Extern & flexibel
External & flexible

DPO as a Service

Niet elke organisatie heeft nood aan een fulltime interne DPO - wel aan een vast aanspreekpunt dat de GDPR-verplichtingen mee opvolgt. Als externe DPO neem ik die rol op: flexibel inzetbaar, op afstand of ter plaatse, en afgestemd op de grootte en het risicoprofiel van je organisatie.

Not every organisation needs a full-time in-house DPO - but it does need a fixed point of contact who keeps GDPR obligations on track. As an external DPO, I take on that role: flexibly deployed, remote or on-site, and tailored to the size and risk profile of your organisation.

Voor wie

Who it's for

  • KMO's en scale-ups die onder de GDPR-aanstellingsplicht vallen
  • Overheidsinstanties en publieke sector
  • Zorg-, onderwijs- en welzijnsorganisaties
  • Organisaties die op grote schaal persoonsgegevens verwerken of onder NIS2 vallen
  • SMEs and scale-ups subject to the GDPR DPO-appointment requirement
  • Government bodies and the public sector
  • Healthcare, education and welfare organisations
  • Organisations processing personal data at scale or subject to NIS2

Takenpakket als externe DPO

External DPO scope of work

  • Monitoring van de naleving van GDPR binnen de organisatie
  • Aanspreekpunt voor de Gegevensbeschermingsautoriteit en betrokkenen
  • Advies bij verwerkingen, DPIA's en nieuwe projecten
  • Opleiding en sensibilisering van medewerkers
  • Ondersteuning bij datalekken en incidenten
  • Periodieke rapportering aan directie of bestuur
  • Monitoring GDPR compliance across the organisation
  • Point of contact for the Data Protection Authority and data subjects
  • Advice on processing activities, DPIAs and new projects
  • Staff training and awareness
  • Support during data breaches and incidents
  • Periodic reporting to management or the board
01

Kennismaking

Introductory call

Vrijblijvend gesprek over je organisatie, risicoprofiel en huidige stand van zaken.

A no-obligation conversation about your organisation, risk profile and current status.

02

Nulmeting

Baseline assessment

Analyse van bestaande processen tegenover GDPR-verplichtingen.

Analysis of existing processes against GDPR obligations.

03

Vast aanspreekpunt

Ongoing point of contact

Structurele opvolging op maandelijkse of contractuele basis, op afstand of ter plaatse.

Structured follow-up on a monthly or contractual basis, remote or on-site.

04

Rapportering

Reporting

Periodieke stand van zaken en aanbevelingen naar directie of bestuur.

Periodic status updates and recommendations to management or the board.

Heeft mijn organisatie wettelijk een DPO nodig?

Does my organisation legally need a DPO?

Volgens artikel 37 van de AVG/GDPR is een DPO verplicht voor overheidsinstanties, en voor organisaties die op grote schaal mensen monitoren of gevoelige gegevens verwerken. Voor andere organisaties is er geen wettelijke plicht, maar wél volledige aansprakelijkheid bij inbreuken - vandaar dat een extern aanspreekpunt ook zonder strikte verplichting sterk aan te raden blijft.

Under Article 37 of the GDPR, a DPO is mandatory for public authorities, and for organisations that monitor individuals at scale or process sensitive data at scale. Other organisations have no legal obligation, but remain fully liable in case of breaches - which is why an external point of contact stays strongly advisable even without a strict requirement.

ToepasselijkheidApplicability Wie valt hieronderWho this covers
VerplichtMandatory Overheidsinstanties; organisaties met grootschalige, stelselmatige monitoring van personen; organisaties die op grote schaal gevoelige gegevens verwerken (gezondheid, biometrie, strafrechtelijke gegevens). Public authorities; organisations with large-scale, systematic monitoring of individuals; organisations processing sensitive data at scale (health, biometric, criminal records).
Sterk aan te radenStrongly advisable KMO's en scale-ups met reguliere verwerking van klanten-/personeelsgegevens, of die onder NIS2 vallen - geen wettelijke plicht, wél volledige aansprakelijkheid. SMEs and scale-ups with regular processing of customer/staff data, or subject to NIS2 - no legal obligation, but full liability remains.
Minder van toepassingLess applicable Zeer kleine ondernemingen zonder systematische, grootschalige gegevensverwerking. De AVG blijft wel gelden - enkel de DPO-aanstellingsplicht vervalt. Very small businesses without systematic, large-scale data processing. The GDPR itself still applies - only the DPO-appointment obligation falls away.

Bron: AVG/GDPR, artikel 37. Algemene informatie, geen juridisch advies.

Source: GDPR, Article 37. General information, not legal advice.

Pakketten
Packages

Kies het niveau van ondersteuning dat past

Choose the level of support that fits

Drie vaste pakketten, op te schalen naarmate je organisatie groeit of het risicoprofiel wijzigt. Prijs op maat, op basis van grootte en risicoprofiel - vraag een vrijblijvende offerte aan.

Three fixed packages, scalable as your organisation grows or its risk profile changes. Pricing is tailored to size and risk profile - request a free quote.

Basis

Basic

Advisory op afroep

Advisory on demand

  • Vast aanspreekpunt op afroep
  • Periodiek advies bij verwerkingen & vragen
  • Jaarlijkse check van het verwerkingsregister
  • E-mail- en telefonische ondersteuning
  • Point of contact on demand
  • Periodic advice on processing activities & questions
  • Annual review of the processing register
  • Email and phone support

Geschikt voor: kleine organisaties met een beperkt risicoprofiel

Best for: small organisations with a limited risk profile

Vraag offerte aanRequest a quote

Premium

Premium

Volledige ontzorging

Full-service

  • Alles uit het pakket Uitgebreid
  • Actieve monitoring en interne audits
  • Raakvlakken met NIS2 en ISO 27001
  • Maandelijkse rapportering aan directie of bestuur
  • Prioritaire beschikbaarheid bij incidenten
  • Everything in the Essentials package
  • Active monitoring and internal audits
  • NIS2 and ISO 27001 touchpoints
  • Monthly reporting to management or the board
  • Priority availability during incidents

Geschikt voor: overheid, grotere organisaties en complexe/multi-site omgevingen

Best for: government, larger organisations and complex/multi-site environments

Vraag offerte aanRequest a quote

Onafhankelijke blik, geen belangenconflict, en kostenefficiënter dan een fulltime interne aanwerving - met de certificering (DPO, NIS2 Lead Implementer) en de projectmatige uitvoeringskracht om het ook effectief door de organisatie te trekken.

An independent perspective, no conflict of interest, and more cost-efficient than a full-time in-house hire - backed by certification (DPO, NIS2 Lead Implementer) and the project discipline to actually drive it through the organisation.

Veelgestelde vragen

Frequently asked questions

Vervangt dit mijn interne compliance-medewerker?Does this replace my internal compliance staff?

Niet noodzakelijk. Een externe DPO werkt vaak samen met een intern aanspreekpunt of privacyteam en neemt de wettelijk verplichte DPO-rol op, los van de dagelijkse operationele opvolging.

Not necessarily. An external DPO often works alongside an internal point of contact or privacy team, taking on the legally required DPO role separate from day-to-day operational follow-up.

Werk je op locatie of op afstand?Do you work on-site or remotely?

Beide, in overleg en afhankelijk van de noden van je organisatie. Ik ben actief tot 80 km rondom Mol, en werk daarnaast ook op afstand.

Both, in consultation and depending on your organisation's needs. I'm active within 80 km of Mol, and also work remotely.

Hoe start een traject?How does an engagement start?

Met een vrijblijvend kennismakingsgesprek waarin we je risicoprofiel en verplichtingen bespreken. Daarna volgt een concreet voorstel op maat van je organisatie.

With a no-obligation introductory call to discuss your risk profile and obligations. After that, you'll receive a concrete proposal tailored to your organisation.

Search