What should a contract with an external data protection officer contain?

Michał Rutkowski • for boards and procurement • published September 19, 2026 • 8 min read

Let’s talk

Wondering how this plays out in your organisation? Get in touch — I answer personally.

Short answer

According to the Polish Personal Data Protection Office (UODO), a contract with an external DPO is a service contract under Article 37(6) GDPR and not a data processing agreement. Its subject matter is the tasks of the officer under Article 39(1), not the tasks of the controller. The Regulation does not specify the content of such a contract, and in my assessment its provisions follow from the obligations that Article 38 imposes on the controller and the processor. The contract may set the framework of cooperation, but it may not contain instructions regarding the exercise of the officer’s tasks.

Why this question arises at all

The Regulation allows two ways of performing the role. Under Article 37(6) GDPR the data protection officer may be a staff member of the controller or processor, or fulfil the tasks on the basis of a service contract. The Regulation does not regulate the content of such a contract. It does not specify its mandatory provisions or how it ends, although Article 38 sets limits for both.

The gap is usually filled by the template the procurement department knows best. A supplier with access to data receives a data processing agreement, and a service supplier receives quality metrics and the client’s right to give instructions. In my assessment neither template fits the officer well. A data processing agreement must stipulate that the processor processes personal data only on documented instructions from the controller (Article 28(3)(a) GDPR). The exception covers a requirement imposed on it by Union or Member State law to which the processor is subject. The controller and the processor must instead ensure that the officer does not receive any instructions regarding the exercise of his or her tasks (Article 38(3)).

The second reason lies in the design of the role itself. Paragraphs 1 to 3 and 6 of Article 38 GDPR mainly set out obligations of the controller and the processor towards the officer. In my assessment the contract with an external DPO is the natural place where the organisation records how it fulfils those obligations towards a person from outside its staff.

The contract only comes after the choice of model. The criteria for that choice are described in External or internal DPO? What to consider before deciding?.

What has to be established before a decision

Who is designated and who works in the team

The guidelines of the Article 29 Working Party on data protection officers, known as WP 243, allow a service contract concluded with an individual or with an organisation outside the controller’s or processor’s organisation. In the latter case the guidelines consider it essential that each member of the organisation exercising the functions of a DPO fulfils all applicable requirements of Section 4 of Chapter IV GDPR. As an example they give the requirement that no one has a conflict of interests.

For the sake of legal clarity and good organisation, and to prevent conflicts of interests for the team members, the guidelines recommend a clear allocation of tasks. They also recommend assigning a single individual as a lead contact and person in charge for each client. They add that it would generally also be useful to specify these points in the service contract.

The Polish Act on the Protection of Personal Data requires the notification to the President of the Personal Data Protection Office to state the officer’s first name and surname and his or her email address or telephone number (Article 10(1)). In my assessment the contract should therefore name the person who will be notified as the officer. The notification is made by the entity that designated the officer within 14 days of the designation. Under Article 10(2) of the Act the notification may be made by a proxy, and a power of attorney granted in electronic form is attached to it. The contract may provide for such an authorisation.

The organisation publishes the same officer details on its website without delay after the designation (Article 11 of the Act). If it has no website, it makes them publicly available at its place of business.

The contract may also provide for a deputy. Under Article 11a(1) of the Act the entity that designated the officer may designate a person to replace the officer during his or her absence. It takes into account the criteria of Article 37(5) and (6) GDPR. Under Article 11a(3) the designation of the deputy requires a notification in the procedure of Article 10 of the Act and publication of the deputy’s details in accordance with Article 11.

The provisions on the officer apply accordingly to the deputy in connection with performing the officer’s duties during the officer’s absence (Article 11a(2)). In my assessment the contract should therefore cover the deputy with the same guarantees as the officer.

What the contract with an external DPO must secure

Article 38 GDPR does not create a catalogue of contractual provisions. The report of the European Data Protection Board on its 2023 coordinated action suggests that organisations and DPOs could formalise the DPO’s duties and the conditions for performing them in an engagement letter. In my assessment the paragraphs of Article 38 can be translated into specific clauses. The following list is ordered by the author.

  • Involvement in issues. Under Article 38(1) the officer must be involved, properly and in a timely manner, in all issues which relate to the protection of personal data. The contract may state who on the organisation’s side informs the officer about new processes, impact assessments and breaches. When carrying out an impact assessment the controller seeks the advice of the officer, as Article 35(2) requires.
  • Access, resources and time. Under Article 38(2) the organisation provides the officer with the resources necessary to carry out the tasks and with access to personal data and processing operations. It also provides the resources necessary to maintain his or her expert knowledge, so in my assessment the contract should settle who bears that cost. According to UODO the external officer’s access to the personal data necessary to perform his or her tasks follows from the law, including Article 38(2). The WP 243 guidelines consider it good practice to determine the time needed to carry out the function.
  • Contact with data subjects. Data subjects may contact the officer with regard to all issues related to processing of their personal data and to the exercise of their rights under the Regulation (Article 38(4)). The contract may set the channel and the response time for such enquiries.
  • Reporting line. The officer directly reports to the highest management level of the controller or the processor (Article 38(3)). The guidelines give an annual report of the officer’s activities provided to the highest management level as an example of such direct reporting. In my assessment the contract should name the highest management level as the recipient of the officer’s reports.
  • Confidentiality. The officer is bound by secrecy or confidentiality concerning the performance of his or her tasks in accordance with Union or Member State law (Article 38(5)). According to the guidelines this obligation does not prohibit the officer from contacting and seeking advice from the supervisory authority.
  • Other tasks. The officer may fulfil other tasks and duties, and the organisation ensures that they do not result in a conflict of interests (Article 38(6)).

The obligations under Article 38(1) to (3) and (6) rest on the organisation by law even where the contract does not mention them. In the same way the confidentiality obligation under Article 38(5) rests on the officer whatever the contract says. The controller also implements appropriate measures to ensure and to be able to demonstrate that processing is performed in accordance with the Regulation (Article 24(1)). In my assessment a clause in the contract makes that demonstration easier as far as the officer is concerned.

Where the framework of cooperation ends and an instruction begins

Under the first sentence of Article 38(3) the controller and the processor ensure that the officer does not receive any instructions regarding the exercise of his or her tasks. Recital 97 GDPR concerns officers designated on a mandatory basis. It states that such officers, whether or not they are employees of the controller, should be in a position to perform their duties and tasks in an independent manner.

The WP 243 guidelines translate this requirement into examples. As prohibited instructions they list telling the officer what result should be achieved, how to investigate a complaint or whether to consult the supervisory authority. Nor may the officer be instructed to take a certain view of an issue related to data protection law, for example a particular interpretation of the law. The officer’s autonomy does not mean decision-making powers extending beyond the tasks under Article 39.

The EDPB report applies this requirement directly to contracts. Organisations that use an external DPO need to be very mindful that the contractual relationship does not entail instructions on how to carry out the officer’s tasks, either directly or indirectly. One supervisory authority encountered a data processing agreement between an organisation and its external DPO. It pointed out that considering the officer as a processor could lead to a breach of the independence requirements under Article 38(3).

In my assessment the same care is needed with the authorisation to process data. Under Article 29 GDPR any person acting under the authority of the controller or the processor who has access to personal data shall not process those data except on instructions from the controller, unless required to do so by Union or Member State law. The authorisation may define the scope of the officer’s access to data, but it should not bind the officer with instructions on how to perform the tasks under Article 39.

In practice the contract with an external DPO touches this line in clauses that appear in every service contract. The following table is my assessment and not a list taken from the legislation or the guidelines.

ClauseWithin the framework of cooperationBecomes an instruction
Working timenumber of hours, days of availability, response time to a requestan indication of which matters the officer should give less attention to
Opinionsdeadline for an opinion and its forman indication of the outcome or the interpretation the opinion is to adopt
Contact with the authorityinforming the board about contacts with UODOa requirement for the client’s consent to consult the authority
Reportingdeadline and form of the report to the boardagreeing the content of the report with the department it concerns
Service metricstimeliness, availability, completeness of documentationmetrics or contractual penalties linked to the content of the officer’s positions

How a contract with an external DPO can end

Under the second sentence of Article 38(3) the officer shall not be dismissed or penalised by the controller or the processor for performing his or her tasks. For a contract with an external organisation the WP 243 guidelines state that it is equally important that each person exercising the role is protected by the provisions of the GDPR. They give two examples. The first is no unfair termination of the service contract for activities as DPO. The second is no unfair dismissal of any individual member of the organisation carrying out the DPO tasks.

This protection is not unconditional. The guidelines state that the officer could still be dismissed legitimately for reasons other than performing his or her tasks. As for any other employee or contractor, this happens under applicable national contract or labour and criminal law. As examples the guidelines give gross misconduct such as theft or harassment. UODO adds that the provision should be read as referring to the objectively correct performance of the tasks. It does not protect an officer who fails to perform them properly. Apart from the prohibition on dismissal for performing the tasks, the Regulation does not specify the reasons for dismissal or the procedure.

Remember

The contract should describe the grounds for termination so that they can be told apart from a reaction to the content of the officer’s position.

In my view the UODO position also allows those grounds to include deficient performance of the service, provided it can be verified. Examples are timeliness, availability or a breach of confidentiality. The guidelines would welcome efforts by organisations towards a stable contract and guarantees against unfair dismissal, because this makes independent action by the officer more likely.

The end of the cooperation triggers an obligation on the organisation’s side. Article 10(4) of the Act requires notifying the President of the Office of the dismissal of the officer and of every change in the details from the notification. The deadline is 14 days from the date of the change or dismissal. In my assessment the end of the contract falls within this obligation. I recommend a notice period long enough to designate a successor and a clause on handing over the documentation of the officer’s work.

Additional services from the same provider

A provider performing the officer role is sometimes engaged for other work as well, for example preparing documentation or procedures. UODO points out that the possibility of performing tasks other than those set out in the GDPR is limited by the prohibition of a conflict of interests under Article 38(6). The WP 243 guidelines give an example of such a conflict. It may arise if an external officer is asked to represent the controller or processor before the courts in cases involving data protection issues.

The EDPB report draws attention to a wider risk. Additional tasks may lead to situations in which the external officer monitors his or her own activities. In another case one supervisory authority found that the external DPO also acted as the DPO of the controller and of its processor. According to the report such a situation may give rise to a conflict of interests, because the officer then monitors two entities with different responsibilities and interests. In my assessment a similar analysis is needed where the officer’s firm itself processes the client’s data as a processor.

The guidelines allow the controller or the processor to assign the officer the task of maintaining the record of processing activities. The obligation to maintain the record nevertheless remains with the controller or the processor. Depending on the activities, size and structure of the organisation, the guidelines also consider that it can be good practice to include safeguards in the internal rules of the organisation. That practice also includes ensuring that the service contract is sufficiently precise and detailed to avoid a conflict of interests. I therefore recommend describing additional services in a separate part of the contract or in a separate contract.

Common mistakes

  • A data processing agreement attached to the service contract. According to UODO a contract whose subject matter is the performance of the officer’s tasks is not a data processing agreement.
  • Placing the officer under a department director. Article 38(3) requires the officer to report directly to the highest management level.
  • A confidentiality clause that shuts off contact with the authority. The guidelines state that the confidentiality obligation does not prohibit the officer from contacting and seeking advice from the supervisory authority.
  • Assigning representation before the courts in data protection cases. The WP 243 guidelines give it as an example of a situation in which a conflict of interests may arise.
  • A clause shifting responsibility for compliant processing onto the officer. According to the guidelines the officer is not personally responsible for non-compliance with data protection requirements, and compliance is the responsibility of the controller or the processor.
  • No named individual. Without one the organisation lacks the details for the notification required by Article 10(1) of the Act.

Conclusions and next steps

A contract with an external DPO does not transfer to the provider the obligations that Article 38 imposes on the controller and the processor. In my assessment its value lies in showing how the organisation fulfils those obligations. It also separates the framework of cooperation from instructions. Most of the risk lies in clauses taken over from standard service contracts, that is in metrics, approvals and confidentiality clauses.

Five steps that put the preparation of the contract in order.

  1. Name the person notified as the officer, the lead contact and the members of the provider’s team.
  2. Describe the subject matter of the contract through the tasks under Article 39(1) and separate additional services from them.
  3. Record how the organisation ensures the officer’s involvement, access to data and direct reporting to the highest management level.
  4. Review the metrics, approvals and confidentiality clause for hidden instructions.
  5. Describe the grounds for termination and the notice period, the handover of documentation and who makes the notifications to the President of the Office.

Related materials

Sources

  • Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), consolidated version — Article 24(1), Article 28(3), Article 29, Article 35(2), Article 37(5) and (6), Article 38 and Article 39 — eur-lex.europa.eu (accessed September 19, 2026).
  • Regulation (EU) 2016/679 (GDPR), version as published in OJ EU L 119 of 4 May 2016 — recital 97 — eur-lex.europa.eu (accessed September 19, 2026).
  • Act of 10 May 2018 on the Protection of Personal Data, consolidated text as at 6 May 2026 — Articles 10, 11 and 11a (in Polish) — isap.sejm.gov.pl (accessed September 19, 2026).
  • Personal Data Protection Office (UODO), Does a processing agreement have to be concluded with an external DPO? (in Polish) — uodo.gov.pl (accessed September 19, 2026).
  • Personal Data Protection Office (UODO), What guarantees of independence does the GDPR give the DPO? (in Polish) — uodo.gov.pl (accessed September 19, 2026).
  • Article 29 Data Protection Working Party, Guidelines on Data Protection Officers (‘DPOs’), wp243rev.01, adopted 13 December 2016, last revised 5 April 2017 — sections 2.5, 3.2 to 3.5 and 4.3 and questions 12 and 13 — ec.europa.eu (accessed September 19, 2026).
  • European Data Protection Board, 2023 Coordinated Enforcement Action. Designation and Position of Data Protection Officers, adopted 16 January 2024 — sections 4.5.1 and 4.5.2 — edpb.europa.eu (accessed September 19, 2026).

Check the contract before you sign it

In my assessment the independence of the officer is often decided by clauses taken over from a standard service contract. External DPO support also covers a review of the contract with the officer against the requirements of Article 38 GDPR, whoever performs the role.

Author

Michał Rutkowski — LabLogic. He combines the legal, organisational and technological perspective in his work with the boards of medium-sized and large organisations: support for and performance of the DPO role, preparation for NIS2 and the Polish KSC Act, incident response, audits and training. Contact: M.Rutkowski@LabLogic.pl · LinkedIn

This material is general and educational in nature. It is not an individual legal opinion or a recommendation for any specific organisation. The scope of the obligations should be assessed against the situation of the organisation concerned.

Legal status: September 2026.

Scroll to Top