Your external
data protection officer

Empowered by the experience of a leading law firm in data protection.

Empowered by the experience of a leading law firm in data protection.

Talk to us
Data protection compliance made actionable: our guidance combines legal accuracy, strategic foresight, and technical depth, all aligned with your corporate realities.

As a result, with OC Services you are in good hands. And in the best of company.

Why choose an external data protection officer?

External expertise combines specialist knowledge with an impartial perspective that companies rarely have in-house yet urgently need.

Working with us gives you access to broad industry know-how and relieves your internal teams. This lets you focus on your core business while minimising data protection risks.

Why OC Services?

We avoid one-size-fits-all approaches and turn complexity into guidance you can understand and act on.

With OC Services, you benefit from direct access to the specialised knowledge of Osborne Clarke GmbH & Co. KG (“OC”) , one of the leading international law firms in data protection law. This partnership guarantees you a combination of hands-on operational support and robust legal expertise.

Common data protection topics

As your external data protection officer, we guide you through these key topics.

Your compliance requirements

The fundamental requirements for your company.
Data Protection Management
Systematic data protection management is the basis for verifiable compliance in accordance with the GDPR. We provide comprehensive advice on establishing an effective management system, developing internal policies and processes, and assigning clear responsibilities to meet legal requirements in a structured manner.
Documentation and Accountability Obligations
The GDPR's accountability principle requires proof of compliance. We provide crucial support in fulfilling your documentation obligations, particularly with the methodical creation, review, and ongoing maintenance of your Record of Processing Activities (“ROPA”) as the central tool for demonstrating this.
Legal Bases
All data processing requires a legal basis. We advise you on the review and determination of the relevant legal bases for your processes, particularly in the complex application of legitimate interests, including the performance of balancing tests (“LIA”).
Data Transfers
The transfer of data to service providers, within a corporate group, or to third countries is subject to strict rules. We advise you on reviewing data processing agreements (“DPAs”), securing third-country transfers, and structuring your data flows to comply with the complex legal frameworks.
Information and Transparency Obligations
Transparency is a key principle of the GDPR. We draft and review your privacy policies to ensure that you fulfil your information obligations.
Data Subject Rights
The timely and proper fulfilment of data subject rights under the GDPR is essential. We advise you on developing efficient internal processes, assist in creating response templates, and support you in assessing complex requests to minimise risks.
Data Security and Risk Management
A level of security appropriate to the risk is mandatory under Article 32 GDPR. We advise you on the assessment of your technical and organisational measures, on conducting risk assessments, and provide support you when carrying out data protection impact assessments (“DPIAs”)
Data Breaches
A structured approach to handling data breaches is crucial for minimising risks. We provide preventive advice on creating emergency plans and, in the event of an incident, support you in assessing the situation and complying with statutory reporting and notification obligations to authorities and data subjects.
Deletion and Retention
The principle of storage limitation requires a structured deletion concept. We advise you on developing such a deletion concept, defining retention periods while considering statutory obligations, and implementing processes for verifiable data deletion.

We focus on relevant legislation

Our expertise extends beyond the GDPR, enabling us to consistently provide you with holistic data protection advice.

Core EU regulation

General Data Protection Regulation (“GDPR”)
As the EU-wide foundation for data protection, the GDPR is the foundation of your compliance efforts and central to all our guidance.

German data privacy law

German Federal Data Protection Act (“BDSG”)
We advise you on the nuances of Germany's specific data protection laws that add another layer of complexity, i.a., concerning employee data.

Privacy in digital services

ePrivacy Directive and German Telecommunications and Digital Services Data Protection Act (“TDDDG”)
We guide you through the technical side of compliance, covering regulations for websites, apps, cookies, and tracking technologies.

Marketing and advertising

German Act Against Unfair Competition (“UWG”)
Your advertising campaigns, newsletters, and sales funnels must comply with the strict regulations set by Germany's competition law.
OC Services guides you across the full spectrum of European and German data protection laws.
We do not just see individual laws; we see the entire data protection landscape. This comprehensive approach ensures that your compliance measures are not only correct in isolated cases but are systematically robust throughout your organization, giving you peace of mind to focus on what you do best.

Benefit from our comprehensive industry expertise

From healthcare and insurance to manufacturing, we understand the unique requirements of your sector.
In data protection, industry-specific details are essential.
Whether healthcare, e-commerce, manufacturing, or critical infrastructure, we know your processes and the associated data protection challenges.
Based on this understanding, we develop tailored, effective solutions that meet your sector’s specific needs and ensure long-term compliance.

The joint path for your compliance

Discover our approach: No templates, but a structured path for your data protection topics. From initial understanding to effective compliance.

Understand

We begin with an in-depth discussion to understand your individual requirements and processes.

Analyse

Following a detailed analysis of your structures, we develop concrete, prioritised recommendations for action.

Implement

We actively support you in a spirit of partnership during the implementation of the measures.

Advise

We monitor your data protection compliance and proactively advise on new legal developments.

OC Services is your first point of contact for all data protection matters, both internally and externally.

As your external data protection officer (“DPO”), OC Services (“OCS”) is the central point of contact both internally and externally. We promote an active data protection culture, thereby strengthening the trust of your business partners, customers, and employees. Consider us your independent expert in the corporate context for sustainable compliance.

Leveraging synergies: pptional supplementary legal advice from Osborne Clarke

Do you also require support with legal drafting, for example, of contracts? Our colleagues at our parent company, Osborne Clarke GmbH & Co. KG (“OC”) , are happy to provide this service. Through this close coordination and clear division of responsibilities, you can receive both, as and when required: practical DPO support from OCS, and legal advice and representation from OC.

Frequently asked questions

Commercial

No. Our contracts do not have a minimum term and can be terminated with one month's notice. The collaboration with an external data protection officer is based on a deep relationship of trust. We want you to work with us out of conviction, not due to contractual obligations. If it's not the right fit for you, you should have the freedom to end the collaboration without complication.

We work transparently based on fixed monthly time quotas, which we tailor to your individual needs. We don't believe fixed price tiers or rigid packages like Basic or Premium are effective, as every company has unique requirements. Before we begin working together, we discuss your situation and goals in detail to understand exactly where you stand on data protection and what time quota would best support you.

Yes, we are also happy to act as the external data protection officer for your entire corporate group, drawing on our many years of experience in advising complex group structures.

Organisational

Our advice, as well as the creation of all necessary documents, is provided in either German or English.

Our consulting is primarily designed for flexible and efficient remote collaboration to provide you with short communication channels and fast response times. Of course, as part of our engagement, we are also happy to visit you on-site for appointments such as kick-off workshops, audits, or training sessions. You are, of course, also always welcome at our offices in Cologne.

Yes. Thanks to our proven remote-first approach, we advise companies efficiently and without geographical restrictions throughout Germany and beyond.

Subject-matter related

The obligation to appoint a DPO exists in particular if your company's core activity consists of the large-scale processing of sensitive data (e.g., health data) or the regular and systematic monitoring of individuals. A DPO is also generally required if at least 20 people are regularly involved in the automated processing of personal data.

Regardless of any legal obligation, the voluntary appointment of a DPO can be a sensible measure to minimise risks.

To advise you in the best possible way, it is crucial for us to understand your company, your processes, and your goals. We typically get an overview of your organisational structure, the IT systems and service providers you use, and your key data processing operations during an initial kick-off meeting. Any existing documentation, such as policies or contracts, is very helpful in this regard.

Of course, this is not a rigid process: if you already have a high level of data protection maturity, we will adapt our approach and, if you wish, can move directly to advising on specific, detailed questions.

If your company is legally required to appoint a DPO, failing to do so can lead to various business risks. Internally, you will lack a central, expert point of contact who can maintain an overview of complex data protection requirements and support you in risk assessment. Externally, this can increase the likelihood of action from supervisory authorities, including the imposition of fines. Furthermore, a designated DPO is also an important signal of trust to customers and business partners.

Dr Marc Störing
Managing Director
Certified Information Privacy Professional, CIPP/E
+49 175 930 555 1 marc.stoering@osborneclarke-services.com
OC Services GmbH, Innere Kanalstraße 15, 50823 Cologne, Germany
Registration Court: Local Court of Cologne, HRB 92393
Managing Director: Gereon Abendroth, Nicolas Gabrysch-Wolff, Dr Marc Störing
Language: