Pillar A — Data Protection

GDPR work in practice is rarely abstract. Triggers tend to be concrete: a client demands a Data Processing Agreement, a competitor sends a cease-and-desist over a cookie banner, a tax advisor mentions the DPO obligation, or the supervisory authority writes after an incident. This pillar covers the legal-compliance side — from the first row of a record-of-processing register through to a full external DPO mandate.

When this pillar fits

  • DPO obligation under German BDSG § 38 — kicks in at 20 employees regularly processing personal data automatically
  • Online presence with newsletter, sign-up forms, online shop, course portal — the German legal kit (imprint, privacy notice, cookie banner, processor agreements)
  • Client or major customer demanding a processor agreement under GDPR Article 28
  • Employee data protection at growing teams: new hires, recruiting data, IT monitoring
  • Personal data incident requiring 72-hour notification to the supervisory authority (GDPR Article 33)

Sub-services

ServiceTriggerPriceLead time
External DPO 12 months (10–20 employees)DPO threshold closeEUR 195 / month2-week onboarding
External DPO 12 months (21–35 employees)Standard DPO mandateEUR 295 / month3-week onboarding
External DPO 12 months (36–50 employees)Mid-sized SMEEUR 495 / month4-week onboarding
GDPR Quickscan (1-hour audit + report)“Where do we stand?”EUR 1905 working days
Website compliance setupImprint, notice, banner, DPA setEUR 290–3902 weeks
Online-shop quickstartStripe/Klarna shopEUR 690–9903 weeks
Employee data protection auditGrowing team, IT monitoringEUR 890–11903 weeks
DPA inventory + gap closureClient demands DPA or tool auditEUR 6902 weeks

→ Detail in Services overview.

GDPR (in particular Articles 5, 6, 13, 15–22, 28, 30, 32, 35, 37–38), German BDSG § 26 (employee data protection) and § 38 (DPO threshold), TDDDG/EinwV (cookies and trackers), DDG § 5 (imprint), KUG § 22 (image rights).

Differentiation

  • vs. law firms: more affordable, technically closer to your stack
  • vs. IT consultancies: TÜV credential as the legally required proof for external DPO appointment
  • vs. classic DPO providers: trilingual capability (DE/EN/RU) and SME/solo-professional understanding

Credentials

  • TÜV Rheinland Data Protection Officer (DPO) — direct compliance proof under German BDSG § 38
  • TÜV Rheinland IT Security Manager — synergy for technical and organisational measures (GDPR Art. 32)
  • CompTIA CySA+ / CSAP — technical depth for measures audits

→ Detail in Certifications.


Discovery call

A discovery call clarifies the trigger, the right service, and the lead time. For DPO mandates: 12-month contract, first month upfront, then monthly billing.

Book a slot · or email alex@alex-sokolov.de