Outsourced Data Protection Officer
A named Data Protection Officer discharging the statutory role, including regulator contact and data subject escalation.
Fee & intake
Sign in to see the engagement fee (plus 7.5% VAT), complete the intake form, save a draft if you need to, then pay to submit.
- Renews
- Every 12 months
Regulatory and standards basis
This engagement is performed against the following instruments. Each is cited in the deliverable at the point it is relied on.
- Nigeria Data Protection Act 2023 DPO requirements
- Kenya Data Protection Act 2019
- GDPR Article 37 where applicable
Who this is for
- Controllers required to appoint a DPO
- Firms processing at scale
What you receive
- 01Named DPO appointed and registered where required
- 02DPIA review and sign-off
- 03Data subject request escalation handling
- 04Annual compliance audit support and board reporting
How the engagement runs
Phase 1
Onboarding
Appointment, regulator notification where required, and a handover of existing programme material.
Phase 2
Steady state
The named role-holder discharges the function: reviews, decisions, filings and escalations.
Phase 3
Reporting
Monthly management information and quarterly board reporting.
Phase 4
Review
Annual programme review, with the engagement rolling on a 12-month term.
Questions
Who approves the deliverable?
A named member of the engagement team reviews it and a partner approves it. Their name, title and credentials are printed on the report, and the approval is recorded against the engagement in the portal.
What is the minimum term?
Twelve months, invoiced monthly in advance, or annually in advance where agreed at intake.
What happens next year?
The portal reminds you 90, 60 and 30 days before it is due, and you start a new version of this engagement pre-filled from the answers you gave last time. You update only what has changed, and you see a side-by-side of what changed before you submit.
Where do our documents live?
In private storage, accessible only through short-lived signed links, with every view and download logged. Nothing is attached to email. Our sub-processors and data residency are published on the trust page.
How do we pay?
By card through Stripe after you complete intake in the portal. You can save a draft without paying; submission happens only after payment succeeds.
Related engagements in Data Protection and Privacy
Breach Response Playbook and Notification Templates
A playbook that gets you to a defensible regulator notification inside the statutory window, written before you need it.
Cross-Border Transfer Impact Assessment
An assessment of your international data transfers and the mechanism each one relies on, including cloud processing outside the country.
Data Protection Impact Assessment
A documented impact assessment for a high-risk processing activity, with mitigations and a residual risk conclusion your DPO can sign.