Pillar A — Data Protection
GDPR work in practice is rarely abstract. Triggers tend to be concrete: a client demands a Data Processing Agreement, a competitor sends a cease-and-desist over a cookie banner, a tax advisor mentions the DPO obligation, or the supervisory authority writes after an incident. This pillar covers the legal-compliance side — from the first row of a record-of-processing register through to a full external DPO mandate.
When this pillar fits
- DPO obligation under German BDSG § 38 — kicks in at 20 employees regularly processing personal data automatically
- Online presence with newsletter, sign-up forms, online shop, course portal — the German legal kit (imprint, privacy notice, cookie banner, processor agreements)
- Client or major customer demanding a processor agreement under GDPR Article 28
- Employee data protection at growing teams: new hires, recruiting data, IT monitoring
- Personal data incident requiring 72-hour notification to the supervisory authority (GDPR Article 33)
Sub-services
| Service | Trigger | Price | Lead time |
|---|---|---|---|
| External DPO 12 months (10–20 employees) | DPO threshold close | EUR 195 / month | 2-week onboarding |
| External DPO 12 months (21–35 employees) | Standard DPO mandate | EUR 295 / month | 3-week onboarding |
| External DPO 12 months (36–50 employees) | Mid-sized SME | EUR 495 / month | 4-week onboarding |
| GDPR Quickscan (1-hour audit + report) | “Where do we stand?” | EUR 190 | 5 working days |
| Website compliance setup | Imprint, notice, banner, DPA set | EUR 290–390 | 2 weeks |
| Online-shop quickstart | Stripe/Klarna shop | EUR 690–990 | 3 weeks |
| Employee data protection audit | Growing team, IT monitoring | EUR 890–1190 | 3 weeks |
| DPA inventory + gap closure | Client demands DPA or tool audit | EUR 690 | 2 weeks |
→ Detail in Services overview.
Legal foundation
GDPR (in particular Articles 5, 6, 13, 15–22, 28, 30, 32, 35, 37–38), German BDSG § 26 (employee data protection) and § 38 (DPO threshold), TDDDG/EinwV (cookies and trackers), DDG § 5 (imprint), KUG § 22 (image rights).
Differentiation
- vs. law firms: more affordable, technically closer to your stack
- vs. IT consultancies: TÜV credential as the legally required proof for external DPO appointment
- vs. classic DPO providers: trilingual capability (DE/EN/RU) and SME/solo-professional understanding
Credentials
- TÜV Rheinland Data Protection Officer (DPO) — direct compliance proof under German BDSG § 38
- TÜV Rheinland IT Security Manager — synergy for technical and organisational measures (GDPR Art. 32)
- CompTIA CySA+ / CSAP — technical depth for measures audits
→ Detail in Certifications.
Discovery call
A discovery call clarifies the trigger, the right service, and the lead time. For DPO mandates: 12-month contract, first month upfront, then monthly billing.
→ Book a slot · or email alex@alex-sokolov.de