DPO as a Service
Niet elke organisatie heeft nood aan een fulltime interne DPO - wel aan een vast aanspreekpunt dat de GDPR-verplichtingen mee opvolgt. Als externe DPO neem ik die rol op: flexibel inzetbaar, op afstand of ter plaatse, en afgestemd op de grootte en het risicoprofiel van je organisatie.
Not every organisation needs a full-time in-house DPO - but it does need a fixed point of contact who keeps GDPR obligations on track. As an external DPO, I take on that role: flexibly deployed, remote or on-site, and tailored to the size and risk profile of your organisation.
Voor wie
Who it's for
- KMO's en scale-ups die onder de GDPR-aanstellingsplicht vallen
- Overheidsinstanties en publieke sector
- Zorg-, onderwijs- en welzijnsorganisaties
- Organisaties die op grote schaal persoonsgegevens verwerken of onder NIS2 vallen
- SMEs and scale-ups subject to the GDPR DPO-appointment requirement
- Government bodies and the public sector
- Healthcare, education and welfare organisations
- Organisations processing personal data at scale or subject to NIS2
Takenpakket als externe DPO
External DPO scope of work
- Monitoring van de naleving van GDPR binnen de organisatie
- Aanspreekpunt voor de Gegevensbeschermingsautoriteit en betrokkenen
- Advies bij verwerkingen, DPIA's en nieuwe projecten
- Opleiding en sensibilisering van medewerkers
- Ondersteuning bij datalekken en incidenten
- Periodieke rapportering aan directie of bestuur
- Monitoring GDPR compliance across the organisation
- Point of contact for the Data Protection Authority and data subjects
- Advice on processing activities, DPIAs and new projects
- Staff training and awareness
- Support during data breaches and incidents
- Periodic reporting to management or the board
Kennismaking
Introductory call
Vrijblijvend gesprek over je organisatie, risicoprofiel en huidige stand van zaken.
A no-obligation conversation about your organisation, risk profile and current status.
Nulmeting
Baseline assessment
Analyse van bestaande processen tegenover GDPR-verplichtingen.
Analysis of existing processes against GDPR obligations.
Vast aanspreekpunt
Ongoing point of contact
Structurele opvolging op maandelijkse of contractuele basis, op afstand of ter plaatse.
Structured follow-up on a monthly or contractual basis, remote or on-site.
Rapportering
Reporting
Periodieke stand van zaken en aanbevelingen naar directie of bestuur.
Periodic status updates and recommendations to management or the board.
Heeft mijn organisatie wettelijk een DPO nodig?
Does my organisation legally need a DPO?
Volgens artikel 37 van de AVG/GDPR is een DPO verplicht voor overheidsinstanties, en voor organisaties die op grote schaal mensen monitoren of gevoelige gegevens verwerken. Voor andere organisaties is er geen wettelijke plicht, maar wél volledige aansprakelijkheid bij inbreuken - vandaar dat een extern aanspreekpunt ook zonder strikte verplichting sterk aan te raden blijft.
Under Article 37 of the GDPR, a DPO is mandatory for public authorities, and for organisations that monitor individuals at scale or process sensitive data at scale. Other organisations have no legal obligation, but remain fully liable in case of breaches - which is why an external point of contact stays strongly advisable even without a strict requirement.
| Toepasselijkheid | Applicability | Wie valt hieronder | Who this covers |
|---|---|---|---|
| VerplichtMandatory | Overheidsinstanties; organisaties met grootschalige, stelselmatige monitoring van personen; organisaties die op grote schaal gevoelige gegevens verwerken (gezondheid, biometrie, strafrechtelijke gegevens). | Public authorities; organisations with large-scale, systematic monitoring of individuals; organisations processing sensitive data at scale (health, biometric, criminal records). | |
| Sterk aan te radenStrongly advisable | KMO's en scale-ups met reguliere verwerking van klanten-/personeelsgegevens, of die onder NIS2 vallen - geen wettelijke plicht, wél volledige aansprakelijkheid. | SMEs and scale-ups with regular processing of customer/staff data, or subject to NIS2 - no legal obligation, but full liability remains. | |
| Minder van toepassingLess applicable | Zeer kleine ondernemingen zonder systematische, grootschalige gegevensverwerking. De AVG blijft wel gelden - enkel de DPO-aanstellingsplicht vervalt. | Very small businesses without systematic, large-scale data processing. The GDPR itself still applies - only the DPO-appointment obligation falls away. |
Bron: AVG/GDPR, artikel 37. Algemene informatie, geen juridisch advies.
Source: GDPR, Article 37. General information, not legal advice.
Kies het niveau van ondersteuning dat past
Choose the level of support that fits
Drie vaste pakketten, op te schalen naarmate je organisatie groeit of het risicoprofiel wijzigt. Prijs op maat, op basis van grootte en risicoprofiel - vraag een vrijblijvende offerte aan.
Three fixed packages, scalable as your organisation grows or its risk profile changes. Pricing is tailored to size and risk profile - request a free quote.
Basis
Basic
Advisory op afroep
Advisory on demand
- Vast aanspreekpunt op afroep
- Periodiek advies bij verwerkingen & vragen
- Jaarlijkse check van het verwerkingsregister
- E-mail- en telefonische ondersteuning
- Point of contact on demand
- Periodic advice on processing activities & questions
- Annual review of the processing register
- Email and phone support
Geschikt voor: kleine organisaties met een beperkt risicoprofiel
Best for: small organisations with a limited risk profile
Vraag offerte aanRequest a quoteUitgebreid
Essentials
Aangestelde externe DPO
Named external DPO
- Aanstelling als externe DPO bij de toezichthouder
- Opvolging verwerkingsregister & begeleiding bij DPIA's
- Opleiding en sensibilisering van medewerkers
- Ondersteuning bij datalekken en incidenten
- Kwartaalrapportering aan directie
- Appointment as external DPO with the supervisory authority
- Processing register follow-up & DPIA guidance
- Staff training and awareness
- Support during data breaches and incidents
- Quarterly reporting to management
Geschikt voor: kmo's en scale-ups met reguliere gegevensverwerking
Best for: SMEs and scale-ups with regular data processing
Vraag offerte aanRequest a quotePremium
Premium
Volledige ontzorging
Full-service
- Alles uit het pakket Uitgebreid
- Actieve monitoring en interne audits
- Raakvlakken met NIS2 en ISO 27001
- Maandelijkse rapportering aan directie of bestuur
- Prioritaire beschikbaarheid bij incidenten
- Everything in the Essentials package
- Active monitoring and internal audits
- NIS2 and ISO 27001 touchpoints
- Monthly reporting to management or the board
- Priority availability during incidents
Geschikt voor: overheid, grotere organisaties en complexe/multi-site omgevingen
Best for: government, larger organisations and complex/multi-site environments
Vraag offerte aanRequest a quoteOnafhankelijke blik, geen belangenconflict, en kostenefficiënter dan een fulltime interne aanwerving - met de certificering (DPO, NIS2 Lead Implementer) en de projectmatige uitvoeringskracht om het ook effectief door de organisatie te trekken.
An independent perspective, no conflict of interest, and more cost-efficient than a full-time in-house hire - backed by certification (DPO, NIS2 Lead Implementer) and the project discipline to actually drive it through the organisation.
Veelgestelde vragen
Frequently asked questions
Vervangt dit mijn interne compliance-medewerker?Does this replace my internal compliance staff?
Niet noodzakelijk. Een externe DPO werkt vaak samen met een intern aanspreekpunt of privacyteam en neemt de wettelijk verplichte DPO-rol op, los van de dagelijkse operationele opvolging.
Not necessarily. An external DPO often works alongside an internal point of contact or privacy team, taking on the legally required DPO role separate from day-to-day operational follow-up.
Werk je op locatie of op afstand?Do you work on-site or remotely?
Beide, in overleg en afhankelijk van de noden van je organisatie. Ik ben actief tot 80 km rondom Mol, en werk daarnaast ook op afstand.
Both, in consultation and depending on your organisation's needs. I'm active within 80 km of Mol, and also work remotely.
Hoe start een traject?How does an engagement start?
Met een vrijblijvend kennismakingsgesprek waarin we je risicoprofiel en verplichtingen bespreken. Daarna volgt een concreet voorstel op maat van je organisatie.
With a no-obligation introductory call to discuss your risk profile and obligations. After that, you'll receive a concrete proposal tailored to your organisation.