Skip to content

External DPO fees in Spain: budget variables and legal obligation

The General Data Protection Regulation (GDPR) — known in Spain as the RGPD (Reglamento General de Protección de Datos) — requires certain types of organisations to appoint a Data Protection Officer (DPO). For most companies that cannot justify a full-time in-house DPO, the external DPO (Data Protection Officer as a Service) is the standard solution. The external DPO market in Spain has grown enormously since 2018, and budgeting criteria vary widely between providers. This guide explains the variables that determine the price and how to evaluate an external DPO proposal.

Since 2010 · 16 years Tax agent AEAT

Pick a slot in the specialist's calendar.

Tell us when to call and a partner will contact you in your chosen window.

Write to us and we'll reply within 24 business hours.

Data processed in the EU · GDPR · No commitment

How we work

From first contact to case completion

  1. Initial data protection audit

    We review the current state of data protection compliance: records of processing activities, legal bases, data processing agreements, privacy and cookies policy, and the technical and organisational measures in place.

  2. GDPR adaptation plan

    We identify the gaps between the current situation and the requirements of the GDPR and LOPDGDD. We draw up an adaptation plan with priority measures, an implementation schedule, and an allocation of responsibilities.

  3. Formal DPO designation and notification to the AEPD

    We formalise the DPO designation, notify the contact details to the Agencia Española de Protección de Datos (AEPD), and communicate this to employees as required by the GDPR.

  4. Ongoing maintenance and supervision

    The external DPO continuously monitors compliance, responds to internal and external data protection queries, manages data subject rights (access, rectification, erasure, objection), and coordinates the response to data breaches.

Self-check · 45 seconds

Do you need this service?

Answer three questions and we'll show you the most relevant service for your case.

Do you currently reside in Spain?
Do you have assets or income in another country?
Have you received or are you expecting an inheritance?
Are you considering setting up a company?
Answer to see your recommended services.

The problem

The General Data Protection Regulation (GDPR) — known in Spain as the RGPD (Reglamento General de Protección de Datos) — requires certain types of organisations to appoint a Data Protection Officer (DPO). For most companies that cannot justify a full-time in-house DPO, the external DPO (Data Protection Officer as a Service) is the standard solution. The external DPO market in Spain has grown enormously since 2018, and budgeting criteria vary widely between providers. This guide explains the variables that determine the price and how to evaluate an external DPO proposal.

Our solution

At BMC we provide the external DPO service with data protection professionals who hold recognised certifications and have experience in the most heavily regulated sectors: healthcare, finance, human resources, technology, and education. We are not a templates provider: we are advisers who understand the client's business and tailor the data compliance programme to their operational reality. The first consultation is complimentary. See our [fee structures](/es/honorarios) for further information.

Process

How we do it

1

Initial data protection audit

We review the current state of data protection compliance: records of processing activities, legal bases, data processing agreements, privacy and cookies policy, and the technical and organisational measures in place.

2

GDPR adaptation plan

We identify the gaps between the current situation and the requirements of the GDPR and LOPDGDD. We draw up an adaptation plan with priority measures, an implementation schedule, and an allocation of responsibilities.

3

Formal DPO designation and notification to the AEPD

We formalise the DPO designation, notify the contact details to the Agencia Española de Protección de Datos (AEPD), and communicate this to employees as required by the GDPR.

4

Ongoing maintenance and supervision

The external DPO continuously monitors compliance, responds to internal and external data protection queries, manages data subject rights (access, rectification, erasure, objection), and coordinates the response to data breaches.

Case by case
Detailed budget following initial audit
Mandatory
For certain sectors and public authorities (Art. 37 GDPR)
72h
Maximum deadline for notifying breaches to the AEPD

How are external DPO fees calculated in Spain?

External Data Protection Officer (DPO) fees in Spain depend on multiple variables: company size, sector of activity, the number and sensitivity of the data processing activities, and whether the organisation operates in a high-risk sector such as healthcare, finance, or tracking technology. At BMC we always provide fee proposals in writing after an initial compliance audit. See our fee structures for an overview of our general process.

Variables that determine the budget

The price of an external DPO service is not simply a function of company size. The factors that most affect the budget are as follows.

Sector of activity and categories of data processed. Health data, biometric data, data relating to minors, and financial data are subject to far stricter legal requirements than ordinary customer and employee data. A sector with higher inherent risk requires more DPO input.

Number and diversity of processing activities. A company that processes data of customers, employees, job candidates, website users, and recipients of commercial communications has several independent processing activities to document, maintain, and supervise.

Data Protection Impact Assessments (DPIAs). Certain high-risk processing activities require a Data Protection Impact Assessment (DPIA, or EIPD in Spanish) before they commence. Preparing a DPIA involves significant additional work beyond routine compliance maintenance.

Number of entities in the group. A corporate group with several companies can share a single external DPO, but the work of maintaining the records of processing activities and compliance for each entity multiplies accordingly.

Security incidents. Companies with greater exposure to cyberattacks or a history of security incidents require a more active DPO with greater availability to manage notifications to the AEPD within the 72-hour deadline.

Supplementary services. Initial audit (gap analysis), employee training, management of complex data breaches, and representation before the AEPD are services that may be included within the monthly scope or budgeted separately.

Fee transparency at BMC

At BMC the external DPO service is always budgeted in writing, with a detailed scope of what is included in the monthly fee and what is invoiced separately (additional audits, DPIAs, management of complex data breaches, representation before the AEPD). We do not apply generic pricing without first understanding the reality of each organisation.

Enquire about our external DPO service →

FAQ

Frequently asked questions

The DPO is mandatory for three types of organisations under Article 37 of the GDPR: public authorities and bodies; organisations whose core activity consists of large-scale processing operations that require regular and systematic monitoring of data subjects (e.g. digital advertising companies, tracking platforms); and organisations whose core activity consists of large-scale processing of special categories of data (health, biometric, religious, criminal). For all other companies, the DPO is voluntary but recommended.
The budget is built on several factors: sector of activity (healthcare, finance, and technology have stricter requirements), number and diversity of processing activities, volume of data, number of group entities, and the need for Data Protection Impact Assessments (DPIAs). After an initial audit we send a detailed proposal with the scope of the monthly service and what is invoiced separately. See our fee structures.
An internal DPO is an employee of the organisation who assumes DPO functions in addition to, or instead of, their usual duties. An external DPO is an external provider that delivers the service under a services contract. The GDPR permits both arrangements. The advantage of an external DPO is guaranteed functional independence and multi-sector experience; the advantage of an internal one is a deep knowledge of the organisation. Companies processing highly sensitive data or operating in heavily regulated sectors typically prefer an external DPO.
The initial audit (gap analysis) of a company's data protection compliance is a one-off piece of work budgeted separately from the ongoing external DPO service. The scope varies depending on the number of processing activities, the diversity of information systems, and whether the company already has prior documentation. The audit is the starting point for determining the volume of work required to achieve compliance.
The absence of a DPO in an organisation that is required to have one is a GDPR infringement that may result in fines of up to 10 million euros or 2% of total worldwide annual turnover. The AEPD has sanctioned multiple entities for the absence or incorrect designation of a DPO. In addition to the fine, the company may have difficulty demonstrating the accountability principle in the event of a data breach.
The GDPR does not require a specific certification for the DPO, but does require expert knowledge of data protection law and practices and the capacity to fulfil the tasks defined in the Regulation. In practice, CIPP/E (IAPP), CDPP, or AEPD/ENAC certification schemes are a guarantee of competence. When engaging an external DPO it is advisable to verify their credentials and sector experience.
When a data breach occurs (unauthorised access, loss, theft, or leakage of personal data), the controller has 72 hours to notify the AEPD if there is a risk to data subjects' rights. The DPO coordinates this notification. In complex incidents (ransomware, large-scale customer data leaks), DPO and legal team support during crisis management is budgeted as an additional service based on the severity and effort required.
The main ones are: (1) high-risk sector (healthcare, finance, tracking technology), (2) special categories of data (health, biometric, minors), (3) number and diversity of processing activities, (4) need for DPIAs, and (5) number of group entities. At BMC we analyse these factors during the initial audit.

Speak with a specialist

Complimentary first call. No commitment. Response within 1 hour during office hours.

Free first consultation 30 minutes with a specialist in your area
Fixed quote before we start No surprises, no success fees
Registered tax agent Electronic filing of all tax returns

4.8/5 · Data processed in the EU · GDPR · No commitment

Frequently asked questions

Questions about External DPO Fees in Spain

The DPO is mandatory for three types of organisations under Article 37 of the GDPR: public authorities and bodies; organisations whose core activity consists of large-scale processing operations that require regular and systematic monitoring of data subjects (e.g. digital advertising companies, tracking platforms); and organisations whose core activity consists of large-scale processing of special categories of data (health, biometric, religious, criminal). For all other companies, the DPO is voluntary but recommended.
The budget is built on several factors: sector of activity (healthcare, finance, and technology have stricter requirements), number and diversity of processing activities, volume of data, number of group entities, and the need for Data Protection Impact Assessments (DPIAs). After an initial audit we send a detailed proposal with the scope of the monthly service and what is invoiced separately. See our fee structures.
An internal DPO is an employee of the organisation who assumes DPO functions in addition to, or instead of, their usual duties. An external DPO is an external provider that delivers the service under a services contract. The GDPR permits both arrangements. The advantage of an external DPO is guaranteed functional independence and multi-sector experience; the advantage of an internal one is a deep knowledge of the organisation. Companies processing highly sensitive data or operating in heavily regulated sectors typically prefer an external DPO.
The initial audit (gap analysis) of a company's data protection compliance is a one-off piece of work budgeted separately from the ongoing external DPO service. The scope varies depending on the number of processing activities, the diversity of information systems, and whether the company already has prior documentation. The audit is the starting point for determining the volume of work required to achieve compliance.
The absence of a DPO in an organisation that is required to have one is a GDPR infringement that may result in fines of up to 10 million euros or 2% of total worldwide annual turnover. The AEPD has sanctioned multiple entities for the absence or incorrect designation of a DPO. In addition to the fine, the company may have difficulty demonstrating the accountability principle in the event of a data breach.
The GDPR does not require a specific certification for the DPO, but does require expert knowledge of data protection law and practices and the capacity to fulfil the tasks defined in the Regulation. In practice, CIPP/E (IAPP), CDPP, or AEPD/ENAC certification schemes are a guarantee of competence. When engaging an external DPO it is advisable to verify their credentials and sector experience.
When a data breach occurs (unauthorised access, loss, theft, or leakage of personal data), the controller has 72 hours to notify the AEPD if there is a risk to data subjects' rights. The DPO coordinates this notification. In complex incidents (ransomware, large-scale customer data leaks), DPO and legal team support during crisis management is budgeted as an additional service based on the severity and effort required.
The main ones are: (1) high-risk sector (healthcare, finance, tracking technology), (2) special categories of data (health, biometric, minors), (3) number and diversity of processing activities, (4) need for DPIAs, and (5) number of group entities. At BMC we analyse these factors during the initial audit.
Email
Contact