Your outsourced DPO, provided by a law firm.

Our firm is appointed as your data protection officer. We keep your GDPR compliance up to date over time and act as your contact point with the CNPD.

From €600 excl. VAT per month.

Fixed monthly price, set according to your needs: volume and sensitivity of your processing.

Obligations

Do you need a DPO?

Appointment is mandatory if:

  • you are a public authority or body;
  • your core activities involve regular and systematic monitoring of individuals on a large scale;
  • your core activities involve large-scale processing of sensitive data (such as health data) or data relating to criminal convictions.

It is often useful even when not mandatory:

  • your major clients expect a named data protection contact;
  • tenders ask for proof of compliance;
  • an investor or a buyer will review your compliance;
  • you want a professional to handle the topic for you, over time.

The DPO’s work

What your DPO does, in practice.

  • Formal appointment

    We handle the procedure and notify our DPO details to the CNPD.

  • Contact point

    We become the contact for the CNPD and for the people whose data you process.

  • Up-to-date record of processing

    Your record follows your business as it evolves. We update it, you approve it.

  • GDPR advice

    New tool, new supplier, new marketing campaign: you consult us before launching.

  • Impact assessments

    We give our opinion on your data protection impact assessments when processing is high-risk.

  • Data subject requests

    Access, rectification, erasure: we prepare compliant answers, on time.

  • Data breaches

    We assess the incident, prepare the notification to the CNPD within 72 hours and the communication to the people concerned where required.

  • Regulatory monitoring

    GDPR, the EU Artificial Intelligence Act, the NIS2 directive: we flag what affects you.

  • Regular compliance reviews

    A periodic review of your compliance and the actions to take.

Pricing

A fixed price, set for your needs.

Every company processes data differently. We review your situation, then send you a written proposal with a fixed monthly price, before any commitment. No overruns, no meter running.

What affects the price

  • the number and nature of your processing activities;
  • the sensitivity of the data processed (health, profiling, HR data);
  • the size of your company;
  • your processors and any transfers outside the European Union;
  • your starting level of compliance.

How it works

From getting compliant to staying compliant.

  1. 01

    Getting compliant

    If your compliance still needs building, we start with an audit of your processing, then draft your record, policies and privacy notices, review your processor agreements and train your teams. This stage is a fixed-fee project, priced upfront.

  2. 02

    Ongoing support from your DPO

    We are then appointed as your DPO and keep your compliance on track over time.

Already compliant? The DPO service can start straight away, after a review of what you have in place.

Why us

Why entrust this role to a law firm.

Professional secrecy

Your exchanges with your DPO are covered by lawyers’ professional secrecy.

A complete legal view

Processor agreements, transfer clauses, client relationships: data protection runs through your contracts, and we draft them.

Defence when it matters

In the event of an inspection or a dispute, the team that knows your compliance is also the one that can defend you.

Built-in independence

An external DPO has no conflict of interest with your internal roles, as the GDPR requires.

Combining services

DPO and legal subscription: complete cover.

The DPO service covers the data protection officer role. The legal subscription covers the rest of your company’s legal needs: contracts, employment law, trademarks, pre-litigation. The two work together.

Explore the legal subscription

Frequently asked questions

Your questions about the outsourced DPO.

Is the DPO responsible for our compliance?

The DPO advises, monitors and alerts. Legal responsibility stays with your company, as the data controller. Our role is to get you compliant, keep you compliant and warn you as soon as a risk appears.

How long does it take to become compliant?

The timeline depends on the volume of your processing. We always tackle the highest risks first.

Do you work with healthcare organisations?

Yes. Health data is among the most sensitive. Our medical law practice works alongside our GDPR team on these matters.

Do you work in English?

Yes. We support our clients in French and English.

Contact

Hand your GDPR over to us.

Describe your business in a few lines. We will come back to you with a fixed-price proposal.

Write to us or call us

Describe your situation in a few lines: a lawyer will reply within the business day.

Or by email: info@infuero.lu