Myles Dacres
Marketing Manager
Myles Dacres is the Marketing Manager at Data Protection People. Over the past six years, he has led the organisation’s physical and digital presence, helping to strengthen the brand and grow what is now one of the UK’s largest data protection communities. He played a key role in the creation of the Data Protection Made Easy community and podcast, which has grown to more than 1,700 subscribers across the UK and beyond.
Get to Know Myles
Myles joined Data Protection People in 2020 and leads the organisation’s marketing strategy, brand development and community growth. His focus is on making data protection clearer, more practical and more accessible for organisations across the UK.
He drives the growth of the Data Protection Made Easy podcast and wider professional community, alongside sector events and AI led search initiatives. Through these platforms, he helps translate complex regulatory expectations into content that is engaging, understandable and relevant for both new and experienced practitioners.
Experience
Myles has built over five years of specialist B2B marketing experience within the data protection and cyber security sector. Beginning his career through a marketing apprenticeship at Data Protection People, he progressed into leading the organisation’s marketing function and shaping its long term growth strategy.
He has been instrumental in developing the Data Protection Made Easy community from the ground up, growing it into a network of more than 1,700 engaged professionals. This has been achieved through consistent podcast delivery, sector focused events, strategic collaborations and carefully structured thought leadership campaigns.
His expertise spans brand positioning, SEO, AEO and AI search visibility, campaign planning, event delivery, partnership marketing and PR strategy. He also oversees the creation of content that supports training, audit and consultancy services, ensuring that marketing activity aligns directly with operational objectives.
Working closely with senior leadership, Myles translates commercial goals into measurable marketing performance, embedding structure, data insight and long term thinking into every initiative.
“During my time at DPP, I have learned that community and brand are everything. I am fortunate to work with an incredible team that I have seen grow year after year, and I am proud to showcase the outstanding work they deliver every day.”
Myles Dacres
Marketing Manager
Myles's Posts
Finding What’s Exposed With EASM
External Attack Surface Management, usually shortened to EASM, is the continuous discovery and monitoring of everything your organisation exposes to the internet, domains, subdomains, cloud services, servers and applications, including the ones nobody currently has on a list.
What “attack surface” actually means
Your external attack surface is every point an attacker could potentially reach from outside your network. That includes the systems your IT team knows about and manages deliberately, but it also includes things that accumulate without anyone fully tracking them, a test server spun up for a project and never decommissioned, a marketing microsite built by an agency years ago, a cloud storage bucket set up for a one-off task, a subdomain nobody remembers creating. None of these are necessarily malicious or even risky on their own, but each one is a potential entry point, and you can’t secure what you don’t know exists.
Why this differs from a pentest or a vulnerability scan
Penetration testing and vulnerability scanning both work against a defined, known scope, systems you’ve already identified and agreed to test. EASM works the other way round, it starts from the outside, mapping what’s actually visible on the internet under your organisation’s name, and works to identify assets you may not have deliberately included in any existing security process at all. It’s the discovery layer that should logically come before testing, since a pentest against a scope that’s missing half your real exposure only gives you confidence in the part you already knew about.
How EASM actually works
EASM tools and services continuously scan public sources, DNS records, certificate transparency logs, IP ranges and cloud provider metadata, to build and maintain a live map of everything associated with your organisation that’s reachable from outside. That map gets checked for common exposure issues, out of date software, exposed admin panels, misconfigured cloud storage, expired certificates and anything genuinely concerning gets flagged for investigation. Because it’s continuous rather than a one-off exercise, new exposure gets caught close to when it appears, not months later during the next scheduled review.
Why this has become more important
Organisations’ external footprints have grown substantially with the shift to cloud services, third-party tools and distributed teams who can spin up new infrastructure without necessarily going through a central IT process. That’s not a criticism of how modern organisations operate, it’s simply a consequence of how much easier it now is to stand up a new service, and it means the gap between what security teams officially track and what’s actually exposed has grown alongside it. EASM exists specifically to close that gap.
Questions organisations usually ask about EASM
How is this different from just asking IT for a list of our systems? An internally maintained list only ever reflects what was deliberately recorded, and in practice things get missed, a project ends, a subdomain stays live, a cloud account gets set up outside the usual process. EASM discovers assets independently of any internal list, which is exactly the point, it finds what the list doesn’t know about.
Is this a one-off exercise or does it need to run continuously? It works best as continuous monitoring rather than a single scan, since new external assets appear constantly as an organisation operates. A one-off discovery exercise gives you an accurate picture on the day it runs, but that picture starts going out of date almost immediately.
What happens once something unexpected is found? Typically the finding gets triaged, confirmed as genuinely belonging to your organisation, assessed for how exposed or risky it actually is, and then either brought under proper management or decommissioned if it’s no longer needed. Not everything found is a problem, some of it is simply forgotten infrastructure that just needs tidying up.
Do we need this if we already do regular penetration testing? The two work together rather than replacing each other. A pentest assesses depth against an agreed, known scope. EASM addresses breadth, finding what should be in scope in the first place. Testing against an incomplete scope only ever gives you confidence in the part you already knew about.
Is EASM right for your organisation
It’s particularly valuable for organisations of meaningful size or with a history of mergers, acquisitions, agency-built projects, or multiple teams independently provisioning their own infrastructure, all situations where an accurate, centrally held inventory of external assets is unlikely to exist without deliberate effort. Even smaller organisations benefit from an initial discovery exercise, since the honest answer to “do you know everything your organisation exposes to the internet” is very often no, and finding that out is the necessary first step before any other security work can be properly scoped.
If you want an accurate picture of what your organisation actually exposes to the outside world, our External Attack Surface Management service is built to find out.
How Penetration Testing Actually Works
Pentesting, short for penetration testing, is an authorised, simulated attack on your organisation’s systems, carried out by a security professional using the same techniques a real attacker would, to find exploitable vulnerabilities before someone with genuinely bad intentions does.
How pentesting differs from a vulnerability scan
These two are often confused but they’re not the same thing. A vulnerability scan is largely automated, it checks systems against a database of known issues and flags what it finds, quickly and at relatively low cost. A penetration test goes further, a skilled tester actively tries to exploit what they find, chains weaknesses together the way a real attacker would and looks for issues automated tools simply can’t identify, like flawed business logic or weaknesses that only appear when several small issues are combined. A scan tells you what might be wrong, a pentest tells you what’s actually exploitable.
The types of pentesting
Penetration testing covers several distinct areas, and which ones matter depends on your organisation’s systems. Network pentesting examines your internal or external network infrastructure for exploitable weaknesses. Web application testing looks specifically at custom-built websites and applications, often where the most organisation-specific vulnerabilities sit. Testing can also extend to wireless networks, cloud environments and even physical or social engineering scenarios, depending on scope. A good testing provider will help you scope the right combination for your actual risk, rather than defaulting to a generic package.
How a pentest actually runs
A typical engagement starts with agreeing scope, exactly which systems are in play and what’s explicitly out of bounds, since testing without clear boundaries carries real risk to live systems. The tester then works through reconnaissance, identifying the attack surface, active testing, attempting to exploit what they find, and reporting, a detailed account of what was found, how it was exploited, and how serious each issue actually is, not just a raw list of findings. The report should prioritise issues by real-world risk, so you know what needs fixing first.
Why pentesting matters beyond ticking a box
It’s tempting to treat pentesting as something done purely to satisfy a client requirement or an insurance condition, and it often is required for exactly those reasons. But the underlying value is real, independent, expert verification that the controls you believe are in place are actually working, tested the way a genuine attacker would test them rather than assumed to be effective because they were configured correctly on paper.
Questions organisations usually ask about pentesting
Will a pentest disrupt our live systems? Scope and timing are agreed in advance specifically to manage this, testing can be scheduled outside business hours, restricted to non-production environments where appropriate, and any potentially disruptive technique is discussed with you before it’s attempted, not sprung on you mid-test.
What’s the difference between a pentest and a red team exercise? A pentest works against an agreed, defined scope over a set time. A red team exercise is broader and more adversarial, simulating a real attacker’s full approach, often without your internal security team knowing it’s happening, to test detection and response as well as raw vulnerability. Most organisations start with pentesting and consider red teaming once their basics are already solid.
Do we need a pentest if we already run vulnerability scans regularly? Scanning and testing serve different purposes, and most well-run security programmes use both, scanning as a frequent, automated check, and pentesting periodically for the deeper, human-led assessment that a scan genuinely can’t replicate.
What happens after the report lands, do you help fix what’s found? A pentest report should give you enough detail to remediate the issues found, prioritised by real risk, and many providers offer follow-up retesting once fixes are in place to confirm the issue is genuinely closed, not just addressed on paper.
How often you should test
There’s no single universal answer, but common triggers include a set annual or biannual schedule, any significant change to your systems, a new application, a major infrastructure change, before a security-conscious client or partner requires evidence, and after any security incident, to confirm the underlying issue is genuinely resolved rather than just patched on the surface. Systems and threats both change continuously, so a test from two years ago tells you very little about your risk today.
If you want to know where your organisation’s systems would actually give way under real attack, our Penetration Testing service is built to find out properly.
Cyber Security Support
Cyber security support is an ongoing, retained service that gives your organisation continued access to expert security guidance. Rather than a single project with a fixed end date, it’s a standing relationship, someone you can turn to as questions, decisions and issues come up, rather than starting from scratch every time.
How support differs from a one-off consultancy project
A consultancy engagement usually has a defined scope and a clear finish line, a risk assessment, a set of recommendations, a report. Support is different, it continues after that point, or exists without a single defined project at all. It covers the ongoing questions that come up in the normal course of running a business, a new supplier wants to know about your security posture, a new system is being considered, a policy needs updating, staff need guidance on something that’s come up. Rather than each of those becoming its own separate piece of work, a support arrangement means there’s already someone who knows your organisation and can respond.
What cyber security support typically includes
The specifics vary by provider and by what an organisation actually needs, but a well-structured support service generally covers regular access to expert advice, rather than needing to scope and commission a new project for every question, help reviewing new suppliers, systems, or projects from a security perspective before they’re committed to, ongoing policy and process guidance, keeping your documentation and practices current as the organisation and the threat landscape change, and support if something does go wrong, having an established relationship in place before an incident happens makes response considerably faster than starting from nothing under pressure.
Why ongoing support matters more than a single review
Security isn’t a state you reach and then leave alone, it’s a moving target. New systems get introduced, staff change, suppliers change and the threat landscape itself shifts constantly. A single assessment gives you an accurate picture of your risk at one point in time, but that picture starts going stale almost immediately. Ongoing support means someone is tracking that drift with you, rather than your organisation only finding out its security posture has moved when the next periodic review happens, often after something’s already gone wrong.
Who cyber security support is for
It suits organisations that don’t have the scale to justify a full-time, dedicated security specialist on staff, but that handle enough data, systems, or risk that having nobody responsible for security questions is a genuine gap. It’s also valuable for organisations already working with a consultant on a specific project, since support extends that relationship past the project’s end date rather than leaving you without anyone to ask once the initial engagement closes.
Questions organisations usually ask about ongoing support
How is support usually priced? Typically a retained monthly or annual fee scaled to your organisation’s size and how much contact you need, rather than paying separately for every question or decision. This is deliberately different from project-based consultancy pricing, since the value of support comes from continuity, not from billing per incident.
What’s the difference between support and just calling a consultant when something comes up? Without an existing relationship, every new question starts from zero, scoping the work, explaining your organisation’s context, agreeing a fee, before any actual help arrives. Support removes that friction entirely, the person you’re contacting already knows your systems, your history, and your risk profile.
Can support scale up if something serious happens? Yes, a well-structured support arrangement typically includes a defined path for exactly this, more intensive involvement during an active incident or a major change, rather than being capped at a fixed light-touch level regardless of what’s actually needed at the time.
Is support only for organisations without any internal security capability? No, it’s equally common for organisations with some internal resource to use support as additional capacity and expertise, covering gaps, giving a second opinion, or handling specialist areas that don’t justify a dedicated internal hire.
Getting the right level of support
Support arrangements can be scaled to what an organisation actually needs, from a lighter-touch retained advisory relationship through to more hands-on, regular involvement in day-to-day decisions. The right level depends on your organisation’s size, how much your systems and risk profile change and how much internal capability you already have. Getting this right usually starts with an honest look at how often security questions actually come up and how they’re currently being handled, or not handled, today.
If your organisation needs ongoing access to expert security guidance rather than a single one-off review, our Cyber Security Support service is built for exactly that.
What Cyber Security Consultancy Actually Covers
Cyber security consultancy is independent expert advice on identifying, prioritising and managing your organisation’s information security risk. Rather than a single product or a fixed technical check, it’s guidance shaped around your actual business, what data and systems you have, what threatens them, and what a sensible, proportionate response looks like.
What a cyber security consultant actually does
A consultant’s work typically starts with understanding what you have and what matters most, your critical systems, your data and where the real exposure sits. From there, the work usually covers risk assessment, identifying and prioritising the threats most relevant to your organisation, policy and process development, building the governance that sits behind good security practice, incident response planning, so you know what happens if something does go wrong, and ongoing advice as your organisation, your systems, and the threat landscape all change over time.
Consultancy versus a specific technical service
It’s worth being clear about how this differs from a named technical service like penetration testing or ISO 27001 certification. Those are specific, defined pieces of work with a clear scope and a clear output, a test report, a certificate. Consultancy is broader and more advisory, it often points toward those specific services as part of a wider plan, rather than being one itself. A good consultancy engagement will usually tell you which specific technical work, if any, you actually need, rather than assuming you need everything.
Why organisations bring in a consultant rather than handling security internally
Few organisations outside large enterprises have a dedicated, senior security specialist on staff, and cyber security is a genuinely broad field, technical controls, governance, regulatory obligations, and incident response all draw on different expertise. Bringing in a consultant gives you access to that breadth without the cost of building an internal security function from scratch, and it gives you an independent perspective, someone assessing your risk without the internal politics or blind spots that can affect how an organisation sees its own weaknesses.
What a good consultancy engagement should produce
You should come away from a proper consultancy engagement with a clear picture of your actual risk, not a generic list of best practices, a prioritised set of recommendations that reflects what genuinely matters for your organisation rather than everything technically possible and a realistic view of cost and effort, so decisions can actually be made and acted on rather than filed away. If an engagement doesn’t leave you able to explain your top three security risks and what you’re doing about them, it hasn’t done its job.
Questions organisations usually ask before bringing in a consultant
How is a consultancy engagement usually priced? Most commonly either a fixed fee for a defined piece of work, a risk assessment with a report and recommendations, or day-rate work for more open-ended engagements. A good consultant scopes this with you upfront so cost is clear before work starts, rather than becoming open-ended once underway.
Will a consultant just tell us to buy expensive technical solutions? A good one won’t. The point of independent consultancy is a recommendation shaped by your actual risk and budget, not a sales process for a particular product or vendor. If every recommendation happens to point toward one specific tool, that’s worth questioning.
Do we need consultancy if we already have an IT provider? Often yes, and the two aren’t the same thing. An IT provider typically keeps systems running and supported, which is necessary but different from an independent assessment of security risk and governance. Many organisations use consultancy specifically to get a view that isn’t shaped by whoever also benefits commercially from the technical decisions made afterward.
What if the consultant finds something serious straight away? A properly run engagement flags anything urgent immediately, rather than waiting for a final report, so you can act on genuine risk as soon as it’s identified rather than sitting on it for weeks while the rest of the assessment continues.
When to bring in cyber security consultancy
The most common triggers are a specific event, a near miss, an incident at a similar organisation, a new client or contract that expects evidence of good practice, a genuine unknown, uncertainty about where your actual exposure sits, or a planned change, a new system, a merger, or expansion into a new market that changes your risk profile. It’s also worth treating security as an ongoing conversation rather than a one-off project, threats and systems both change, and a consultancy relationship that continues past the first engagement tends to catch problems earlier than a single audit ever could.
If you want an honest, independent view of where your organisation’s cyber security risk actually sits, our Cyber Security Consultancy service is built to give you exactly that.
ISO 27001 Certification: What’s Actually Involved
ISO 27001 is the international standard for an Information Security Management System, or ISMS. It’s not a single technical control or a piece of software, it’s a structured framework for how an organisation identifies its information security risks, decides how to manage them, and proves it’s actually doing so consistently.
What an ISMS actually is
An ISMS is the set of policies, processes, and controls an organisation puts in place to protect the confidentiality, integrity and availability of its information. ISO 27001 doesn’t tell you exactly which technical tools to buy, it tells you how to build a management system that identifies your actual risks and applies proportionate controls to them, then keeps reviewing whether those controls are still working.
The certification process
Getting certified to ISO 27001 involves building the ISMS itself, running a risk assessment across the organisation, implementing the controls that risk assessment points to, and then going through an external audit carried out by an accredited certification body. The audit typically happens in two stages, a review of your documentation and readiness, followed by a more detailed assessment of whether the ISMS is genuinely operating as described. Certification isn’t permanent, it’s maintained through ongoing surveillance audits, usually annually, with full recertification typically every three years.
Annex A and the control set
ISO 27001 includes a reference set of controls, known as Annex A, covering areas like access control, physical security, supplier relationships, incident management and business continuity. Not every control applies to every organisation, part of the process is justifying which controls are relevant to your specific risks and which genuinely aren’t, documented in what’s called a Statement of Applicability.
Why organisations pursue it
A few reasons come up consistently. Certification is increasingly a requirement to win or retain contracts, particularly with larger clients, public sector bodies and organisations that handle sensitive data through their supply chain, since it gives a third party independent evidence of your security posture rather than just your own word for it. It also forces a level of internal discipline that many organisations wouldn’t otherwise get around to, a proper risk assessment, clear ownership of security decisions and a documented incident response process. For organisations already required to demonstrate strong data protection practices, having a recognised ISMS in place makes it considerably easier to evidence that seriously.
ISO 27001 versus other cyber security standards
It’s worth being clear about how ISO 27001 differs from other things it sometimes gets confused with. Cyber Essentials is a narrower, UK government-backed scheme focused on a specific set of technical controls, it’s faster and cheaper to achieve but covers considerably less ground than a full ISMS. PCI DSS is specific to organisations handling payment card data. ISO 27001 is broader than either, covering the management system around information security generally, not just a fixed technical checklist or a single type of data.
Questions organisations usually ask about ISO 27001
How long does certification usually take? For most small and mid-sized organisations, building the ISMS and getting through both audit stages typically takes several months, largely driven by how mature your existing documentation and controls already are, not just the size of the organisation. Starting from close to nothing takes considerably longer than formalising practices that already exist informally.
Do we need to certify the whole organisation, or can we scope it to part of the business? You can define the scope of your ISMS deliberately, certifying a specific department, service line, or set of systems rather than the entire organisation, provided that scope is clearly documented and genuinely reflects where the relevant risk sits. Many organisations start with a narrower scope and expand it over time.
What’s the difference between ISO 27001 and Cyber Essentials in practical terms? Cyber Essentials is faster, cheaper, and covers a fixed set of technical controls, a good baseline. ISO 27001 is a full management system covering governance, risk assessment, and a much broader control set, verified by external audit rather than self-assessment. Many organisations hold both, Cyber Essentials as a baseline and ISO 27001 as the more comprehensive standard clients and larger contracts increasingly expect.
What happens if an audit finds a nonconformity? It’s not an automatic failure. Auditors typically distinguish between minor nonconformities, which you address within an agreed timeframe while keeping certification on track, and major ones, which need resolving before certification is granted. A well-prepared organisation usually finds and fixes the significant gaps itself before the external audit ever happens.
Is ISO 27001 right for your organisation
Certification makes most sense for organisations that handle sensitive or high-volume data, operate in sectors where clients or regulators expect independent assurance, or are regularly asked by procurement processes to prove their security posture. For smaller organisations without those pressures, the investment of time and cost needs weighing against the actual demand for it from your clients and market. The starting point either way is usually the same, a proper gap analysis against the standard, so you know exactly what you’d need to build before committing to the certification process itself.
If you want to understand where your organisation currently stands against ISO 27001, or you’re ready to start the certification journey properly, our ISO 27001 service is built to guide you through it.
PCI DSS Explained: What It Actually Requires
PCI DSS stands for the Payment Card Industry Data Security Standard. It’s a set of security requirements created by the major card schemes (Visa, Mastercard and the others) that applies to any organisation that stores, processes, or transmits cardholder data, regardless of size or sector.
Who PCI DSS actually applies to
If your organisation takes card payments in any form, in person, online, or over the phone, PCI DSS applies to you. That includes retailers, hospitality businesses, healthcare providers, charities taking donations by card, and any organisation using a third-party payment processor. Using a payment provider reduces some of your obligations, but it doesn’t remove them entirely, you still need to understand what that provider is doing on your behalf and confirm it’s compliant.
What the standard actually requires
PCI DSS is built around a set of control areas rather than a single checklist. In broad terms, organisations need to: build and maintain a secure network, protect stored cardholder data, encrypt data in transit, use and update anti-malware protection, restrict access to cardholder data on a need-to-know basis, monitor and test networks regularly, and maintain a formal information security policy. The specific technical requirements underneath each of these depend on how much card data your organisation handles and how you handle it.
The compliance levels
PCI DSS applies different levels of scrutiny depending on transaction volume. Smaller organisations typically complete a Self-Assessment Questionnaire (SAQ), a structured set of questions covering the relevant controls. Larger organisations, generally those processing millions of transactions a year, need an external assessment carried out by a Qualified Security Assessor (QSA). Which level and which SAQ type applies depends on exactly how your organisation takes payments, so this isn’t something to assume from general size alone.
Why PCI DSS matters beyond the requirement itself
PCI DSS compliance isn’t optional in the way some standards are. Card schemes and acquiring banks can apply fines for non-compliance, and in the event of a card data breach, an organisation that wasn’t compliant faces significantly more exposure, both financially and reputationally, than one that can demonstrate it met the standard. There’s also a genuine security argument underneath the compliance requirement, cardholder data is one of the most consistently targeted types of data, and the controls PCI DSS requires exist because they address real, common attack methods.
PCI DSS and UK GDPR are not the same thing
It’s worth being precise here. PCI DSS is a payment card industry standard, not a UK GDPR requirement. Cardholder data is personal data, so UK GDPR still applies to how you handle it, but meeting PCI DSS doesn’t automatically mean you’re meeting your UK GDPR obligations, and vice versa. Organisations that treat the two as interchangeable often end up with a security programme that satisfies one and quietly misses parts of the other.
Questions organisations usually ask about PCI DSS
Does using a payment processor like Stripe or Worldpay mean we’re already compliant? No, though it does reduce your workload considerably. A reputable processor handles a large share of the technical requirements, but your organisation still needs to complete the relevant SAQ, follow secure practices around how payment pages are built and hosted and confirm the processor’s own compliance rather than assuming it. Outsourcing the technology doesn’t outsource the responsibility.
What actually happens if we’re not compliant and suffer a breach? Consequences typically include fines from the card schemes or your acquiring bank, potential loss of the ability to process card payments at all, and considerably higher costs if a breach investigation finds you weren’t meeting the standard at the time. Compliance doesn’t prevent every breach, but it materially changes the financial and reputational outcome if one happens.
Do small organisations really need to worry about this? Yes, though the level of scrutiny scales with volume. Even a small organisation taking a modest number of card payments a year has an SAQ obligation, it’s simply a shorter, less intensive one than a large retailer would face. The requirement doesn’t have a size threshold below which it stops applying.
How long does becoming compliant usually take? This depends heavily on your current setup, but establishing scope, completing the right SAQ and closing any gaps typically takes a matter of weeks for a straightforward small or mid-sized organisation, longer if cardholder data touches more systems than expected once you actually map it out properly.
Getting started with PCI DSS compliance
The first practical step is usually establishing your actual scope, working out exactly where cardholder data enters, moves through and leaves your systems, since PCI DSS requirements apply specifically to that scope, not your whole IT estate. From there, the right SAQ type or assessment path becomes much clearer, along with which of the control areas above need real attention versus which are already covered.
If you’re not sure where your organisation sits with PCI DSS, or you know you need to get compliant and want it handled properly rather than guessed at, our PCI DSS service is built for exactly this.
What an Outsourced DPO Actually Does
An outsourced DPO is a qualified Data Protection Officer who works for your organisation without being your employee. You get the same role, the same legal duties and the same point of accountability that an in-house DPO would provide, just delivered as a service rather than a salary.
What a DPO actually does
Under UK GDPR, a Data Protection Officer monitors your organisation’s compliance with data protection law, advises staff and leadership on their obligations, acts as the contact point for the Information Commissioner’s Office (ICO) and handles enquiries from the people whose data you hold. The DPO doesn’t do the processing themselves, they oversee it, flag risk and make sure the organisation can demonstrate it’s meeting its obligations if asked.
Who actually needs one
UK GDPR requires a DPO for public authorities, and for any organisation whose core activities involve large-scale, regular and systematic monitoring of individuals, or large-scale processing of special category data (health records, criminal offence data and similar). Plenty of organisations outside those categories choose to appoint one anyway, generally because they handle enough personal data that having a named, accountable expert reduces real risk, not because the law requires it in their case. If you’re not sure which category you fall into, that’s usually the first question worth answering before deciding on the DPO question at all.
Why organisations outsource the role rather than hire for it
A few reasons come up consistently:
Hiring a full-time, qualified DPO is expensive, and for most organisations there isn’t enough day-to-day work to justify a full salary. An outsourced DPO gives you the expertise at a fraction of the cost of a permanent hire.
An internal DPO can end up with a conflict of interest if they also hold another senior role, since the DPO is meant to operate independently and report any issues without being compromised by their own operational responsibilities elsewhere in the business. An external DPO doesn’t have that conflict.
You get access to a wider team, not just one person. When a DPO works alongside colleagues who specialise in different areas, subject access requests, breach response, DPIAs, you’re covered even when one specific issue falls outside their personal specialism.
It’s also faster to start. Recruiting, vetting, and training an internal DPO can take months. An outsourced service is already in place and already qualified.
What to expect from the service day to day
A properly run outsourced DPO service isn’t a once-a-year sign-off. It should include regular contact with your organisation, advice on specific decisions as they come up (a new supplier, a new system, a marketing campaign that touches personal data), oversight of your data protection processes and direct handling of ICO contact if it’s ever needed. You should always know who your DPO is and how to reach them, the same as you would with an internal hire.
Common misconceptions
An outsourced DPO is not the same as general data protection consultancy. Consultancy is project-based advice, an outsourced DPO is an ongoing, named, accountable role with specific legal duties attached to it. It’s also not a way to transfer legal responsibility away from your organisation, the DPO advises and oversees, but your organisation remains the data controller and carries the ultimate accountability for compliance.
Questions organisations usually ask before appointing one
Can one DPO work for several organisations at once? Yes, this is normal practice for an outsourced service, and it’s specifically permitted under UK GDPR provided the DPO can genuinely prioritise and give each organisation proper attention, and provided there’s no conflict of interest between the organisations involved. A reputable outsourced provider manages this deliberately, not as an afterthought.
What happens if someone internally already handles some of this? Common situation, and not a problem. Many organisations already have someone fielding data protection questions informally, often alongside a completely different job. An outsourced DPO doesn’t replace that person’s day-to-day work, it gives the organisation a properly qualified, independent, named point of accountability that the informal arrangement usually can’t provide, while your existing staff member becomes the internal point of contact the DPO works through.
How is cost usually structured? Typically a fixed monthly or annual retainer based on the size of your organisation, how much personal data you process and how much day-to-day contact you need, rather than being billed hour by hour for every query. This makes budgeting considerably more predictable than either an internal hire or ad hoc consultancy.
What happens if the ICO does contact us? This is one of the clearest reasons to have a DPO in place before you need one. Your DPO handles that contact directly, on your behalf, drawing on experience of exactly this kind of engagement, rather than your organisation trying to manage a regulator conversation for the first time with no one who’s done it before.
Is an outsourced DPO right for your organisation
If you’re required to have one under UK GDPR, the question isn’t whether, it’s how. If you’re not required to but handle a meaningful volume of personal data, weigh the cost of an outsourced service against the actual risk of not having anyone clearly accountable for data protection in your organisation. For most small and mid-sized organisations, outsourcing gives you a properly qualified DPO without the overhead of a full-time role.
If you want to know whether your organisation needs a DPO, or you already know you do and want to see how an outsourced service would actually work for you, our Outsourced DPO service covers exactly this.
How DPP Helped Progeny Build a Mature Data Protection and Information Governance Framework
The Challenge
DPP’s engagement with Progeny has centred on establishing and maturing Progeny’s data protection and information governance framework across the Asset and Wealth Management businesses.
What DPP Did
DPP has undertaken a large-scale data mapping project to identify processing activities, data flows, retention requirements, security measures, international transfers and lawful bases for processing. Detailed workshops have taken place with Finance, HR, Marketing, IT, Estates Management, Strategic Operations, Digital and Advisory Services amongst other departments, from which a comprehensive and up to date Record of Processing Activities (ROPA, the internal log of what personal data an organisation holds and why) has been produced.
Alongside the data mapping programme, substantial advisory support has been provided in relation to information governance, privacy compliance and emerging technologies. This has included reviewing and enhancing key policies such as Progeny’s Data Retention and Destruction Standard, Data Classification Standard and DPIA Policy (Data Protection Impact Assessment Policy, the process for identifying and reducing privacy risk before a new project goes live), as well as providing specialist advice on proposed AI integrations to ensure risk management is embedded from the outset. This has involved assessing UK GDPR implications, international transfer considerations, DPIA requirements, staff guidance needs and wider regulatory obligations relevant to the financial services sector.
Additional support has also been provided on data subject rights processes, including SAR (Subject Access Request) and DSAR handling, redaction services, rights request procedures and governance documentation.
The Outcome
Establishing the ROPA has provided the foundation for wider governance initiatives, including the development of an organisation-wide retention schedule and information asset register, which are the focus of recent efforts. This work has helped Progeny continue to develop a more mature and operationalised privacy framework.
DPP continues to work closely with Progeny to mature its data protection and information governance frameworks and drive towards the highest standard of compliance and best practice.
“Mark is really invested in the role he provides as DPO and the Service Desk always reply promptly and with well reasoned responses.”
Martin Ankers, Progeny
Get in touch
If your organisation needs support building or maturing its data protection and information governance framework, DPP’s Outsourced DPO service can help.