Our GDPR data protection officers take on the DPO mandate under Art. 37 GDPR for Swiss and EU companies, with the required expertise and independence, before supervisory authorities in DE, AT, IT, ES, NL and other member states. As an outsourced DPO we work for a fixed fee and are available immediately.
Packages starting from standard SMEArt. 37 GDPRCIPP/E certified
LL.M., Dr. iur., CIPP/E · Attorney at Law (New York) · Solicitor (UK)
Takes on DPO mandates for GDPR in the member states DE, AT, IT, ES, NL and Swiss dual mandates (revised FADP + GDPR). Reports directly to executive management.
Data protection and privacy are fundamental rights in the EU (Art. 7, 8 Charter), and have long been a business necessity.
70% of cyberattacks target SMEs (source: FIS Global).
95% of companies regard data protection as a business necessity (source: Cisco Data Privacy Benchmark).
Faster sales cycles through efficient vendor reviews.
Building customer trust and business appeal.
Avoidance of fines up to EUR 20 million or 4% of global annual turnover.
Do you need a Data Protection Officer?
Art. 37(1) GDPR makes the designation of a DPO mandatory in three situations:
The core activity requires large-scale processing of special categories (Art. 9) or systematic monitoring of data subjects.
The core activity consists of the regular and systematic processing on a large scale.
The company is a public authority (except courts).
In addition, there are national opening clauses. Example Germany: from 20 employees engaged in automated processing. We assess your obligation in the initial consultation.
Which tasks do we take on as your DPO?
Full-scope DPO mandate under Art. 39 GDPR, advising, monitoring, cooperating.
Informing and advising the controller, the processor and the employees on their GDPR obligations
Monitoring compliance with the GDPR, other data protection regulations and internal policies
Raising awareness and training employees involved in processing operations
Advising on data protection impact assessments (DPIAs) and monitoring their performance
Cooperating with and acting as point of contact for the competent supervisory authority
Maintaining the records of processing activities (ROPA)
How much effort does a Data Protection Officer require?
The effort varies considerably depending on company size, sector and IT complexity. Reference values:
Conference of the Independent Data Protection Authorities (DSK, Germany): up to 20 h/week for a fully utilised DPO
Federal Data Protection Commissioner (Bundestag response 2019): approx. 10 h/week for a 250-person company
Professional association BvD (member survey 2017): 14.2 h/week on average
With an external mandate, you pay only for the hours used, without recruiting, training, backup and social-insurance overhead.
Why you should designate us as your external Data Protection Officer
You save time and costs, DPO tasks are outsourced.
You benefit from many years of experience and expertise.
You minimise the risk of data protection breaches, fines and liability.
You receive independent, objective advice.
You strengthen the trust of your customers, employees and partners.
You make use of our mandates in DE · AT · IT · ES · NL and other member states.
Packages
Standard · SME
from CHF 600 / month
Fixed quarterly mandate: half a day per quarter plus availability. Additional tasks at an hourly or daily rate.
DPO mandate under Art. 37 GDPR
Quarterly meeting with executive management
ROPA maintenance
Response time 24 h
Premium
Annual quota custom
Flexible hourly quota from 30 h. Ideal for SMEs with 150–500 employees or DPIA needs.
Support through advice, training, audits and communication with authorities.
Ongoing support
Dedicated point of contact, with ongoing monitoring and updating.
Why SIDD?
A DPO mandate under Art. 37 GDPR only holds up when expertise, independence and auditable evidence come together, and this is precisely where SIDD makes the difference.
Legally and technically robust
Your DPO holds a doctorate in law, is CIPP/E-certified and admitted to the bar (New York, UK), backed by an in-house InfoSec team. This allows us to assess processing operations, data processing agreements and DPIAs not only on legal grounds but also on a technically robust basis, with no need to buy in external expertise.
Twofold confidentiality protection
Where Dr Staiger acts as an attorney, your information is covered by professional secrecy under Art. 321 SCC, in addition to the DPO's duty of confidentiality under Art. 38(5) GDPR. An in-house DPO cannot offer this twofold protection.
Appointment in multiple countries
We hold DPO mandates in DE, AT, IT, ES, NL and other EU countries, including Swiss dual mandates under the revised FADP and the GDPR. A single point of contact for correspondence with the respective competent supervisory authorities, instead of a separate provider for each country.
Audit-ready evidence
We maintain the records of processing activities (ROPA) (Art. 30), DPIAs and measures in our own Priverion Platform. In the event of an authority request, the evidence is available as maintained, auditable tooling rather than a scattered collection of documents.
Mandate instead of permanent hire
You appoint a certified role on a fixed mandate from CHF 600/month and pay for hours actually used, with no recruiting, training, backup or social-insurance overhead. If an individual DPO is unavailable, the team keeps the mandate continuously covered.
Takeover during ongoing operations
We have been handling DPO mandates since 2017, with a high renewal rate, a dedicated contact person and an initial response within 24 hours. We take over existing mandates from in-house roles or other providers during ongoing operations.
Outsourced DPO as a Service
Instead of creating an in-house role, you outsource the data protection officer mandate to SIDD. As your outsourced DPO we take on the duties under Art. 37 to 39 GDPR for a fixed fee, with a named contact and immediate availability.
LexCMD
Our tool: LexCommand
Why we work with LexCommand, our own Swiss legal AI
LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.
01
Sovereign in Switzerland
The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.
02
No citation, no claim
Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.
03
From effort to judgement
LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.
04
Three disciplines, one picture
We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.
For the DPO mandate, concretely, LexCommand keeps research scoped to each member state so your Art. 30 register and every DPIA rest on the correct national version with a link to the primary source, and on a Swiss double mandate it surfaces the FADP and GDPR duties side by side.
Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.
Frequently asked questions before engaging us
In which countries can you be appointed as DPO?
We handle DPO mandates in DE, AT, IT, ES, NL and other EU member states. For Swiss dual mandates, see DPO Switzerland.
How much does an external DPO cost?
Standard from CHF 600/month, Premium individually priced with an annual hour allowance. Group mandates on request.
Can you take over an existing DPO mandate?
Yes. We take over DPO mandates from in-house roles or other providers and continue ongoing operations.
Do I also need an EU representative in addition to the DPO?
Possibly. These are two distinct roles with different legal bases (Art. 27 vs. Art. 37 GDPR). See EU Representative.
Who is liable in the event of a data breach?
The company remains responsible for the processing (Art. 5 GDPR). The DPO is not personally liable for data protection breaches, we minimise the risk through documented processes, training and an incident playbook.
Are inquiries subject to confidentiality?
Yes, Art. 321 SCC. In addition, the DPO is bound by the duty of confidentiality under Art. 38(5) GDPR.
Ready for an external GDPR Data Protection Officer?
We will calculate the right solution for you, or book a 15-minute initial call with Dr Staiger directly.