No. Our contracts do not have a minimum term and can be terminated with one month's notice. The collaboration with an external data protection officer is based on a deep relationship of trust. We want you to work with us out of conviction, not due to contractual obligations. If it's not the right fit for you, you should have the freedom to end the collaboration without complication.
We work transparently based on fixed monthly time quotas, which we tailor to your individual needs. We don't believe fixed price tiers or rigid packages like Basic or Premium are effective, as every company has unique requirements. Before we begin working together, we discuss your situation and goals in detail to understand exactly where you stand on data protection and what time quota would best support you.
Yes, we are also happy to act as the external data protection officer for your entire corporate group, drawing on our many years of experience in advising complex group structures.
Our advice, as well as the creation of all necessary documents, is provided in either German or English.
Our consulting is primarily designed for flexible and efficient remote collaboration to provide you with short communication channels and fast response times. Of course, as part of our engagement, we are also happy to visit you on-site for appointments such as kick-off workshops, audits, or training sessions. You are, of course, also always welcome at our offices in Cologne.
Yes. Thanks to our proven remote-first approach, we advise companies efficiently and without geographical restrictions throughout Germany and beyond.
The obligation to appoint a DPO exists in particular if your company's core activity consists of the large-scale processing of sensitive data (e.g., health data) or the regular and systematic monitoring of individuals. A DPO is also generally required if at least 20 people are regularly involved in the automated processing of personal data.
Regardless of any legal obligation, the voluntary appointment of a DPO can be a sensible measure to minimise risks.
To advise you in the best possible way, it is crucial for us to understand your company, your processes, and your goals. We typically get an overview of your organisational structure, the IT systems and service providers you use, and your key data processing operations during an initial kick-off meeting. Any existing documentation, such as policies or contracts, is very helpful in this regard.
Of course, this is not a rigid process: if you already have a high level of data protection maturity, we will adapt our approach and, if you wish, can move directly to advising on specific, detailed questions.
If your company is legally required to appoint a DPO, failing to do so can lead to various business risks. Internally, you will lack a central, expert point of contact who can maintain an overview of complex data protection requirements and support you in risk assessment. Externally, this can increase the likelihood of action from supervisory authorities, including the imposition of fines. Furthermore, a designated DPO is also an important signal of trust to customers and business partners.