Consulting for Data Protection and GDPR Implementation
Data Protection Consulting: Turning the GDPR Into Processes That Hold in Daily Work
Data protection consulting works on a single underlying question: why is this data here — and how long may it stay? It sets out which personal data a company processes, what each of those processing activities rests on, who processes it on the company's behalf, and when it ends. The subject rarely turns urgent because of the regulation itself. It turns urgent through an occasion: a new system that touches employee or customer data, a client asking for the records of processing activities, an access or erasure request running to a deadline, a provider with servers outside the EU, a complaint lodged with the supervisory authority. Three things are needed for that: a baseline that describes the process as it is lived rather than as it was intended; for every processing activity a named purpose, a legal basis that holds, and a retention period; and somebody who builds both into systems, contracts and work instructions instead of filing them in a folder.
Leading companies trust our network
What Data Protection Consulting Delivers — and What It Does Not

Data protection consulting — also called data privacy consulting, GDPR consulting or advice on a data protection management system — puts every processing activity to three questions. Is it named what the data was collected for? Is it settled what the processing rests on? Is it fixed when it ends? Purpose, legal basis, retention period. If any one of the three is missing, the rest of the documentation is a facade. And the yardstick is not the volume of data but the purpose: ten fields without a named purpose are a problem, two hundred fields with a legal basis that holds and a retention period that has been set are not.
The practical work follows from that. Record processing activities the way they actually run. Name a legal basis for each one — performance of a contract, legal obligation, legitimate interests with a documented balancing test, consent — and where none holds, change the processing instead of rewriting its description. Set retention and erasure as a period per data category, not as an intention. Underpin processors with a data processing agreement, documented instructions and a transfer assessment. Describe technical and organisational measures so that an auditor can follow them against reality. And for new plans, decide early whether a data protection impact assessment is required.
Two confusions cost time again and again. The first: data protection is not data security. Security asks who can reach the data; data protection asks beforehand whether it may be there at all. Encryption, an access model and attack detection belong to cyber security consulting and replace no legal basis. The second: data protection is part of compliance but not the whole of it — whistleblower protection, sanctions law, supply chain due diligence and the internal control system run in compliance consulting and follow other bodies of rules.
And what data protection consulting does not deliver: it is a design question, not an audit question. That is the case for privacy by design — the decision is taken while a process or a system is being designed, over which fields are collected, which interface passes them on, how long a record stays. Whoever reviews only at the end can document what already runs, or rebuild it expensively. It also replaces neither legal representation in proceedings nor an assurance that one reading of the law will hold before every supervisory authority: data protection law is open to interpretation, and what carries weight is a reasoned, documented decision rather than a guarantee. And it does not take responsibility off the management — that stays with the controller within the meaning of the Regulation.
When External Support on Data Privacy Questions Is Worth It
Many data protection questions are settled faster in-house. If the processing is known, the legal basis undisputed and somebody on the payroll has both the time and the subject knowledge, nobody from outside is needed. The occasions below turn out differently, and for a structural reason: a company decides the same data protection question once and lives with the answer for years. Whoever decides that same question regularly for different clients knows the readings that have held in an audit — and the ones that have not.
1. A New System Is Meant to Process Personal Data
- The selection process is underway, the business unit is pressing for a decision, and the questions regarding the legal basis and retention period remain unresolved.
- Once the contract is signed, there's no more room for flexibility: data fields, interfaces, and retention periods become product features.
- A preliminary review with a clear "yes" or "no" regarding the DPIA costs a fraction of what a later overhaul would cost.
2. A Client or Auditor Asks for Evidence
- Tenders and corporate clients ask for the records of processing activities, the description of technical and organisational measures, the erasure concept and the data processing agreements.
- Existing papers are often older than the systems they describe — and the contradiction is spotted by the other side, not by your own team.
- What counts in a GDPR audit is a version that matches the current state, not a template pulled off the internet.
3. Data Subject Rights Are Running to a Deadline
- Access, Erasure, rectification, portability: The one-month period begins upon receipt of the request, not upon clarification of responsibility.
- Without a fixed procedure, designated responsibility, and knowledge of where the data is located, every request becomes a case-by-case matter.
- A well-established process prevents complaints arising from missed deadlines.
4. Processors and Third-Country Transfers Are Unsettled
- Cloud services, analytics tools, support from abroad, subcontractors of subcontractors.
- Data processing agreements are missing, incomplete, or fail to name sub-processors whose access has existed for a long time.
- Assessing a transfer takes practice with the standard contractual clauses and the supplementary measures that go with them.
5. The Data Protection Officer Role Is Vacant or Overloaded
- The threshold for a mandatory appointment is met, the succession is open, or the task hangs on one person who carries it alongside their actual job.
- An internal candidate frequently collides with the bar on self-monitoring — head of IT, head of HR and the managing director are all ruled out.
- An external data protection officer resolves that incompatibility and brings cases from other companies along.
6. Something Has Gone Wrong or a Supervisory Authority Is Asking
- A misdirected email, open folders, lost devices, attacks involving data breaches — you have 72 hours to report them.
- During this time, the facts of the incident, the data subjects concerned, the risk, and countermeasures must be described in a reliable manner.
- Anyone who has handled this multiple times can distinguish between incidents that require reporting and those that require documentation.
Do any of these occasions sound familiar? A brief conversation is all it takes to get a preliminary idea: which process should be addressed first, what information is missing — and whether outside help is needed at all.
The Regulated Fields of GDPR Consulting: From Legal Basis to Erasure
The six regulated fields can be commissioned one at a time, but they all rest on the same foundation: the stock of processing activities. Whoever starts with the measures without knowing which processing activities exist may end up securing data that should never have been collected. As a rule it therefore starts with fields one and two and grows from there into the neighbouring ones.
Legal Bases and Purpose Limitation
A sound legal basis for every processing activity: performance of a contract, legal obligation, legitimate interest with a documented balancing test, or consent. In addition, there is the principle of purpose limitation — the purpose for which the data was collected and what may still be derived from it. Special categories under Article 9 (health, trade union membership, biometrics) require separate authorisation. The result is a specified legal basis for each processing operation and, where none applies, a proposed change to the process rather than to the description.
Records of Processing Activities
The records of processing activities under Article 30 are the map everything else is built on: processing activity, purpose, data categories, groups of data subjects, recipients, retention periods, systems. What gets recorded is the process as it is lived, gathered in interviews with the business units and held against the system landscape. Records that do not follow the actual process are not evidence but a dated contradiction. They are kept current through a fixed occasion, not through good intentions.
Processors and Third-Country Transfers
Every provider with access to personal data needs a data processing agreement under Article 28, a documented set of instructions, and a check that actually takes place. Where processing happens outside the EU, the transfer assessment comes on top: adequacy decision, standard contractual clauses, supplementary measures. The most common finding is sub-processors who are absent from the contract but have had technical access for a long time. The result is a current processor register with an assessment for each transfer.
Technical and Organisational Measures
Technical and organisational measures mean: role and permission framework, encryption, logging, separation of environments, erasure routines, employee obligations, and training. These elements are described in a way that allows an auditor to verify them against reality — including the person responsible and the location where evidence can be found. Technical hardening itself comes from the field of IT security; here, the focus is on aligning measures with the risks associated with data processing and determining whether the measures are actually effective in everyday practice.
Data Subject Rights and Erasure Concept
Right of access, rectification, erasure, restriction, data portability, and objection — each right requires a process that includes a channel for submission, designated responsibility, identity verification, and a deadline. The erasure concept specifies, for each data type, when data is to be deleted and what must be retained beforehand in accordance with commercial or tax law. The difficult part is not the rule itself, but its implementation in systems that were not designed to handle erasure. The result is a retention schedule with a technical implementation trail.
DPIA and New Systems
Ahead of every high-risk plan — extensive profiling, systematic monitoring, health data, AI-assisted evaluation — stands the question of whether a data protection impact assessment (DPIA) under Article 35 is required. It describes the processing, its necessity, the risks to data subjects and the measures that lower those risks. It is useful early: as a design tool that shapes data fields and retention alongside everything else, not as a form filled in after sign-off.
Which regulated field carries the most weight for you can be placed roughly in a short conversation — together with the honest answer on whether a project of its own is worth it.
How External Data Protection Expertise Is Brought In — Up to DPO as a Service
In data protection it is the role, alongside subject depth, that decides: whoever rejects a legal basis has to defend that in front of the business unit, IT and the managing director — and, in the case of an appointment under Article 37, in front of the supervisory authority as well. Four routes are common, and they differ above all in how much decision-making weight comes with them.
Baseline Assessment of Your Data Protection Standing
A specialist with a specific assignment: reviewing the existing documentation, comparing it with the actual work performed, and identifying gaps in order of priority. The result is a written report outlining priorities and an assessment of which tasks can be handled in-house. No additional structure is provided.
Appointment as External Data Protection Officer
Also known as DPO as a service: the role under Article 37 is filled from outside — monitoring compliance, advising the business units, training, and acting as the point of contact for data subjects and the supervisory authority. Filling it externally resolves the bar on self-monitoring that rules out internal candidates from IT, HR and the management, and it brings cases from other companies along.
Delivery Capacity Inside Your Own Team
Extra hands for the work that keeps being left: recording the processing activities, catching up on data processing agreements, setting retention periods per data category, working through requests from data subjects. The internal data protection officer keeps the role and the decision; the capacity is what gets added.
Steering a Data Protection Programme
Where several legal entities, systems or national laws come together, somebody has to run the project: cutting work packages, coordinating business units and IT, preparing decisions, and representing the state of play to the management and to auditors.
Which Personal Data Sets the Pace in Which Sector
Data protection cannot be set up in a sector-neutral way, because the data categories themselves are the sector. In a hospital, health data is at the centre; Article 9 requires a separate condition for it and state hospital legislation adds its own requirements, and the separation of access between treatment, administration and research is the central question there. At banks and insurers, the Regulation meets a dense body of supervisory law: scoring and automated individual decision-making need a justification that convinces the sector regulator too, while retention duties under commercial and anti-money-laundering law limit erasure. In retail and e-commerce, consent decides: tracking, advertising profiles, customer accounts and newsletters stand or fall on proof of who consented to what and when. In staffing services and the HR field, applicant and employee data are the core, together with works council co-determination and the question of how long an application may stay after a rejection. Public administration and educational institutions almost never work with consent but with a legal basis in sector-specific law — there, mapping each processing activity to a provision is the main work. And at software and technology companies the perspective reverses: they are usually processors themselves, have to demonstrate data protection as a product feature, and have to pass their clients' questionnaires.
We staff by sector experience, not by subject knowledge alone: whoever knows the case-handling systems of a municipality, the audit practice of a state supervisory authority or the client questionnaires of a software vendor does not reopen the argument about interpretation, but brings along the version that has already held there.
Healthcare & Hospitals
Health data constitute special categories under Article 9: In addition to a legal basis, their processing requires specific authorisation, typically derived from the treatment agreement or state hospital legislation. Key issues include the separation of access between treatment, administration, billing, and research; the integration of practice and hospital information systems; data processing by laboratories and billing service providers; and the question of which analyses still constitute treatment and which already constitute research. In addition, there is the physician's duty of confidentiality, which in some respects goes beyond the requirements of the regulation.
Banking & Insurance
Here, the regulation intersects with supervisory law, which imposes its own retention and documentation requirements. Scoring, fraud detection, and automated individual decision-making under Article 22 require a documented justification and the possibility of human review. At the same time, commercial, tax, and anti-money laundering laws impose restrictions on data erasure: a data retention policy must account for both sets of requirements. In addition, there are outsourcing arrangements with data centres and service providers that must be evaluated in light of both regulatory and data protection requirements.
Retail & E-Commerce
Consent is the linchpin: tracking, retargeting, advertising profiles, newsletters, and customer accounts all stand or fall on proof of who consented to what and when — and on a revocation that actually takes effect. Added to this are payment service providers and shipping service providers acting as data processors, analytics tools with servers located outside the EU, and the retention of order histories, which must be balanced against warranty obligations, tax law, and data minimisation.
Staffing Services & HR
Applicant and employee data are at the core, and employee data protection law establishes a stricter framework than customer data protection. Topics include the retention of applications after rejection, applicant tracking systems and their data processing, time tracking and performance evaluation with the involvement of the works council, as well as company agreements as a separate legal basis. In the case of AI-supported pre-selection, the question of Article 22 and a data protection impact assessment also arises.
Public Administration & Education
Public authorities and educational institutions almost never operate on the basis of consent, but rather on a legal basis provided by sector-specific laws — the main task, therefore, is to map each processing activity to a specific legal provision, including the applicable state data protection act. Added to this are sector-specific case-handling systems with long lifecycles, joint responsibility across levels and governing bodies, record-keeping plans and retention periods under archival law, and — in the case of schools and universities — the processing of data pertaining to minors.
Software & Technology
Here, the perspective is reversed: Providers are usually data processors themselves and must demonstrate data protection as a product feature — data minimisation by design, client segregation, erasure functions, logging, and a list of subcontractors. In practice, what matters is how well the company passes customer questionnaires and audit requests. Added to this are telemetry and product analysis within its own applications, test data from production environments, and the data protection aspects of model training.
Healthcare & Hospitals
Health data constitute special categories under Article 9: In addition to a legal basis, their processing requires specific authorisation, typically derived from the treatment agreement or state hospital legislation. Key issues include the separation of access between treatment, administration, billing, and research; the integration of practice and hospital information systems; data processing by laboratories and billing service providers; and the question of which analyses still constitute treatment and which already constitute research. In addition, there is the physician's duty of confidentiality, which in some respects goes beyond the requirements of the regulation.
Banking & Insurance
Here, the regulation intersects with supervisory law, which imposes its own retention and documentation requirements. Scoring, fraud detection, and automated individual decision-making under Article 22 require a documented justification and the possibility of human review. At the same time, commercial, tax, and anti-money laundering laws impose restrictions on data erasure: a data retention policy must account for both sets of requirements. In addition, there are outsourcing arrangements with data centres and service providers that must be evaluated in light of both regulatory and data protection requirements.
Retail & E-Commerce
Consent is the linchpin: tracking, retargeting, advertising profiles, newsletters, and customer accounts all stand or fall on proof of who consented to what and when — and on a revocation that actually takes effect. Added to this are payment service providers and shipping service providers acting as data processors, analytics tools with servers located outside the EU, and the retention of order histories, which must be balanced against warranty obligations, tax law, and data minimisation.
Staffing Services & HR
Applicant and employee data are at the core, and employee data protection law establishes a stricter framework than customer data protection. Topics include the retention of applications after rejection, applicant tracking systems and their data processing, time tracking and performance evaluation with the involvement of the works council, as well as company agreements as a separate legal basis. In the case of AI-supported pre-selection, the question of Article 22 and a data protection impact assessment also arises.
Public Administration & Education
Public authorities and educational institutions almost never operate on the basis of consent, but rather on a legal basis provided by sector-specific laws — the main task, therefore, is to map each processing activity to a specific legal provision, including the applicable state data protection act. Added to this are sector-specific case-handling systems with long lifecycles, joint responsibility across levels and governing bodies, record-keeping plans and retention periods under archival law, and — in the case of schools and universities — the processing of data pertaining to minors.
Software & Technology
Here, the perspective is reversed: Providers are usually data processors themselves and must demonstrate data protection as a product feature — data minimisation by design, client segregation, erasure functions, logging, and a list of subcontractors. In practice, what matters is how well the company passes customer questionnaires and audit requests. Added to this are telemetry and product analysis within its own applications, test data from production environments, and the data protection aspects of model training.
The Data Protection Projects Most Often Commissioned
What actually gets commissioned in data protection falls largely into four pictures. Each has a typical starting point, a sequence that has proved itself, and a result that should be named before the start — otherwise the project ends in a folder instead of in a working process.
GDPR Baseline Assessment and Closing the Gaps
Starting point: papers exist but are older than the systems. Approach: record the processing activities, hold them against the existing documentation, order the gaps by risk and effort, work them off. The result is a finding with a ranking and a closed list of the points that have to stand before the next audit or tender.
Building Records of Processing and an Erasure Concept
Starting point: no records of processing activities, or a spreadsheet nobody maintains. Approach: business unit interviews, a system comparison, per processing activity the purpose, legal basis, data categories and recipients, and from that the retention schedule per data category. The result is records of processing activities that match the actual state, plus an erasure rule with a named technical implementation.
Putting Processors and Third-Country Transfers in Order
Starting point: a processor landscape that grew over time, incomplete contracts, transfers never assessed. Approach: survey the providers, establish access and data categories for each, catch up on the contracts, assess the transfers, make sub-processors visible. The result is a register with an assessment per transfer and a list of the contracts that have to be renegotiated.
Rolling Out a New System in Line With the GDPR
Starting point: the selection is under way or the rollout has begun. Approach: fix the processing purpose and the data fields early, settle the legal basis, check whether a DPIA is required, model the role and erasure concept inside the system, and regulate processing on behalf and transfers. The result is a rollout that needs no repair afterwards.
Roles That Staff Data Protection Projects
Which profile a data protection project needs is decided by its cut: an appointment under Article 37 calls for a different person than recording two hundred processing activities or assessing a third-country transfer, and with the move from recording into technical implementation the staffing often changes too. The following six roles are a selection from the Compliance & Legal area — the full overview with every profile and its daily rate sits on the category page.
How a Data Protection Project Moves From Baseline to Routine Operation
The scope and duration of the steps depend on the number of companies, the system landscape, and the status of the existing documentation; the sequence does not: first assess, then justify, then prioritise, then implement. Steps are not skipped — a measure without a specified purpose cannot be defended later on.
1. Record the Processing Activities
2. Check Purpose and Legal Basis
3. Assess and Prioritise the Gaps
4. Draw Up Measures and Documents
5. Build It Into Processes and Systems
6. Check Effectiveness and Hand Over
What Data Protection Consulting Costs: Daily Rates and Budget Ranges
External support in data protection is billed by daily rate with us, not as a fixed project fee. The rate follows from five variables: seniority and audit experience; a legal versus a technical orientation; the sector with its additional rules (healthcare, financial supervision, sector-specific public law); the language requirement where several national subsidiaries are involved; and the role — an appointment under Article 37 with external standing is rated differently from a contribution to the recording work. The ranges below are not an estimate; they stand exactly like that on the role pages of the area.
-
€900 – €1,600 per day
-
€900 – €1,400 per day
-
External Data Protection Officer
€800 – €1,400 per day
-
Freelance Trade Compliance Specialist
€900 – €1,300 per day
-
Freelance Penetration Tester / Ethical Hacker
€850 – €1,300 per day
-
€850 – €1,300 per day
-
Freelance SOC Analyst / Incident Response Specialist
€750 – €1,150 per day
Every range is stated on the matching role page itself, not on request.
How a data protection project can be budgeted. The unit of reference is person-days, not a lump sum. A baseline assessment that reviews the existing papers and holds them against the actual processing activities sits, for a mid-sized estate, in the low double digits of days by experience; building complete records of processing activities together with the retention schedule sits well above that, because it hangs on the number of business units and systems and not on the number of employees. An appointment as external data protection officer, by contrast, does not run through a project budget but through a recurring annual allowance of days — the task does not stop.
What pulls the rate up. Special categories under Article 9, automated individual decision-making, several national subsidiaries under differing national law, a supervisory procedure already under way, or a deadline imposed from outside. What lowers it: an existing and reasonably current baseline, a named internal contact per business unit, and access to the system documentation without a detour.
What we advise against. Commissioning documentation without the baseline underneath it — the result is a paper that does not survive the first follow-up question. And a project without a named internal recipient: data protection is lived in daily work or not at all, and a handover to nobody is no handover.
Which role carries the work is decided by the concrete occasion: an appointment under Article 37 calls for different experience than the technical implementation of an erasure concept. Every profile in the category, each with its task picture and a stated daily rate, is listed on the Compliance & Legal page. If you are unsure which role your occasion needs, we place that in a conversation.
The Bottleneck Is Not the Rule — It Is the Uncertainty About Reading It
97 %
82 %
59 %
Frequently Asked Questions About Data Protection Consulting
Data protection consulting orders the processing of personal data in a company along three questions: what was the data collected for, what does the processing rest on, and when does it end. In practice that means: recording processing activities the way they actually run; naming a legal basis for each one; setting retention and erasure as a period per data category; regulating processors and transfers outside the EU; assigning technical and organisational measures to the risk; and clarifying early for new plans whether a data protection impact assessment is required. The result is not folders but processes, system settings and contracts that hold up to the requirements in daily work.
The duty to appoint follows from the Regulation and, in Germany, additionally from the Federal Data Protection Act. It applies among other things where at least 20 people are permanently occupied with the automated processing of personal data, where processing activities are subject to a data protection impact assessment, or where data is processed commercially for transmission, for anonymised transmission, or for market and opinion research. Public authorities are obliged as a matter of principle. More important than the headcount threshold in practice is the question of compatibility: whoever is responsible for the processing itself — head of IT, head of HR, managing director — must not also monitor it. That is the most common reason to fill the role with an external data protection officer.
Pursuant to Article 30 for each processing operation: the name and contact information of the controller and, if appointed, the data protection officer; the purpose of the processing; the categories of data subjects and the types of data; the recipients to whom the data is disclosed, including processors; transfers to third countries, including the legal basis; the intended retention periods; and a description of the technical and organisational measures. In practice, it is also worthwhile to maintain a record of the systems used and the legal basis for each processing activity — neither of which is explicitly required by law, but both are needed during any audit. It is crucial that the record describes the actual process as it is carried out: if it deviates from this, it is not evidence but rather a dated contradiction.
Where a processing activity is likely to bring a high risk to the rights and freedoms of data subjects. Article 35 names three standard cases: extensive evaluation of personal aspects including profiling as the basis for automated decisions, extensive processing of special categories such as health data, and systematic extensive monitoring of publicly accessible areas. Beyond that, the supervisory authorities keep lists of processing activities for which they require a DPIA. It is worth doing early in the design: then it shapes data fields, access and retention, instead of assessing a decision that has already been taken.
Data security addresses who has access to data and how it is protected against loss and unauthorised access — encryption, access permissions, attack detection, and fault tolerance. Data protection, on the other hand, asks beforehand whether the data is even permitted to exist: for what purpose it was collected, on what legal basis it is processed, and when it must be deleted. The two are intertwined, because the technical and organisational measures under Article 32 are security measures designed to support data protection. But they are not interchangeable: a perfectly encrypted dataset without a legal basis remains unlawful, and a sound legal basis does not protect an unsecured server.
Billing is by daily rate. For the Compliance & Legal area, the ranges stated on our role pages currently run between €750 and €1,600 per day, framed more narrowly per role — an external data protection officer, for instance, between €800 and €1,400. How many days a project needs does not hang on the headcount but on the number of business units and systems, the state of the existing papers, and whether special categories or third-country transfers are in play. A baseline assessment is far smaller than building complete records of processing activities; an appointment under Article 37 does not run through a project budget but through an annual allowance.
On five variables. First, seniority and audit experience — somebody who has accompanied several supervisory procedures is rated differently from somebody with a certificate and little practice. Second, the orientation: legal assessment, technical implementation, or both. Third, the sector with its additional rules, such as state hospital legislation, financial supervision or sector-specific public law. Fourth, the language requirement, as soon as several national subsidiaries with their own national data protection law come in. And fifth, the role: an appointment with external standing towards the supervisory authority carries more responsibility than a contribution to a baseline assessment, and is placed accordingly.
That hangs on the cut, but the order in which the effect appears is stable. Effect shows first where a deadline runs: a practised procedure for access and erasure requests and a working notification route for personal data breaches are quickly established and immediately measurable against the number of deadlines met. After that the baseline takes effect, because it ends the argument inside the company. The implementation into systems takes longest — erasure routines and authorisation models hang on release cycles and on applications that never provided for erasure. Success is measured against checkable figures: the share of processing activities with a named legal basis and retention period, the share of providers with a complete contract and an assessed transfer, deadlines met on data subject requests, and client questionnaires or audits passed.
Excellent. We are not the only ones who think so.
consultingheads has received several awards from leading trade magazines and independent third parties.