External Data Protection Officers for Companies & Municipalities
Structured. Transparent. Collaborative.
With our external Data Protection Officers, you achieve transparency, minimize risks, and alleviate the burden on your team.
We support you in implementing legal requirements and develop practical data protection solutions – ensuring a high level of protection, clear processes, and sustainable relief for your organization.
Your Benefits
IT & Data Protection from a Single Source
We combine technical security with legal precision.
Tailored Solutions over Standard Offerings
We review your processes, create transparency, and implement measures in a targeted manner.
Relief for Your Team
We support you with data protection.
You can focus on your core business.
Enterprises & Municipalities
Our experience with complex IT infrastructures makes the difference.
To ensure data protection poses no risk to you
Data Protection Check
Transparency at a Fixed Price: In a structured workshop, we assess your data protection status and immediately identify risks.
Audit & Action Plan
Detailed analysis with audit report, prioritization, and effort estimation – clear, structured, and implementation-oriented.
Assumption of the DPO Mandate
We provide comprehensive support in data protection: As external Data Protection Officers, we ensure that data protection is actively and practically implemented within your organization.
ceterion – Legal Precision meets Technical Expertise
We combine data protection expertise with technical experience – fostering clear processes, transparent workflows, and collaborative partnerships.

Verena Rheker-Heerde
Data Protection Officer
- Lawyer for IT & Data Protection Law (since 2012)
- Over 20 years of experience in international IT companies
- TÜV-certified Data Protection Officer & Auditor

Dirk Beckel
Data Protection Officer
- IT Specialist for Security & Data Protection Management
- 15 Years of Consulting for Public Authorities & Enterprises
- TÜV-certified Data Protection Officer
Services within the Scope of the Data Protection Mandate
ceterion AG's external Data Protection Officer supports and advises you from the time of appointment – with a practical, structured approach, focusing on your IT and business processes.
Their responsibilities particularly include:
Training & Awareness
Instruction and Training of Your Employees on Data Protection
Verification of Employee Adherence to Data Secrecy
Answering Specific Data Protection Questions from Employees or Customers
Legal Consulting & Implementation
Development of internal guidelines and regulations regarding data protection and data security
Support with and response to data subject requests in accordance with Art. 15–20 EU-GDPR
Communication and Coordination with Supervisory Authorities
Assessment of the lawfulness of the processing of personal and special categories of data
(Articles 6–10 of the EU GDPR)Support with compliance and implementation of legal information obligations
(Art. 13 & 14 EU GDPR)
Technical & Organizational Measures
Assessment and review of suitable technical and organizational measures (TOMs) in accordance with Art. 24, 25 & 32 GDPR
Support for data processing by a processor (Art. 28 GDPR)
Consulting on maintaining the record of processing activities (Art. 30 GDPR)
Guidance in selecting and/or implementing suitable data protection management software
Risk & Process Management
Consulting and support for risk assessments and data protection impact assessments
(Art. 35 of the EU GDPR)Regular review of data protection compliance, e.g., through audits, process reviews, and guideline checks
Support in fulfilling documentation, reporting, and notification obligations in the event of data breaches
Consulting on the implementation of data subject rights (access, rectification, restriction, erasure)
Documentation & Governance
Assistance in establishing and maintaining data privacy-related processes and documentation
Setup or optimization of a Data Privacy Management System (DPMS), if not yet established
Acting as the central point of contact for supervisory authorities regarding all data privacy matters
Your Advantage
ceterion provides more than just regulatory compliance:
We combine data privacy expertise with technical IT security – for efficient processes, clear structures, and lasting trust among customers, partners, and employees.
You take care of business. We take care of your privacy.
Secure your independent data privacy consulting and external Data Protection Officer today, strengthening your IT strategy.
Questions? We are happy to help.
Find quick answers here – or feel free to contact us directly.
Not every company is legally obliged to appoint a Data Protection Officer – but many are de facto required without realizing it.
According to the General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG), a company must appoint a Data Protection Officer if one of the following conditions is met:
- At least 20 individuals are regularly involved in the automated processing of personal data (e.g., through email communication, CRM, HR software, etc.).
- The company's core activity involves the extensive processing of personal data – such as health, financial, or human resources data.
- The company carries out processing operations that are subject to a Data Protection Impact Assessment (e.g., video surveillance, tracking, profiling).
- The company commercially transmits or processes personal data (e.g., IT service providers, marketing agencies, cloud providers).
Even when not legally mandated, an external Data Protection Officer is often advisable for practical and liability-related reasons:
- You avoid fines and reputational risks.
- You relieve internal teams of complex GDPR obligations.
- You receive an independent, legally sound assessment of your processes.
Conclusion:
A data protection officer is always a good idea when personal data plays a significant role in day-to-day business operations—and that is the case in almost every company today.
Our collaboration is structured, transparent, and practice-oriented.
After a brief introduction and clarification of your requirements, we proceed step-by-step with:
- Initial Consultation & Assessment
During the initial consultation, we will work together to gain an overview of your data protection organization, existing processes, and systems. This will provide an initial, realistic picture of your current implementation of GDPR requirements—before we delve into a detailed analysis during the audit.
Audit & Action PlanDuring the audit, we assess how effectively your organization is implementing data protection requirements—going far beyond a mere process-based perspective. We examine structures, responsibilities, and technical and organizational measures, and identify where risks or gaps exist.
The result: a concrete, prioritized action plan that immediately shows you what needs to be done—clear, practical, and actionable.- Appointment as Data Protection Officer & Ongoing Support
Once appointed, we assume the role of external Data Protection Officer and assist you with the practical implementation of data protection requirements.
We advise, train, and support you on an ongoingbasis—ensuring that data protection within your organization remains clear, secure, and easy to implement. - Reporting
We ensure continuity in data protection: with regular reports, clear recommendations, and up-to-date information on legal changes.
➜ Our goal: to make data protection an integral part of your compliance strategy—efficient, practical, and integrated across all areas of your business.
In brief: We view data protection not merely as a mandatory task, but as an integral component of your IT strategy and corporate security.
An external Data Protection Officer from ceterion offers you in-depth expertise and organizational relief – without tying up additional internal resources.
Your Advantages at a Glance:
- Compliance & Guidance:
We ensure that your company meets all GDPR and BDSG requirements—including documentation and reporting obligations. - Expertise on demand:
Our certified data protection and IT experts bring up-to-date legal, technical, and organizational expertise to the table. - Efficiency & Relief:
You save internal resources—we handle audits, training, and communication with regulatory authorities. - A Head Start in Trust:
Your customers, partners, and employees will see that you take data protection seriously—this strengthens your image and builds trust. - A Holistic Approach:
As IT and data protection specialists, we consider both areas together—to ensure sustainable security and digital sustainability.
Conclusion:
An external data protection officer is more than just a mandatory requirement—they are your partner for robust processes, effective data protection, and future-oriented IT.
Our mandates are clearly structured and transparently calculated – without hidden costs or ambiguous expenses.
For companies, we offer ongoing support by an external Data Protection Officer under the following conditions:
Monthly retainer:
750 EUR / month
✔️ Includes 3.5 hours of consulting and implementation time per month
These hours include, for example:
- Responding to data protection inquiries
- Review and maintenance of records of processing activities
- Support for Data Protection Impact Assessments (DPIAs)
- Drafting of policies or data processing agreements
Flexible & scalable:
If additional support is needed—for example, for projects, audits, or short-term reviews—additional consulting hours can be arranged on a case-by-case basis, naturally at transparent hourly rates.
Conclusion:
With our monthly service agreement, you receive reliable data protection support, predictable costs, and dedicated contacts who understand your IT and business processes.
Inquire now without obligation – and discover how we can support your company in a future-oriented and efficient manner.
Our Data Protection Check is the initial step towards achieving an appropriate level of data protection and ensuring the long-term legal compliance of personal data handling. It forms the basis for assuming the mandate as an external Data Protection Officer and provides transparency regarding the current state of your data protection organization.
Objective and Approach
With a view to establishing a robust data protection management system, an initial inventory analysis is required.
This is carried out in two steps:
1. Workshop – Determining the Status Quo (approx. 3 hours)
- Joint recording of existing data protection measures and processes
- Reconciliation with legal requirements according to GDPR and BDSG
- Identification of initial areas for action
2. Audit – In-depth Analysis and Evaluation (approx. 3 hours, on-site)
- Conducting an audit based on a standardized questionnaire (aligned with legal requirements and best practice standards)
- Verification of compliance with data protection obligations and organizational measures
- Evaluation of technical and organizational measures (TOMs)
Results and Benefits
Upon completion of the workshop and audit, you will receive:
- A detailed report documenting the current data protection level
- A catalog of measures, prioritized by the urgency of any measures yet to be established
- An effort estimate for implementing the recommended steps
- A clear basis for decision-making regarding further action and the assumption of the data protection mandate
Your Advantage
The Data Protection Check provides you with a practical overview of your data protection compliance, identifies risks and optimization potential, and enables you to manage data protection strategically and efficiently.
Concurrently, it serves as a binding foundation for the mandate of ceterion AG's external Data Protection Officer – thus ensuring seamless and structured support from day one.
Conclusion:
The Data Protection Check is not a theoretical assessment, but a concrete, structured first step toward implementing data protection requirements— at a transparent, fixed price and with results you can put into practice immediately.
Yes – ceterion can fully support data protection services within an IKZ (Inter-municipal Cooperation) model. In this model, several municipalities – for example, within a district – consolidate their data protection tasks to leverage synergies and reduce costs.
We integrate our services in such a way that all participating municipalities benefit from centralized, coordinated data protection support.
Key Benefits:
- Cost savings through joint commissioning and efficient structures
- Maximum flexibility through individual customization for each municipality
- Uniform data protection standards and coordinated procedures
- Central point of contact for all participating municipalities
The IKZ model is ideal for cities, municipalities, and districts that wish to implement their data protection obligations collaboratively, economically, and with a future-oriented approach.
Yes – upon request, we would be pleased to connect you with one of our references who have successfully implemented data protection projects.
This provides you with direct insight into our working methods and the results achieved.
