing, breach response, and privacy-by-design advisory for your product and engineering teams.

Overview

Privacy handled, properly.

GDPR compliance is an ongoing operational responsibility, not a one-off project. Whether you need to reach compliance or to outsource the DPO role entirely, we provide pragmatic, defensible privacy management.

We map your data flows, build your records of processing, run DPIAs, handle data-subject requests and breach notifications, and embed privacy-by-design into your product and engineering processes — acting as your outsourced Virtual DPO where required.


Scope

What we deliver.

End-to-end privacy operations and DPO duties.

Framework: EU GDPR Virtual DPO DPIA Privacy by design

FAQ

GDPR & Virtual DPO FAQ

The questions we're asked most about scope, cost, and timing.

How much does a Virtual DPO or GDPR support cost?
A Virtual DPO retainer typically runs €1,500–3,000 per month depending on size and data processing. One-off GDPR readiness projects are scoped separately. Use our estimator for a tailored figure.
Do we legally need a Data Protection Officer?
A DPO is mandatory under GDPR for large-scale systematic monitoring or large-scale processing of special-category data, and in some public-sector cases. Many others appoint one voluntarily. We advise during scoping.
Can you act as our outsourced DPO?
Yes — our Virtual DPO service fulfils the statutory role, including acting as contact point for your supervisory authority and data subjects.
What does GDPR readiness involve?
Data mapping, records of processing, DPIAs, privacy notices, processor agreements, breach procedures, and embedding privacy-by-design.
How does GDPR relate to ISO 27001?
ISO 27001 provides the security backbone supporting many GDPR obligations. They complement each other and are frequently delivered together.
Does GDPR apply to us if we are outside the EU?
Yes — if you offer goods/services to, or monitor, people in the EU, GDPR applies regardless of where you are based.
What is the difference between a controller and a processor?
A controller decides why and how data is processed; a processor acts on its behalf. Your role determines your obligations, which we clarify during scoping.
How fast must we report a breach?
Notifiable personal-data breaches must be reported to the supervisory authority within 72 hours; we build the process to meet this.
Do you handle data-subject requests?
Yes — as your Virtual DPO we can manage access, deletion, and other data-subject requests end to end.
How does GDPR relate to ISO 27001?
ISO 27001 provides the security controls that underpin many GDPR requirements; they work well together.

Related services

Explore more.

Ready to get GDPR right?

A 30-minute scoping call costs nothing. A privacy fine costs considerably more.

Book a meeting Send an email