Current language: English
Models of Collaboration
Support for growth strategies, transformations or M&A processes.
Our freelance experts have in-depth specialist knowledge in their field.
We provide you with experienced interim managers who take on responsibility.
Customized expert teams for complex projects
We find the best experts for these companies
Private equity
Efficient support throughout the deal cycle
Corporates
Technical and management experts for operational excellence
Scale-ups
Strategic & operational support for growth
Scope and Delineation

What Data Protection Consulting Delivers — and What It Does Not

Two colleagues checking processing activities and their legal bases on screen

Data protection consulting — also called data privacy consulting, GDPR consulting or advice on a data protection management system — puts every processing activity to three questions. Is it named what the data was collected for? Is it settled what the processing rests on? Is it fixed when it ends? Purpose, legal basis, retention period. If any one of the three is missing, the rest of the documentation is a facade. And the yardstick is not the volume of data but the purpose: ten fields without a named purpose are a problem, two hundred fields with a legal basis that holds and a retention period that has been set are not.

The practical work follows from that. Record processing activities the way they actually run. Name a legal basis for each one — performance of a contract, legal obligation, legitimate interests with a documented balancing test, consent — and where none holds, change the processing instead of rewriting its description. Set retention and erasure as a period per data category, not as an intention. Underpin processors with a data processing agreement, documented instructions and a transfer assessment. Describe technical and organisational measures so that an auditor can follow them against reality. And for new plans, decide early whether a data protection impact assessment is required.

Two confusions cost time again and again. The first: data protection is not data security. Security asks who can reach the data; data protection asks beforehand whether it may be there at all. Encryption, an access model and attack detection belong to cyber security consulting and replace no legal basis. The second: data protection is part of compliance but not the whole of it — whistleblower protection, sanctions law, supply chain due diligence and the internal control system run in compliance consulting and follow other bodies of rules.

And what data protection consulting does not deliver: it is a design question, not an audit question. That is the case for privacy by design — the decision is taken while a process or a system is being designed, over which fields are collected, which interface passes them on, how long a record stays. Whoever reviews only at the end can document what already runs, or rebuild it expensively. It also replaces neither legal representation in proceedings nor an assurance that one reading of the law will hold before every supervisory authority: data protection law is open to interpretation, and what carries weight is a reasoned, documented decision rather than a guarantee. And it does not take responsibility off the management — that stays with the controller within the meaning of the Regulation.

Occasions

When External Support on Data Privacy Questions Is Worth It

Many data protection questions are settled faster in-house. If the processing is known, the legal basis undisputed and somebody on the payroll has both the time and the subject knowledge, nobody from outside is needed. The occasions below turn out differently, and for a structural reason: a company decides the same data protection question once and lives with the answer for years. Whoever decides that same question regularly for different clients knows the readings that have held in an audit — and the ones that have not.

1. A New System Is Meant to Process Personal Data

  • The selection process is underway, the business unit is pressing for a decision, and the questions regarding the legal basis and retention period remain unresolved.
  • Once the contract is signed, there's no more room for flexibility: data fields, interfaces, and retention periods become product features.
  • A preliminary review with a clear "yes" or "no" regarding the DPIA costs a fraction of what a later overhaul would cost.

2. A Client or Auditor Asks for Evidence

  • Tenders and corporate clients ask for the records of processing activities, the description of technical and organisational measures, the erasure concept and the data processing agreements.
  • Existing papers are often older than the systems they describe — and the contradiction is spotted by the other side, not by your own team.
  • What counts in a GDPR audit is a version that matches the current state, not a template pulled off the internet.

3. Data Subject Rights Are Running to a Deadline

  • Access, Erasure, rectification, portability: The one-month period begins upon receipt of the request, not upon clarification of responsibility.
  • Without a fixed procedure, designated responsibility, and knowledge of where the data is located, every request becomes a case-by-case matter.
  • A well-established process prevents complaints arising from missed deadlines.

4. Processors and Third-Country Transfers Are Unsettled

  • Cloud services, analytics tools, support from abroad, subcontractors of subcontractors.
  • Data processing agreements are missing, incomplete, or fail to name sub-processors whose access has existed for a long time.
  • Assessing a transfer takes practice with the standard contractual clauses and the supplementary measures that go with them.

5. The Data Protection Officer Role Is Vacant or Overloaded

  • The threshold for a mandatory appointment is met, the succession is open, or the task hangs on one person who carries it alongside their actual job.
  • An internal candidate frequently collides with the bar on self-monitoring — head of IT, head of HR and the managing director are all ruled out.
  • An external data protection officer resolves that incompatibility and brings cases from other companies along.

6. Something Has Gone Wrong or a Supervisory Authority Is Asking

  • A misdirected email, open folders, lost devices, attacks involving data breaches — you have 72 hours to report them.
  • During this time, the facts of the incident, the data subjects concerned, the risk, and countermeasures must be described in a reliable manner.
  • Anyone who has handled this multiple times can distinguish between incidents that require reporting and those that require documentation.

Do any of these occasions sound familiar? A brief conversation is all it takes to get a preliminary idea: which process should be addressed first, what information is missing — and whether outside help is needed at all.

Regulated Fields

The Regulated Fields of GDPR Consulting: From Legal Basis to Erasure

The six regulated fields can be commissioned one at a time, but they all rest on the same foundation: the stock of processing activities. Whoever starts with the measures without knowing which processing activities exist may end up securing data that should never have been collected. As a rule it therefore starts with fields one and two and grows from there into the neighbouring ones.

Legal Bases and Purpose Limitation

A sound legal basis for every processing activity: performance of a contract, legal obligation, legitimate interest with a documented balancing test, or consent. In addition, there is the principle of purpose limitation — the purpose for which the data was collected and what may still be derived from it. Special categories under Article 9 (health, trade union membership, biometrics) require separate authorisation. The result is a specified legal basis for each processing operation and, where none applies, a proposed change to the process rather than to the description.

Records of Processing Activities

The records of processing activities under Article 30 are the map everything else is built on: processing activity, purpose, data categories, groups of data subjects, recipients, retention periods, systems. What gets recorded is the process as it is lived, gathered in interviews with the business units and held against the system landscape. Records that do not follow the actual process are not evidence but a dated contradiction. They are kept current through a fixed occasion, not through good intentions.

Processors and Third-Country Transfers

Every provider with access to personal data needs a data processing agreement under Article 28, a documented set of instructions, and a check that actually takes place. Where processing happens outside the EU, the transfer assessment comes on top: adequacy decision, standard contractual clauses, supplementary measures. The most common finding is sub-processors who are absent from the contract but have had technical access for a long time. The result is a current processor register with an assessment for each transfer.

Technical and Organisational Measures

Technical and organisational measures mean: role and permission framework, encryption, logging, separation of environments, erasure routines, employee obligations, and training. These elements are described in a way that allows an auditor to verify them against reality — including the person responsible and the location where evidence can be found. Technical hardening itself comes from the field of IT security; here, the focus is on aligning measures with the risks associated with data processing and determining whether the measures are actually effective in everyday practice.

Data Subject Rights and Erasure Concept

Right of access, rectification, erasure, restriction, data portability, and objection — each right requires a process that includes a channel for submission, designated responsibility, identity verification, and a deadline. The erasure concept specifies, for each data type, when data is to be deleted and what must be retained beforehand in accordance with commercial or tax law. The difficult part is not the rule itself, but its implementation in systems that were not designed to handle erasure. The result is a retention schedule with a technical implementation trail.

DPIA and New Systems

Ahead of every high-risk plan — extensive profiling, systematic monitoring, health data, AI-assisted evaluation — stands the question of whether a data protection impact assessment (DPIA) under Article 35 is required. It describes the processing, its necessity, the risks to data subjects and the measures that lower those risks. It is useful early: as a design tool that shapes data fields and retention alongside everything else, not as a form filled in after sign-off.

Which regulated field carries the most weight for you can be placed roughly in a short conversation — together with the honest answer on whether a project of its own is worth it.

Engagement Routes

How External Data Protection Expertise Is Brought In — Up to DPO as a Service

In data protection it is the role, alongside subject depth, that decides: whoever rejects a legal basis has to defend that in front of the business unit, IT and the managing director — and, in the case of an appointment under Article 37, in front of the supervisory authority as well. Four routes are common, and they differ above all in how much decision-making weight comes with them.

Assessment

Baseline Assessment of Your Data Protection Standing

A specialist with a specific assignment: reviewing the existing documentation, comparing it with the actual work performed, and identifying gaps in order of priority. The result is a written report outlining priorities and an assessment of which tasks can be handled in-house. No additional structure is provided.

Appointment

Appointment as External Data Protection Officer

Also known as DPO as a service: the role under Article 37 is filled from outside — monitoring compliance, advising the business units, training, and acting as the point of contact for data subjects and the supervisory authority. Filling it externally resolves the bar on self-monitoring that rules out internal candidates from IT, HR and the management, and it brings cases from other companies along.

Added Capacity

Delivery Capacity Inside Your Own Team

Extra hands for the work that keeps being left: recording the processing activities, catching up on data processing agreements, setting retention periods per data category, working through requests from data subjects. The internal data protection officer keeps the role and the decision; the capacity is what gets added.

Programme Steering

Steering a Data Protection Programme

Where several legal entities, systems or national laws come together, somebody has to run the project: cutting work packages, coordinating business units and IT, preparing decisions, and representing the state of play to the management and to auditors.

Sectors and Data Categories

Which Personal Data Sets the Pace in Which Sector

Data protection cannot be set up in a sector-neutral way, because the data categories themselves are the sector. In a hospital, health data is at the centre; Article 9 requires a separate condition for it and state hospital legislation adds its own requirements, and the separation of access between treatment, administration and research is the central question there. At banks and insurers, the Regulation meets a dense body of supervisory law: scoring and automated individual decision-making need a justification that convinces the sector regulator too, while retention duties under commercial and anti-money-laundering law limit erasure. In retail and e-commerce, consent decides: tracking, advertising profiles, customer accounts and newsletters stand or fall on proof of who consented to what and when. In staffing services and the HR field, applicant and employee data are the core, together with works council co-determination and the question of how long an application may stay after a rejection. Public administration and educational institutions almost never work with consent but with a legal basis in sector-specific law — there, mapping each processing activity to a provision is the main work. And at software and technology companies the perspective reverses: they are usually processors themselves, have to demonstrate data protection as a product feature, and have to pass their clients' questionnaires.

We staff by sector experience, not by subject knowledge alone: whoever knows the case-handling systems of a municipality, the audit practice of a state supervisory authority or the client questionnaires of a software vendor does not reopen the argument about interpretation, but brings along the version that has already held there.

Hospital staff discussing health data on a tablet

Healthcare & Hospitals

Meeting on customer data and scoring at a financial institution

Banking & Insurance

Card payment on a laptop — customer data in e-commerce

Retail & E-Commerce

Employee data being captured on a tablet on the move

Staffing Services & HR

A case-handling procedure in public administration: a document is stamped

Public Administration & Education

Digital services of a technology company on a laptop

Software & Technology

Hospital staff discussing health data on a tablet

Healthcare & Hospitals

Meeting on customer data and scoring at a financial institution

Banking & Insurance

Card payment on a laptop — customer data in e-commerce

Retail & E-Commerce

Employee data being captured on a tablet on the move

Staffing Services & HR

A case-handling procedure in public administration: a document is stamped

Public Administration & Education

Digital services of a technology company on a laptop

Software & Technology

Delivery Patterns

The Data Protection Projects Most Often Commissioned

What actually gets commissioned in data protection falls largely into four pictures. Each has a typical starting point, a sequence that has proved itself, and a result that should be named before the start — otherwise the project ends in a folder instead of in a working process.

GDPR Baseline Assessment and Closing the Gaps

Starting point: papers exist but are older than the systems. Approach: record the processing activities, hold them against the existing documentation, order the gaps by risk and effort, work them off. The result is a finding with a ranking and a closed list of the points that have to stand before the next audit or tender.

Building Records of Processing and an Erasure Concept

Starting point: no records of processing activities, or a spreadsheet nobody maintains. Approach: business unit interviews, a system comparison, per processing activity the purpose, legal basis, data categories and recipients, and from that the retention schedule per data category. The result is records of processing activities that match the actual state, plus an erasure rule with a named technical implementation.

Putting Processors and Third-Country Transfers in Order

Starting point: a processor landscape that grew over time, incomplete contracts, transfers never assessed. Approach: survey the providers, establish access and data categories for each, catch up on the contracts, assess the transfers, make sub-processors visible. The result is a register with an assessment per transfer and a list of the contracts that have to be renegotiated.

Rolling Out a New System in Line With the GDPR

Starting point: the selection is under way or the rollout has begun. Approach: fix the processing purpose and the data fields early, settle the legal basis, check whether a DPIA is required, model the role and erasure concept inside the system, and regulate processing on behalf and transfers. The result is a rollout that needs no repair afterwards.

Data Protection Profiles

Roles That Staff Data Protection Projects

Which profile a data protection project needs is decided by its cut: an appointment under Article 37 calls for a different person than recording two hundred processing activities or assessing a third-country transfer, and with the move from recording into technical implementation the staffing often changes too. The following six roles are a selection from the Compliance & Legal area — the full overview with every profile and its daily rate sits on the category page.

How a Data Protection Project Moves From Baseline to Routine Operation

The scope and duration of the steps depend on the number of companies, the system landscape, and the status of the existing documentation; the sequence does not: first assess, then justify, then prioritise, then implement. Steps are not skipped — a measure without a specified purpose cannot be defended later on.

Processing activities recorded in business unit interviews

1. Record the Processing Activities

Business unit interviews and system reconciliation: what personal data is generated where, where it flows, and who has access to it.
What is recorded is the actual sequence of events, not the documented one — the difference is usually the actual finding.
The result is a list of processing activities that are no longer a point of contention within the company.
The purpose and legal basis of a processing activity are checked

2. Check Purpose and Legal Basis

Per processing activity: what it was collected for, what the processing rests on, how long it may run.
A legitimate interest requires a documented assessment, while consent requires proof and an effective revocation.
Where a foundation is missing, the implementation is changed — not its description.
Data protection gaps ordered by risk and effort

3. Assess and Prioritise the Gaps

Every gap is given a risk for the data subjects and an effort for the company — the ranking follows from that.
Items that must be reported and have deadlines are listed first; cosmetic documentation is listed last.
The result is a plan that fits within the available capacity, rather than a list that never gets implemented.
Data protection documents and measures being drawn up

4. Draw Up Measures and Documents

Records of processing activities, retention schedule, description of technical and organisational measures, data processing agreements, a data subject rights procedure, and where needed the DPIA.
Each document is assigned a person in charge, a location where it is kept, and an occasion for its update.
Templates are adapted, not adopted — an outside template describes somebody else's company.
Retention periods and permissions implemented in systems

5. Build It Into Processes and Systems

Data retention periods in the systems, permissions in the roles, proof of consent in the customer process, reporting procedures in the operational workflow.
Employees are trained where they are decision-makers — not with the same set of slides across the board.
Only here does the difference appear between a folder and an organisation that actually carries data protection.
The effectiveness of data protection measures checked by spot check

6. Check Effectiveness and Hand Over

Spot checks instead of self-declaration: is data really erased, does a withdrawal of consent take effect, does the check at the processor actually happen.
The update trigger is set — new system, new service provider, new process.
Hand over to the internal role, including what remains open and how it will be resolved.
Daily Rates

What Data Protection Consulting Costs: Daily Rates and Budget Ranges

External support in data protection is billed by daily rate with us, not as a fixed project fee. The rate follows from five variables: seniority and audit experience; a legal versus a technical orientation; the sector with its additional rules (healthcare, financial supervision, sector-specific public law); the language requirement where several national subsidiaries are involved; and the role — an appointment under Article 37 with external standing is rated differently from a contribution to the recording work. The ranges below are not an estimate; they stand exactly like that on the role pages of the area.

Every range is stated on the matching role page itself, not on request.

How a data protection project can be budgeted. The unit of reference is person-days, not a lump sum. A baseline assessment that reviews the existing papers and holds them against the actual processing activities sits, for a mid-sized estate, in the low double digits of days by experience; building complete records of processing activities together with the retention schedule sits well above that, because it hangs on the number of business units and systems and not on the number of employees. An appointment as external data protection officer, by contrast, does not run through a project budget but through a recurring annual allowance of days — the task does not stop.

What pulls the rate up. Special categories under Article 9, automated individual decision-making, several national subsidiaries under differing national law, a supervisory procedure already under way, or a deadline imposed from outside. What lowers it: an existing and reasonably current baseline, a named internal contact per business unit, and access to the system documentation without a detour.

What we advise against. Commissioning documentation without the baseline underneath it — the result is a paper that does not survive the first follow-up question. And a project without a named internal recipient: data protection is lived in daily work or not at all, and a handover to nobody is no handover.

Which role carries the work is decided by the concrete occasion: an appointment under Article 37 calls for different experience than the technical implementation of an erasure concept. Every profile in the category, each with its task picture and a stated daily rate, is listed on the Compliance & Legal page. If you are unsure which role your occasion needs, we place that in a conversation.

Survey Findings

The Bottleneck Is Not the Rule — It Is the Uncertainty About Reading It

97 %

of companies describe their data protection workload as high — 44% even as very high.
Bitkom, Study on Data Protection in the German Economy (2026)

82 %

name uncertainty about the exact data protection requirements as one of their biggest challenges. It is not the rule that is missing, but a reading of it that holds.
Bitkom, Study on Data Protection in the German Economy (2026)

59 %

report that projects around data holdings for AI have failed on data protection requirements or were never started at all.
Bitkom, Study on Data Protection in the German Economy (2026)
Questions and Answers

Frequently Asked Questions About Data Protection Consulting

Data protection consulting orders the processing of personal data in a company along three questions: what was the data collected for, what does the processing rest on, and when does it end. In practice that means: recording processing activities the way they actually run; naming a legal basis for each one; setting retention and erasure as a period per data category; regulating processors and transfers outside the EU; assigning technical and organisational measures to the risk; and clarifying early for new plans whether a data protection impact assessment is required. The result is not folders but processes, system settings and contracts that hold up to the requirements in daily work.

The duty to appoint follows from the Regulation and, in Germany, additionally from the Federal Data Protection Act. It applies among other things where at least 20 people are permanently occupied with the automated processing of personal data, where processing activities are subject to a data protection impact assessment, or where data is processed commercially for transmission, for anonymised transmission, or for market and opinion research. Public authorities are obliged as a matter of principle. More important than the headcount threshold in practice is the question of compatibility: whoever is responsible for the processing itself — head of IT, head of HR, managing director — must not also monitor it. That is the most common reason to fill the role with an external data protection officer.

Pursuant to Article 30 for each processing operation: the name and contact information of the controller and, if appointed, the data protection officer; the purpose of the processing; the categories of data subjects and the types of data; the recipients to whom the data is disclosed, including processors; transfers to third countries, including the legal basis; the intended retention periods; and a description of the technical and organisational measures. In practice, it is also worthwhile to maintain a record of the systems used and the legal basis for each processing activity — neither of which is explicitly required by law, but both are needed during any audit. It is crucial that the record describes the actual process as it is carried out: if it deviates from this, it is not evidence but rather a dated contradiction.

Where a processing activity is likely to bring a high risk to the rights and freedoms of data subjects. Article 35 names three standard cases: extensive evaluation of personal aspects including profiling as the basis for automated decisions, extensive processing of special categories such as health data, and systematic extensive monitoring of publicly accessible areas. Beyond that, the supervisory authorities keep lists of processing activities for which they require a DPIA. It is worth doing early in the design: then it shapes data fields, access and retention, instead of assessing a decision that has already been taken.

Data security addresses who has access to data and how it is protected against loss and unauthorised access — encryption, access permissions, attack detection, and fault tolerance. Data protection, on the other hand, asks beforehand whether the data is even permitted to exist: for what purpose it was collected, on what legal basis it is processed, and when it must be deleted. The two are intertwined, because the technical and organisational measures under Article 32 are security measures designed to support data protection. But they are not interchangeable: a perfectly encrypted dataset without a legal basis remains unlawful, and a sound legal basis does not protect an unsecured server.

Billing is by daily rate. For the Compliance & Legal area, the ranges stated on our role pages currently run between €750 and €1,600 per day, framed more narrowly per role — an external data protection officer, for instance, between €800 and €1,400. How many days a project needs does not hang on the headcount but on the number of business units and systems, the state of the existing papers, and whether special categories or third-country transfers are in play. A baseline assessment is far smaller than building complete records of processing activities; an appointment under Article 37 does not run through a project budget but through an annual allowance.

On five variables. First, seniority and audit experience — somebody who has accompanied several supervisory procedures is rated differently from somebody with a certificate and little practice. Second, the orientation: legal assessment, technical implementation, or both. Third, the sector with its additional rules, such as state hospital legislation, financial supervision or sector-specific public law. Fourth, the language requirement, as soon as several national subsidiaries with their own national data protection law come in. And fifth, the role: an appointment with external standing towards the supervisory authority carries more responsibility than a contribution to a baseline assessment, and is placed accordingly.

That hangs on the cut, but the order in which the effect appears is stable. Effect shows first where a deadline runs: a practised procedure for access and erasure requests and a working notification route for personal data breaches are quickly established and immediately measurable against the number of deadlines met. After that the baseline takes effect, because it ends the argument inside the company. The implementation into systems takes longest — erasure routines and authorisation models hang on release cycles and on applications that never provided for erasure. Success is measured against checkable figures: the share of processing activities with a named legal basis and retention period, the share of providers with a complete contract and an assessed transfer, deadlines met on data subject requests, and client questionnaires or audits passed.

You can rely on us

Excellent. We are not the only ones who think so.

consultingheads has received several awards from leading trade magazines and independent third parties.

Award for consultingheads: F.A.Z. Institut TOP Berater 2026
Award for consultingheads: kununu Top Company 2025
Award for consultingheads: brand eins Beste Unternehmensberater 2025
Award for consultingheads: kununu Top Company 2024
Award for consultingheads: brand eins Beste Unternehmensberater 2024
Award for consultingheads: kununu Top Company 2023
Award for consultingheads: brand eins Beste Berater 2019
Award for consultingheads: brand eins Beste Unternehmensberater 2021
Award for consultingheads: brand eins Beste Unternehmensberater 2020
Award for consultingheads: brand eins Beste Unternehmensberater 2026
Award for consultingheads: F.A.Z. Institut TOP Berater 2026
Award for consultingheads: kununu Top Company 2025
Award for consultingheads: brand eins Beste Unternehmensberater 2025
Award for consultingheads: kununu Top Company 2024
Award for consultingheads: brand eins Beste Unternehmensberater 2024
Award for consultingheads: kununu Top Company 2023
Award for consultingheads: brand eins Beste Berater 2019
Award for consultingheads: brand eins Beste Unternehmensberater 2021
Award for consultingheads: brand eins Beste Unternehmensberater 2020
Award for consultingheads: brand eins Beste Unternehmensberater 2026
bildmarke
brand eins Best Management Consultants 2026 - consultingheads
Get in Touch

Let us sort out your processing activities.

Twenty minutes to place where your data protection stands
One named first processing activity and the paper that is missing for it
Matching profiles from Compliance & Legal with a stated daily rate
Twenty minutes in which we place your occasion and name the processing activity that should be taken on first — and whether our network holds the matching profile for it.