Organising Data Protection for the Long Term and in Practice

Data protection requires clear responsibilities, transparent processes and continuous support in day-to-day operations.

Prof. Dr. Frank Tapella supports companies, organisations and public authorities as a certified Data Protection Officer (TÜV) in establishing, reviewing and continuously maintaining a GDPR-compliant data protection organisation – personally, practically and with a dedicated contact person.

Requirements and Circumstances

When Is a Data Protection Officer Required or Advisable?

Statutory Appointment Requirement

Appointment may be required in particular where, as a rule, at least 20 persons continuously process personal data by automated means or where a data protection impact assessment is required.

Specific Processing Activities

A requirement may apply regardless of the number of employees where the core activities involve extensive regular and systematic monitoring or the large-scale processing of particularly protected categories of data.

Limited Internal Resources

An external Data Protection Officer relieves companies, organisations and public authorities where sufficient internal capacity or specialised expertise is not available.

Ongoing Support

Services as an External Data Protection Officer

We support you in establishing a reliable data protection organisation and provide ongoing support for your company’s data protection requirements in day-to-day operations.

Organisation

Support the Establishment and Development of Your Data Protection Organisation

Support with establishing, reviewing and developing a transparent data protection organisation with clear responsibilities, processes and documentation.

Advice

Advise Management and Employees

Personal advice on data protection matters, new projects, internal processes and the legally compliant handling of personal data.

Review

Review Processing Activities and Contracts

Data protection review of business processes, digital applications, service providers, data processing agreements and other activities involving personal data.

Communication

Support Requests from Authorities and Data Subjects

Support with access, deletion and other data subject requests as well as communication with data protection supervisory authorities.

Awareness

Inform and Train Employees

Practical training and guidance for employees so that data protection requirements are understood in day-to-day work and implemented reliably.

Development

Regularly Monitor Compliance and Recommend Improvements

Regular review of existing measures and ongoing support with organisational, technical or legal changes within the company.

Personal Support

How We Work Together

From the initial assessment to ongoing support, our cooperation follows four clear steps.

  1. Initial Consultation and Needs Assessment

    We discuss your company structure, existing data protection processes and your specific support requirements.

  2. Proposal and Appointment

    Based on the information you provide, you will receive an individual proposal. Once instructed, the formal appointment takes place; the required contact details are published and communicated to the competent supervisory authority.

  3. Review the Data Protection Organisation

    Existing documentation, responsibilities and processes are reviewed, prioritised and, where necessary, developed further in a structured manner.

  4. Ongoing Personal Support

    You have a dedicated contact person for data protection matters, new projects and the continuous development of your organisation.

Direct Contact

Are You Looking for an External Data Protection Officer?

Book an appointment directly for an initial assessment or briefly describe your industry, company size and number of employees.

  • Confidential assessment
  • Quick initial assessment
  • External DPO support

Online appointment for an initial assessment

Book an appointment

Your information will be treated confidentially.

Prof. Dr. Frank Tapella

Prof. Dr. Frank Tapella>19 Beiträge