The data protection officer service is paid as a fixed monthly fee. The price depends not on headcount but on the flow of questions: an institution that processes health or children’s data generates more situations in a year than a company of the same size that processes only staff and supplier data. The initial audit with its document package is paid separately from the monthly service. We send a specific figure within a few working days, and if you need it for a public procurement plan, on the same day and without a questionnaire.
This answers the question we receive through our website form more often than any other. It is almost always put the same way: how much does the data protection officer service cost per month, and what does that price include?
Why the price is needed before anything else
The most common buyer of this service is an education, culture or healthcare institution that is drawing up its public procurement plan. The plan needs a figure, and it needs it before anyone has time to answer a questionnaire about data processing.
So we give an initial price without a questionnaire. It is enough to know the type of institution, the approximate number of staff and whether health or children’s data is processed. It can be refined later — the figure needed for the plan is sent on the same day.
In this situation, an answer of “get in touch and we’ll discuss it” is not caution but an obstacle. An institution that has to enter a line in its plan by a specific date has no time for negotiation.
What the monthly price includes
The monthly service is the performance of the officer’s function, not a bundle of hours. In practice it consists of the following:
- advice to staff when a specific question comes up — can a list be forwarded, can a conversation be recorded, what to tell parents;
- a warning about possible breaches when we see that a planned decision will cause them;
- replies to data subjects’ requests and oversight of the time limits for dealing with them;
- communication with the State Data Protection Inspectorate (VDAI), including acting as the contact point;
- keeping the breach register required by Article 33(5) GDPR;
- maintaining the records of processing activities under Article 30 GDPR.
On top of this come duties that arise once and then remain: Article 37(7) GDPR requires the officer’s contact details to be published and communicated to the supervisory authority. Article 38(1) GDPR requires the officer to be involved in good time in all issues relating to data protection, rather than informed after the decision.
The format that works best in practice
The law does not set how often the officer must communicate with the organisation. It is a question of practice, and our answer to it is this: remote meetings every two weeks, 30 minutes each.
This is a real arrangement with a client, not a textbook recommendation. The reason is simple. A meeting held once a year does not manage to catch anything, and the questions that come up in between are simply never raised. Thirty minutes every two weeks is enough to go through what has changed, and rare enough not to become a burden for anyone. Between meetings, questions are handled by email.
If a provider offers only an annual review, it is worth asking what happens to a question that comes up in October.
The second common case: the previous provider has stopped trading
A good share of enquiries come from organisations whose previous data protection officer has stopped providing the service. The institution is left without an officer, and its document package without an author.
In that case we start not with the documents but with an audit. The reason for this is not sales. Since the previous package was prepared, processes have already changed: new systems have appeared, service providers have changed, people have changed. The old documents describe an organisation that no longer exists. Extending them unchanged means inheriting the error and signing your own name under it.
In this situation, the audit usually shows that most of the documents are still fit for purpose, while a few sections no longer match reality. Those few are rewritten.
What is paid separately
Not everything connected with data protection is part of the officer’s function. Work that is a project rather than ongoing oversight is paid separately:
- the initial compliance audit and document package;
- a description of the purposes of video surveillance cameras, where the need is identified during the audit;
- a data protection impact assessment (DPIA) under Article 35 GDPR, where one is mandatory;
- staff training.
This split is not a price-list trick. Article 39(1)(b) GDPR assigns the officer the task of monitoring compliance. Preparing the documents and then monitoring compliance with documents you prepared yourself are two jobs, and they differ in scope.
How to start
The first step is free: a short assessment of your situation based on a questionnaire, after which we send, within a few working days, a proposal with a specific price. If you need the price earlier for a public procurement plan, say so in your email — we will send the figure without a questionnaire.
You can check whether your organisation needs a record of processing activities with the Privacio tool, built by Linden (in Lithuanian).
Email: info@linden.lt
More about this service: external data protection officer service.