Our Expert in Italy
No results available
In-house vs external DPO Italy is one of the most consequential data protection decisions facing Italian businesses in 2026, and the calculus continues to evolve. The Garante per la protezione dei dati personali maintains clear expectations on DPO independence and resourcing, communication of the Data Protection Officer’s contact details to the authority is an established requirement, and the interaction between the EU AI Act and the DPO’s remit has widened the role’s technical scope. For general counsels, HR directors and compliance officers, this is no longer a theoretical governance question, it is a live operational choice with cost, liability and enforcement consequences.
This guide takes a clear position, benchmarks the costs, and gives you a decision framework you can act on within 30 days.
Our recommendation in one sentence: the majority of Italian SMEs and mid-market firms are likely to find an external DPO the more practical model in 2026; organisations with sustained high-risk processing and the resources to guarantee independence may prefer to build the role in-house.
The starting point for any DPO appointment in Italy is Article 37 of the General Data Protection Regulation (Regulation (EU) 2016/679), read alongside the Italian implementing framework in Legislative Decree No. 101/2018 (which amended the Personal Data Protection Code, Legislative Decree No. 196/2003) and the Garante’s guidance. Before you compare models, you must establish whether appointment is a legal obligation or a voluntary best practice, because the answer changes your liability exposure and your notification duties.
Under Article 37(1) GDPR, appointment of a DPO is mandatory where any of the following applies:
Where none of these triggers applies, appointment is voluntary, but if you appoint voluntarily, the DPO is subject to the same Articles 37–39 obligations as a mandatory appointment.
The Garante’s practical position, consistent with EDPB (formerly Article 29 Working Party) guidance, treats several common business activities as likely triggers when conducted at scale:
In advisory practice, many Italian companies underestimate how quickly ordinary HR plus CRM profiling can approach the “regular and systematic monitoring” threshold. When in doubt, document a formal assessment of whether Art. 37 applies and retain it, the assessment itself is evidence of accountability.
The Garante’s guidance emphasises expectations that apply equally whether you go in-house or external: genuine independence, adequate resources, and communication of the appointed DPO’s contact details to the authority. These are not optional formalities, failure to notify or resource the DPO properly is itself an enforcement risk, independent of any underlying data breach.
Under Article 37(7) GDPR, the controller or processor must publish the DPO’s contact details and communicate them to the supervisory authority. In Italy, the Garante provides an official online procedure for this. In practice, the process follows a predictable sequence:
Crucially, you must update the communication whenever the DPO changes or their contact details change. For an external DPO, verify who bears the notification and update obligation, this should be explicit in the contract. Confirm the current procedure directly on the Garante’s site before filing.
Article 38 GDPR requires that the DPO be involved properly and in a timely manner in all data protection matters, report to the highest management level, and be free from instructions on how to perform their tasks. The Garante scrutinises reporting lines closely: a DPO who reports into IT, marketing or a business unit that determines processing purposes is a red flag. The DPO cannot be dismissed or penalised for performing their duties, and cannot hold a role that creates a conflict of interest, for example, a CIO, HR director or head of marketing generally cannot double as DPO.
With the EU AI Act (Regulation (EU) 2024/1689) reshaping obligations around high-risk automated systems, the DPO is increasingly expected to advise on AI-related processing, profiling and data governance, widening the competence bar for both in-house and external candidates.
An in-house DPO is an employee (or seconded internal appointee) who performs the Article 39 tasks from within the organisation. This model buys proximity and availability, but it carries recruitment, cost and conflict-of-interest risks that many Italian companies underestimate.
Under Article 39 GDPR, the DPO’s core tasks are to:
An in-house DPO with deep organisational knowledge can perform these tasks with unmatched speed and context, they know the systems, the processing flows and the people.
Salary depends heavily on organisation size, sector and seniority. As indicative benchmark estimates, to be validated against current market data, Italian in-house DPO compensation in 2026 typically falls in these ranges:
These figures are indicative market estimates, not published statutory rates. Add recruitment costs, ongoing training (particularly on AI governance), and the redundancy/continuity risk if the individual leaves. Contrast this with external legal or consultancy fees discussed below.
The most common failures are structural. Appointing a manager who also decides processing purposes creates a prohibited conflict of interest under Article 38(6). Placing the DPO several layers below the board can breach the requirement to report to the highest management level. And a single individual can become a single point of failure during absence, illness or departure. If you go in-house, you must ring-fence the role, guarantee direct board access, and document independence in writing.
An external DPO is appointed under a service contract, an individual consultant, a law or advisory firm providing an outsourced DPO function, or a shared DPO serving several group entities. Article 37(6) GDPR expressly permits the DPO to fulfil the role on the basis of a service contract. For the in-house vs external DPO Italy decision, this model is often the pragmatic choice for organisations that need independence and breadth without a permanent headcount.
The following are indicative benchmark estimates drawn from market observation and should be validated against current quotations:
These ranges are indicative and vary with scope, response-time commitments and industry. The headline advantage is cost predictability and access to a team’s collective experience, an external provider is often exposed to a wider range of enforcement patterns than a single in-house officer.
An external DPO is only as good as its contract. Insist on defined response times, robust confidentiality and data-handling obligations, documented conflict-of-interest checks, professional indemnity insurance, and clear termination and handover provisions. Availability is the classic weakness of outsourced models, a service-level agreement addresses it.
The table below is the centrepiece of the in-house vs external DPO Italy decision. Read it as a diagnostic: count how many rows point to your circumstances on each side.
| Dimension | In-house DPO | External DPO |
|---|---|---|
| Best suited to | Large or high-risk processors with continuous data protection workload | SMEs, mid-market firms, and groups needing predictable, independent coverage |
| Cost structure | €40k–€150k+ salary plus training, recruitment and continuity costs (estimate) | €8k–€25k/yr (SME) to €3k–€10k+/month (large) retainer (estimate) |
| Independence & conflicts | Risk if role overlaps with operational duties; must be ring-fenced | Structurally independent by design; verify no cross-client conflicts |
| Availability / responsiveness | Immediate; embedded in the business | Governed by service levels; can lag without defined response times |
| Institutional knowledge | Deep, knows systems, flows and people | Broader cross-sector experience; slower on internal specifics |
| Recruitment / termination friction | High, hiring, redundancy and single-point-of-failure risk | Low, scalable contract, easier to change provider |
| Garante communication & updates | Internal responsibility; update on staff change | Assign notification/update duty explicitly in contract |
| AI competence | Requires ongoing investment in AI governance training | Often available as team capability across clients |
| Liability & insurance | Employer bears exposure; individual professional cover limited | Provider may carry professional indemnity insurance |
| Contractual controls | Employment terms plus written appointment | Service agreement, confidentiality, conflict checks, handover clauses |
| Enforcement risk profile | Strong if independence maintained; weak if conflicted | Strong on independence; manage availability and continuity |
| Ideal organisational profile | High-volume, high-risk, well-resourced | Cost-conscious, breadth-seeking, lower continuous workload |
The dominant tradeoff: in-house buys proximity and speed at the price of cost and conflict risk; external buys independence, breadth and predictability at the price of availability, which strong service levels can neutralise. If your processing is continuous and high-risk and you can fund an independent role, in-house may suit. If you are an SME or need structural independence without headcount, external is often preferable. For many Italian businesses in 2026, that points to external.
Use the following decision rules. Work through them in order; the first firm “yes” usually informs the answer.
Track A, Appointing an in-house DPO:
Track B, Contracting an external DPO:
Track C, Interim external DPO before an internal hire: appoint an external DPO immediately to close the compliance gap, communicate their details, and run recruitment in parallel, then transfer the function with a documented handover once the internal hire is onboarded.
SME with HR + CRM profiling. A 90-employee retailer runs employee monitoring and large-scale customer segmentation. The processing may trigger Art. 37, but the workload is not continuous and budget is tight. Illustrative recommendation: external DPO on a fixed monthly retainer, predictable cost, guaranteed independence, no recruitment risk.
Large AI company performing high-risk profiling. A technology firm deploys automated decision-making across millions of users. Processing is continuous, high-risk and AI-intensive. Illustrative recommendation: in-house DPO with board reporting, supported where needed by external specialist counsel for AI Act and enforcement matters.
Whichever model you choose, the appointment must be documented. For an external DPO, the service contract is your primary compliance instrument; for an in-house DPO, a written appointment plus employment terms performs the same function.
Retain the Garante notification receipt, the written appointment or service contract, conflict-of-interest declarations, and a record of the DPO’s independence and reporting line. On any change of DPO, update the details communicated to the Garante promptly and archive the previous confirmation. This documentation is your first line of defence in any supervisory inquiry.
The in-house vs external DPO Italy decision in 2026 rewards clarity over hedging. For many Italian SMEs and mid-market companies, an external DPO delivers the independence the Garante expects, predictable cost, cross-sector experience and, where the provider is insured, additional liability protection, without recruitment or continuity risk. The in-house model tends to suit organisations with continuous, high-risk processing and the resources to guarantee a conflict-free role reporting directly to the board. Whichever path you choose, act now: confirm your Article 37 position, communicate the DPO’s details to the Garante, and put a documented appointment or service agreement in place. Explore Data Protection Lawyers, Italy and the expert profile for tailored support.
This content is for general information and does not constitute legal advice. Contact a qualified lawyer for specific advice.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Susanna Greggio at GTA Studio Legale, a member of the Global Law Experts network.
posted 38 minutes ago
posted 60 minutes ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 4 hours ago
posted 4 hours ago
posted 4 hours ago
posted 4 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message