Art. 37 GDPR · External DPO for EU mandates

External DPO Switzerland · Outsourced DPO & GDPR Art. 37

Our GDPR data protection officers take on the DPO mandate under Art. 37 GDPR for Swiss and EU companies, with the required expertise and independence, before supervisory authorities in DE, AT, IT, ES, NL and other member states. As an outsourced DPO we work for a fixed fee and are available immediately.

Packages starting from standard SME Art. 37 GDPR CIPP/E certified
External Data Protection Officer EU - Art. 37 GDPR
CIPP/E · Attorney at Law (NY)

Working for regulated industries and SMEs

CIPP/E · CIPM IAPP certified
ISO 27001 Lead Auditor (BSI)
Aligned with the FDPIC Revised FADP · Art. 10
HQ Baar, ZG Swiss brand
CH · EU · UK · US Mandates worldwide
Dr. Dominic Staiger

Responsible for this mandate

Dr. Dominic Staiger

LL.M., Dr. iur., CIPP/E · Attorney at Law (New York) · Solicitor (UK)

Takes on DPO mandates for GDPR in the member states DE, AT, IT, ES, NL and Swiss dual mandates (revised FADP + GDPR). Reports directly to executive management.

LinkedIn profile

Why data protection matters for your company

Data protection and privacy are fundamental rights in the EU (Art. 7, 8 Charter), and have long been a business necessity.

  • 70% of cyberattacks target SMEs (source: FIS Global).
  • 95% of companies regard data protection as a business necessity (source: Cisco Data Privacy Benchmark).
  • Faster sales cycles through efficient vendor reviews.
  • Building customer trust and business appeal.
  • Avoidance of fines up to EUR 20 million or 4% of global annual turnover.

Do you need a Data Protection Officer?

Art. 37(1) GDPR makes the designation of a DPO mandatory in three situations:

  • The core activity requires large-scale processing of special categories (Art. 9) or systematic monitoring of data subjects.
  • The core activity consists of the regular and systematic processing on a large scale.
  • The company is a public authority (except courts).

In addition, there are national opening clauses. Example Germany: from 20 employees engaged in automated processing. We assess your obligation in the initial consultation.

Which tasks do we take on as your DPO?

Full-scope DPO mandate under Art. 39 GDPR, advising, monitoring, cooperating.

  • Informing and advising the controller, the processor and the employees on their GDPR obligations
  • Monitoring compliance with the GDPR, other data protection regulations and internal policies
  • Raising awareness and training employees involved in processing operations
  • Advising on data protection impact assessments (DPIAs) and monitoring their performance
  • Cooperating with and acting as point of contact for the competent supervisory authority
  • Maintaining the records of processing activities (ROPA)

How much effort does a Data Protection Officer require?

The effort varies considerably depending on company size, sector and IT complexity. Reference values:

  • Conference of the Independent Data Protection Authorities (DSK, Germany): up to 20 h/week for a fully utilised DPO
  • Federal Data Protection Commissioner (Bundestag response 2019): approx. 10 h/week for a 250-person company
  • Professional association BvD (member survey 2017): 14.2 h/week on average

With an external mandate, you pay only for the hours used, without recruiting, training, backup and social-insurance overhead.

Why you should designate us as your external Data Protection Officer

  • You save time and costs, DPO tasks are outsourced.
  • You benefit from many years of experience and expertise.
  • You minimise the risk of data protection breaches, fines and liability.
  • You receive independent, objective advice.
  • You strengthen the trust of your customers, employees and partners.
  • You make use of our mandates in DE · AT · IT · ES · NL and other member states.

Packages

Standard · SME

from CHF 600 / month

Fixed quarterly mandate: half a day per quarter plus availability. Additional tasks at an hourly or daily rate.

  • DPO mandate under Art. 37 GDPR
  • Quarterly meeting with executive management
  • ROPA maintenance
  • Response time 24 h

What happens after the engagement is awarded?

Contract

Digital service agreement defining the scope of services as DPO under Art. 37 GDPR.

Kick-off

Workshop to get acquainted, align expectations, and define next steps.

Analysis

Inventory of data-protection-relevant processes, systems and documents.

Concept

Action plan: privacy notices, ROPA, DPIAs, data processing agreements, internal policies.

Implementation

Support through advice, training, audits and communication with authorities.

Ongoing support

Dedicated point of contact, with ongoing monitoring and updating.

Why SIDD?

A DPO mandate under Art. 37 GDPR only holds up when expertise, independence and auditable evidence come together, and this is precisely where SIDD makes the difference.

Legally and technically robust

Your DPO holds a doctorate in law, is CIPP/E-certified and admitted to the bar (New York, UK), backed by an in-house InfoSec team. This allows us to assess processing operations, data processing agreements and DPIAs not only on legal grounds but also on a technically robust basis, with no need to buy in external expertise.

Twofold confidentiality protection

Where Dr Staiger acts as an attorney, your information is covered by professional secrecy under Art. 321 SCC, in addition to the DPO's duty of confidentiality under Art. 38(5) GDPR. An in-house DPO cannot offer this twofold protection.

Appointment in multiple countries

We hold DPO mandates in DE, AT, IT, ES, NL and other EU countries, including Swiss dual mandates under the revised FADP and the GDPR. A single point of contact for correspondence with the respective competent supervisory authorities, instead of a separate provider for each country.

Audit-ready evidence

We maintain the records of processing activities (ROPA) (Art. 30), DPIAs and measures in our own Priverion Platform. In the event of an authority request, the evidence is available as maintained, auditable tooling rather than a scattered collection of documents.

Mandate instead of permanent hire

You appoint a certified role on a fixed mandate from CHF 600/month and pay for hours actually used, with no recruiting, training, backup or social-insurance overhead. If an individual DPO is unavailable, the team keeps the mandate continuously covered.

Takeover during ongoing operations

We have been handling DPO mandates since 2017, with a high renewal rate, a dedicated contact person and an initial response within 24 hours. We take over existing mandates from in-house roles or other providers during ongoing operations.

Outsourced DPO as a Service

Instead of creating an in-house role, you outsource the data protection officer mandate to SIDD. As your outsourced DPO we take on the duties under Art. 37 to 39 GDPR for a fixed fee, with a named contact and immediate availability.

Our tool: LexCommand

Why we work with LexCommand, our own Swiss legal AI

LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.

Sovereign in Switzerland

The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.

No citation, no claim

Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.

From effort to judgement

LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.

Three disciplines, one picture

We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.

For the DPO mandate, concretely, LexCommand keeps research scoped to each member state so your Art. 30 register and every DPIA rest on the correct national version with a link to the primary source, and on a Swiss double mandate it surfaces the FADP and GDPR duties side by side.

Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.

Frequently asked questions before engaging us

In which countries can you be appointed as DPO?

We handle DPO mandates in DE, AT, IT, ES, NL and other EU member states. For Swiss dual mandates, see DPO Switzerland.

How much does an external DPO cost?

Standard from CHF 600/month, Premium individually priced with an annual hour allowance. Group mandates on request.

Can you take over an existing DPO mandate?

Yes. We take over DPO mandates from in-house roles or other providers and continue ongoing operations.

Do I also need an EU representative in addition to the DPO?

Possibly. These are two distinct roles with different legal bases (Art. 27 vs. Art. 37 GDPR). See EU Representative.

Who is liable in the event of a data breach?

The company remains responsible for the processing (Art. 5 GDPR). The DPO is not personally liable for data protection breaches, we minimise the risk through documented processes, training and an incident playbook.

Are inquiries subject to confidentiality?

Yes, Art. 321 SCC. In addition, the DPO is bound by the duty of confidentiality under Art. 38(5) GDPR.

Ready for an external GDPR Data Protection Officer?

We will calculate the right solution for you, or book a 15-minute initial call with Dr Staiger directly.