A senior, certified DPO acting as your officer of record - registered with the regulator, accountable to your board, and embedded in your day-to-day operations. At a fraction of the cost of a full-time hire.
Under GDPR Article 37, Kenya's DPA (2019) and a growing list of regional laws, many organisations are legally required to designate a DPO. Hiring full-time is expensive; doing nothing is risky. Our retainer model gives you the named officer the law demands and the senior judgement your board needs.
A named, qualified DPO registered with your supervisory authority (ODPC, ICO, CNIL, DPC and others) - meeting Article 37 and equivalent obligations from day one.
Full DPO function from a fraction of a senior salary. No recruitment cycle, no onboarding lag, no single point of failure.
CIPP/E, CIPM and CIPT-certified practitioners who have built programmes for banks, fintechs, hospitals, SaaS scale-ups and public bodies.
An independent DPO without the conflicts of interest that come with internal roles in IT, security or legal.
We bring playbooks, templates and a tested operating rhythm - you start producing evidence in the first month, not the sixth.
One officer, multiple regimes: GDPR, UK GDPR, Kenya DPA, POPIA, LGPD, PIPL and more - mapped to a single control set.
Our retainers map directly to the tasks set out in GDPR Article 39 and the Kenya DPA. Nothing left in a slide deck; everything evidenced.
Initial registration with your supervisory authority, ongoing point-of-contact, and full handling of investigations, audits and complaints.
We run Data Protection Impact Assessments for new products, vendors and cross-border transfers - and brief project teams on lawful design choices before they ship.
A living Record of Processing Activities, internal policies, privacy and cookie notices - reviewed quarterly, not annually.
DSAR, erasure and objection workflows: tooling, SLAs, response templates, and direct handling of escalations.
On-call breach support inside the 72-hour clock, including regulator notifications, communications drafts and post-incident lessons learned.
One vendor inventory, one DPA template set, one renewal calendar - kept current with new sub-processors and cross-border transfer mechanisms.
Role-based privacy training for staff, board briefings, and bespoke sessions for engineering, marketing and customer-success teams.
A quarterly DPO report your board can actually act on - risks, decisions taken, regulator engagement and the metrics that matter.
We engineer the first month so you feel progress immediately - and the regulator sees a credible, named officer the moment paperwork goes in.
A two-week deep dive: data flows, current state, gap analysis against your governing framework, and a prioritised 90-day plan with owners and dates.
We register your designated DPO with the relevant supervisory authority, publish contact details, and announce internally.
A standing rhythm: monthly programme reviews, quarterly board reports, on-demand advice and a shared workspace for live decisions.
New laws, new products, new vendors, new regulators - the programme adapts continuously so you never start from zero again.
There's a time to hire full-time - and a time when a retainer is simply better. Here's how the options stack up.
If any of the following describe you, designating a DPO is no longer optional - and outsourcing is almost always the faster, safer route.
Regulated entities processing financial and special-category data at scale.
Hospitals, providers, EHR vendors and pharma teams handling patient and trial data.
Scale-ups processing customer data across borders or selling into the EU and UK.
Public bodies, donor-funded programmes and NGOs handling citizen and beneficiary data.
Schools, universities and platforms processing minors' data and academic records.
Operators subject to communications metadata, ePrivacy and lawful-access duties.
We can have a named, certified DPO designated and registered with your supervisory authority inside two weeks of signature - and a 90-day plan in front of your board the same week.
Still unclear? Speak to a DPO directly - usually a same-day reply.
Yes. GDPR Article 37(6) explicitly allows the DPO to be a staff member or fulfil the tasks on the basis of a service contract. Kenya's DPA, the UK GDPR and most other modern privacy laws follow the same model. We become the named officer of record, registered with the relevant supervisory authority.
You will be assigned a lead DPO - typically CIPP/E and CIPM certified, with sector experience that matches your business - backed by a bench of privacy counsel, technologists and incident-response specialists. You meet them before you sign.
Retainers start at a few thousand dollars per month for early-stage businesses and scale based on size, sector and number of jurisdictions. Most clients pay 40-70% less than a full-time DPO once recruitment, salary, benefits, training and tooling are accounted for.
Every retainer includes 24x7 incident-response cover inside the 72-hour notification clock. You get a privacy lawyer, an analyst and a communications lead on a single call - with regulator-notification drafts and customer-communications templates ready to file.
Your DPO is independent of your operational teams by design - they report into a governance committee (or directly to the board) and have no decision-making authority in IT, marketing or product. We document the reporting line in your designation letter.
Yes - many clients pair DPO as a Service with our virtual CISO retainer. Two named officers, one team, one operating rhythm. We make sure the roles stay independent where the law requires it.
We design every engagement so you can. We document playbooks, decisions and tooling in your tenancy so an in-house successor can step in with no lift-and-shift. About a third of our clients eventually hire in-house - and we usually help them recruit.
30 minutes, no obligation. We will assess whether a designation is mandatory in your case, and share a fixed-fee proposal the same week.