In-House vs Outsourced DPO: How to Decide
Decide between an in-house and an outsourced DPO by working the independence question first and the budget question second. Article 38 forbids the DPO from holding any role that creates a conflict of interest, which disqualifies most of the people a company would naturally appoint: the CEO, the CTO, the CISO, the head of IT, the heads of HR and marketing, and usually the general counsel. That constraint, not cost, is why most organizations under roughly 1,000 employees end up with an outsourced designation. In-house begins to win once privacy work becomes continuous rather than intermittent, which typically means above 1,000 employees or where personal data is central to the product. For mid-market companies the answer is often neither pure option: an internal privacy manager doing the work, with an outsourced DPO of record holding the designation.
Start with Article 38, not the budget
Three provisions decide who is eligible. Article 38(3) says the DPO shall not receive instructions regarding the exercise of their tasks, cannot be dismissed or penalized for performing them, and reports to the highest management level. Article 38(6) permits the DPO to hold other duties provided the controller ensures no conflict of interest arises. Article 37(6) confirms that the DPO may be a staff member or may act under a service contract, which is what makes outsourcing lawful in the first place.
The consistent regulatory reading of those provisions is that anyone who determines the purposes or means of processing cannot audit that processing. This is not a theoretical concern. The Belgian supervisory authority fined a company 50,000 euros in 2020 because its head of compliance, risk, and internal audit also served as DPO, on the basis that setting processing purposes for those functions and then monitoring them was a conflict on its face. The practical consequence is that the appointment cannot be made for convenience, and that a badly chosen internal appointee is worse than no appointment at all, because it produces a documented conflict rather than a documented gap.
Who is actually left inside the company
Work down a typical org chart and the eligible population shrinks fast. The CEO and COO are out because they own the business model that requires the processing. The CTO, CISO, and head of IT are out because they decide how personal data is stored, secured, and moved. The HR director is out for employee data and the marketing lead is out for customer data, each for the same reason.
The general counsel is a recurring bad fit for a different reason. The GC's professional duty is to defend the company's position, while the DPO's duty runs to compliance and, in effect, to data subjects. Those obligations look aligned until a breach or a complaint arrives, at which point they visibly diverge.
What remains is a dedicated privacy professional with no processing decision rights, reporting to the CEO or the board. In a company of 1,500 people that role exists or can be created. In a company of 120 people it usually cannot, because the only candidates with enough seniority to be heard are the same people the conflict rules exclude.
Where an in-house DPO wins
Four signals point toward hiring. The first is sustained volume: once privacy work runs beyond roughly 20 hours a week for several consecutive months, an internal appointment buys more attention per dollar than a retainer. That threshold usually arrives somewhere above 1,000 employees, or earlier at consumer platforms fielding more than 40 or 50 data subject requests a month.
The second is centrality. If personal data is the product, as it is in ad technology, health technology, insurance, and HR technology, privacy decisions are made in product planning meetings every week and someone needs to be in them. The third is institutional knowledge: an environment with thousands of processing activities, decades of legacy systems, and a complex works council relationship rewards continuity that an external officer with several clients cannot match. The fourth is team size, since a privacy function of two or more people needs day-to-day management rather than periodic oversight.
One caution on the hire. An internal DPO only works if the independence provisions are honored in practice, which means a reporting line above the executives whose work is being monitored and protection from being managed out for inconvenient findings. A DPO who reports to the CTO has the title without the role.
Where outsourcing wins
Outsourcing solves the independence problem by construction. An external officer designated under a service contract has no line management inside the business, no promotion path that depends on the goodwill of the people being monitored, and a professional standing that sits outside your org chart. That structure does not make independence automatic, which is why the contract still needs the no-instruction and reporting-line language written into it, but it removes the structural conflict that internal appointments keep running into.
Three practical advantages follow. Precedent is the largest: an external officer who has assessed 30 breaches against the 72 hour clock and handled a dozen regulator inquiries brings judgment that a capable first-time internal appointee will need three years to accumulate. Speed is the second, since a designation can be live in two to four weeks against a three to six month search. Continuity is the third, because a properly built service includes a named deputy, so a resignation or a two week absence does not leave the statutory contact point unstaffed.
Cost sits behind those rather than ahead of them. Retainers commonly run $1,500 to $8,000 a month against $140,000 to $230,000 loaded for a qualified hire, and our breakdown of DPO as a service pricing sets out what drives the spread.
The hybrid model most mid-market companies land on
The arrangement that resolves the tension is a split between the work and the designation. An internal privacy manager at $90,000 to $140,000 owns operations: maintaining the record of processing activities, taking in data subject requests, running vendor and processor reviews, delivering training, and drafting impact assessments. An outsourced DPO of record at $3,000 to $6,000 a month holds the statutory designation, monitors independently, signs off on impact assessment advice, serves as the contact point for regulators and data subjects, and delivers the annual report to the board. Combined cost is roughly $130,000 to $210,000, and the structure is defensible because the person doing the processing work is not the person monitoring it.
One detail decides whether this works: the internal manager must not be titled DPO. Designating someone attaches the full weight of Articles 37 through 39, including independence and non-dismissal protections, whether or not the appointment was required. Privacy manager, privacy counsel, or privacy program lead are the right titles. Reserve the DPO designation for the person who actually holds it.
Multi-jurisdiction coverage
Article 37(2) lets a group of undertakings appoint a single DPO provided that officer is easily accessible from each establishment, which is a practical test rather than a formal one. Accessible means reachable in a language local data subjects can use, within working hours they recognize, with enough visibility into local processing to monitor it. For a group with entities in three or four member states, one designation communicated to each relevant supervisory authority is usually cleaner than a DPO per subsidiary, and it concentrates the independence problem in a single place that is easier to protect.
The argument strengthens outside the EU. UK GDPR mirrors the requirement, Brazil's LGPD requires a designated officer, and China's PIPL obliges certain processors to name a responsible person. A provider already operating across those regimes replaces four appointments and four learning curves. One clarification worth making before you buy anything: the Article 27 EU representative is a separate obligation for controllers with no EU establishment, and it is not the same role as the DPO. Some companies need one, some need the other, and some need both, so establish which conversation you are having before comparing quotes.
A decision test you can run in an hour
- Independence. Name every internal candidate, then strike anyone who decides how personal data is collected, stored, secured, or used. If the list is empty, outsource or create a new role.
- Volume. Count last year's data subject requests, impact assessments, vendor reviews, and breach assessments. Under roughly 20 hours a week of sustained work, a retainer fits better than a salary.
- Precedent. Ask how many regulator inquiries and notifiable breaches your best internal candidate has handled. If the answer is none and your risk profile is high, buy the experience.
- Geography. List the establishments and supervisory authorities involved. More than two jurisdictions usually favors a provider with existing coverage.
- Continuity. Ask what happens to the designation if the officer resigns or is unavailable for three weeks. If there is no answer, the arrangement is a single point of failure.
What to insist on either way
Whichever route you take, six things belong in writing: the formal designation and the notification to the relevant supervisory authority, a reporting line to the highest management level, a resources commitment covering time, budget, and access to processing systems, an explicit no-instruction clause reflecting Article 38(3), ownership of the records the role produces including the processing register and the request and breach logs, and named deputy coverage. Internal appointments miss the resources and reporting items most often. External appointments miss the records ownership item, which becomes expensive at the moment you change providers.
Where BD Emerson fits
We hold the designation for clients through DPO as a service, including in the hybrid arrangement above where an internal privacy manager runs the operational program and our officer provides independent monitoring and the regulator relationship. If you have not yet established whether the appointment is mandatory at all, that Article 37 analysis, along with the record of processing activities and transfer work behind it, sits inside our GDPR compliance consulting practice, and when GDPR requires you to appoint a DPO walks through the triggers. The two outcomes worth avoiding are appointing a conflicted executive because the org chart made it convenient, and hiring for a role that only needs eight hours a month of real independence.
