[codicts-css-switcher id=”346″]

Global Law Experts Logo
in-house vs external dpo italy

In‑house vs External DPO in Italy (2026): When to Appoint, Costs & Garante Expectations

By Global Law Experts
– posted 55 minutes ago

In-house vs external DPO Italy is one of the most consequential data protection decisions facing Italian businesses in 2026, and the calculus continues to evolve. The Garante per la protezione dei dati personali maintains clear expectations on DPO independence and resourcing, communication of the Data Protection Officer’s contact details to the authority is an established requirement, and the interaction between the EU AI Act and the DPO’s remit has widened the role’s technical scope. For general counsels, HR directors and compliance officers, this is no longer a theoretical governance question, it is a live operational choice with cost, liability and enforcement consequences.

This guide takes a clear position, benchmarks the costs, and gives you a decision framework you can act on within 30 days.

TL;DR, The In-house vs External DPO Italy Decision in Three Lines

  • Choose in-house if you are a large organisation with continuous, high-volume or high-risk processing (large-scale profiling, systematic monitoring, significant AI deployment) and the budget to fund a dedicated, conflict-free role with proper reporting lines.
  • Choose external if you are an SME, a mid-market company, or a group needing predictable costs, breadth of cross-sector experience, and structural independence without the recruitment and redundancy risk of a permanent hire.
  • Do this now regardless of model: confirm whether appointment is mandatory under Art. 37 GDPR, communicate the DPO’s contact details to the Garante, and put a written appointment or a robust service agreement in place with confidentiality, independence and conflict-of-interest clauses.

Our recommendation in one sentence: the majority of Italian SMEs and mid-market firms are likely to find an external DPO the more practical model in 2026; organisations with sustained high-risk processing and the resources to guarantee independence may prefer to build the role in-house.

When Is a DPO Required in Italy?

The starting point for any DPO appointment in Italy is Article 37 of the General Data Protection Regulation (Regulation (EU) 2016/679), read alongside the Italian implementing framework in Legislative Decree No. 101/2018 (which amended the Personal Data Protection Code, Legislative Decree No. 196/2003) and the Garante’s guidance. Before you compare models, you must establish whether appointment is a legal obligation or a voluntary best practice, because the answer changes your liability exposure and your notification duties.

Legal triggers (Art. 37 GDPR)

Under Article 37(1) GDPR, appointment of a DPO is mandatory where any of the following applies:

  • Public authority or body. Processing is carried out by a public authority or body, except courts acting in their judicial capacity.
  • Regular and systematic monitoring at scale. The core activities of the controller or processor consist of processing operations that, by their nature, scope or purposes, require regular and systematic monitoring of data subjects on a large scale.
  • Large-scale special category or criminal data. The core activities consist of processing on a large scale of special categories of data (Art. 9) or personal data relating to criminal convictions and offences (Art. 10).

Where none of these triggers applies, appointment is voluntary, but if you appoint voluntarily, the DPO is subject to the same Articles 37–39 obligations as a mandatory appointment.

Practical thresholds for Italy (Garante interpretation)

The Garante’s practical position, consistent with EDPB (formerly Article 29 Working Party) guidance, treats several common business activities as likely triggers when conducted at scale:

  • HR and workforce monitoring involving systematic employee data processing, geolocation, or productivity tracking.
  • Marketing and CRM profiling that scores, segments or predicts behaviour across large customer bases.
  • CCTV and video surveillance deployed systematically across premises or public-facing spaces.
  • AI-driven profiling, automated decision-making and behavioural inference now attract heightened scrutiny.

In advisory practice, many Italian companies underestimate how quickly ordinary HR plus CRM profiling can approach the “regular and systematic monitoring” threshold. When in doubt, document a formal assessment of whether Art. 37 applies and retain it, the assessment itself is evidence of accountability.

Garante Expectations & Communicating the DPO’s Details

The Garante’s guidance emphasises expectations that apply equally whether you go in-house or external: genuine independence, adequate resources, and communication of the appointed DPO’s contact details to the authority. These are not optional formalities, failure to notify or resource the DPO properly is itself an enforcement risk, independent of any underlying data breach.

Communicating the DPO’s contact data, practical steps

Under Article 37(7) GDPR, the controller or processor must publish the DPO’s contact details and communicate them to the supervisory authority. In Italy, the Garante provides an official online procedure for this. In practice, the process follows a predictable sequence:

  1. Authenticate to the Garante’s online service using recognised digital identity credentials (such as SPID or CIE), consistent with the digital authentication standards promoted by the Agenzia per l’Italia Digitale (AgID).
  2. Enter controller/processor details, legal name, VAT/fiscal code, sector and contact data.
  3. Enter the DPO’s contact data, name (or the name of the external provider), email and telephone through which data subjects and the Garante can reach the DPO directly.
  4. Submit and retain confirmation. Keep the submission receipt as part of your accountability documentation.

Crucially, you must update the communication whenever the DPO changes or their contact details change. For an external DPO, verify who bears the notification and update obligation, this should be explicit in the contract. Confirm the current procedure directly on the Garante’s site before filing.

Independence & reporting lines the Garante watches

Article 38 GDPR requires that the DPO be involved properly and in a timely manner in all data protection matters, report to the highest management level, and be free from instructions on how to perform their tasks. The Garante scrutinises reporting lines closely: a DPO who reports into IT, marketing or a business unit that determines processing purposes is a red flag. The DPO cannot be dismissed or penalised for performing their duties, and cannot hold a role that creates a conflict of interest, for example, a CIO, HR director or head of marketing generally cannot double as DPO.

Impact of AI obligations on DPO tasks

With the EU AI Act (Regulation (EU) 2024/1689) reshaping obligations around high-risk automated systems, the DPO is increasingly expected to advise on AI-related processing, profiling and data governance, widening the competence bar for both in-house and external candidates.

In-house DPO: Pros, Cons, Responsibilities and Approximate Costs

An in-house DPO is an employee (or seconded internal appointee) who performs the Article 39 tasks from within the organisation. This model buys proximity and availability, but it carries recruitment, cost and conflict-of-interest risks that many Italian companies underestimate.

Typical role & duties in practice

Under Article 39 GDPR, the DPO’s core tasks are to:

  • Inform and advise the controller, processor and staff of their GDPR obligations.
  • Monitor compliance with the GDPR, other data protection law, and internal policies, including assigning responsibilities, awareness-raising and staff training.
  • Provide advice on data protection impact assessments (DPIAs) and monitor their performance.
  • Cooperate with the Garante and act as the contact point for the supervisory authority.

An in-house DPO with deep organisational knowledge can perform these tasks with unmatched speed and context, they know the systems, the processing flows and the people.

Recruitment & salary benchmarks (Italy 2026)

Salary depends heavily on organisation size, sector and seniority. As indicative benchmark estimates, to be validated against current market data, Italian in-house DPO compensation in 2026 typically falls in these ranges:

  • SME / smaller organisations: broadly in the region of €40,000–€80,000 per year for a dedicated or part-dedicated role.
  • Large enterprises / high-risk processors: broadly €80,000–€150,000+ per year for a senior, standalone DPO, often with a supporting team.

These figures are indicative market estimates, not published statutory rates. Add recruitment costs, ongoing training (particularly on AI governance), and the redundancy/continuity risk if the individual leaves. Contrast this with external legal or consultancy fees discussed below.

Compliance pitfalls for in-house DPOs (reporting lines, conflicts)

The most common failures are structural. Appointing a manager who also decides processing purposes creates a prohibited conflict of interest under Article 38(6). Placing the DPO several layers below the board can breach the requirement to report to the highest management level. And a single individual can become a single point of failure during absence, illness or departure. If you go in-house, you must ring-fence the role, guarantee direct board access, and document independence in writing.

External DPO: Pros, Cons, Responsibilities and Pricing Benchmarks (In-house vs External DPO Italy)

An external DPO is appointed under a service contract, an individual consultant, a law or advisory firm providing an outsourced DPO function, or a shared DPO serving several group entities. Article 37(6) GDPR expressly permits the DPO to fulfil the role on the basis of a service contract. For the in-house vs external DPO Italy decision, this model is often the pragmatic choice for organisations that need independence and breadth without a permanent headcount.

Typical service models (retainer / pay-per-incident / fractional DPO)

  • Fixed monthly retainer. A defined scope of ongoing advice, monitoring and contact-point duties for a predictable fee.
  • Fractional / shared DPO. One provider serving multiple entities in a group, spreading cost while maintaining a single accountable point of contact.
  • Retainer plus per-incident. A base retainer covering routine work, with ad-hoc fees for breach response, DPIAs, audits or regulatory correspondence.

Pricing benchmarks (Italy 2026)

The following are indicative benchmark estimates drawn from market observation and should be validated against current quotations:

  • SMEs: broadly €1,000–€3,000 per month, or roughly €8,000–€25,000 per year, depending on processing complexity and sector risk.
  • Larger companies: broadly €3,000–€10,000+ per month for a comprehensive outsourced DPO function.
  • Ad-hoc incident response: additional fees for breach management, DPIAs and regulatory representation, typically charged per matter or hourly.

These ranges are indicative and vary with scope, response-time commitments and industry. The headline advantage is cost predictability and access to a team’s collective experience, an external provider is often exposed to a wider range of enforcement patterns than a single in-house officer.

Contractual protections to require (service levels, confidentiality, conflict checks)

An external DPO is only as good as its contract. Insist on defined response times, robust confidentiality and data-handling obligations, documented conflict-of-interest checks, professional indemnity insurance, and clear termination and handover provisions. Availability is the classic weakness of outsourced models, a service-level agreement addresses it.

In-house vs External DPO Italy: Side-by-Side Comparison

The table below is the centrepiece of the in-house vs external DPO Italy decision. Read it as a diagnostic: count how many rows point to your circumstances on each side.

Comparison chart: In-house vs External DPO, Italy 2026
Dimension In-house DPO External DPO
Best suited to Large or high-risk processors with continuous data protection workload SMEs, mid-market firms, and groups needing predictable, independent coverage
Cost structure €40k–€150k+ salary plus training, recruitment and continuity costs (estimate) €8k–€25k/yr (SME) to €3k–€10k+/month (large) retainer (estimate)
Independence & conflicts Risk if role overlaps with operational duties; must be ring-fenced Structurally independent by design; verify no cross-client conflicts
Availability / responsiveness Immediate; embedded in the business Governed by service levels; can lag without defined response times
Institutional knowledge Deep, knows systems, flows and people Broader cross-sector experience; slower on internal specifics
Recruitment / termination friction High, hiring, redundancy and single-point-of-failure risk Low, scalable contract, easier to change provider
Garante communication & updates Internal responsibility; update on staff change Assign notification/update duty explicitly in contract
AI competence Requires ongoing investment in AI governance training Often available as team capability across clients
Liability & insurance Employer bears exposure; individual professional cover limited Provider may carry professional indemnity insurance
Contractual controls Employment terms plus written appointment Service agreement, confidentiality, conflict checks, handover clauses
Enforcement risk profile Strong if independence maintained; weak if conflicted Strong on independence; manage availability and continuity
Ideal organisational profile High-volume, high-risk, well-resourced Cost-conscious, breadth-seeking, lower continuous workload

The dominant tradeoff: in-house buys proximity and speed at the price of cost and conflict risk; external buys independence, breadth and predictability at the price of availability, which strong service levels can neutralise. If your processing is continuous and high-risk and you can fund an independent role, in-house may suit. If you are an SME or need structural independence without headcount, external is often preferable. For many Italian businesses in 2026, that points to external.

Decision Framework, Choose In-house vs External DPO Italy

Use the following decision rules. Work through them in order; the first firm “yes” usually informs the answer.

  • Is your processing continuously high-risk (large-scale profiling, systematic monitoring, significant AI deployment)? If yes and budgeted, lean in-house.
  • Are you an SME or mid-market company with variable data protection workload? If yes, lean external.
  • Do you operate across multiple entities or jurisdictions? A shared or external DPO usually delivers better economics and consistency.
  • Do you have internal roles that would conflict with an in-house appointment? If independence is hard to guarantee internally, choose external.
  • Is continuity a concern (small team, single candidate)? External can remove single-point-of-failure risk.
  • Is budget constrained but the obligation mandatory? An external retainer can deliver compliance at a predictable, lower entry cost.

30/60/90 day implementation plans

Track A, Appointing an in-house DPO:

  • 0–30 days: Confirm Art. 37 trigger, define the role and reporting line to the board, and open recruitment.
  • 31–60 days: Interview for GDPR and AI competence, verify no conflicts, and draft the written appointment.
  • 61–90 days: Onboard, communicate the DPO’s details to the Garante, and publish internal escalation procedures.

Track B, Contracting an external DPO:

  • 0–30 days: Scope requirements, request proposals, and run conflict checks on shortlisted providers.
  • 31–60 days: Negotiate the service agreement (response times, confidentiality, insurance, handover) and sign.
  • 61–90 days: Communicate the external DPO’s contact data to the Garante and integrate them into your incident process.

Track C, Interim external DPO before an internal hire: appoint an external DPO immediately to close the compliance gap, communicate their details, and run recruitment in parallel, then transfer the function with a documented handover once the internal hire is onboarded.

Mini case studies

SME with HR + CRM profiling. A 90-employee retailer runs employee monitoring and large-scale customer segmentation. The processing may trigger Art. 37, but the workload is not continuous and budget is tight. Illustrative recommendation: external DPO on a fixed monthly retainer, predictable cost, guaranteed independence, no recruitment risk.

Large AI company performing high-risk profiling. A technology firm deploys automated decision-making across millions of users. Processing is continuous, high-risk and AI-intensive. Illustrative recommendation: in-house DPO with board reporting, supported where needed by external specialist counsel for AI Act and enforcement matters.

Quick 10-minute checklist (five questions)

  1. Does Art. 37 make appointment mandatory for us?
  2. Is our high-risk processing continuous or occasional?
  3. Can we guarantee an independent, conflict-free internal role?
  4. What is our realistic annual budget for the function?
  5. How exposed are we to continuity risk if one person holds the role?

Contracts, Service Levels & Practical Next Steps

Whichever model you choose, the appointment must be documented. For an external DPO, the service contract is your primary compliance instrument; for an in-house DPO, a written appointment plus employment terms performs the same function.

Sample contract clause snippets

  • Scope & independence. “The DPO shall perform the tasks set out in Article 39 GDPR independently, shall not receive instructions regarding the exercise of those tasks, and shall report directly to the highest level of management.”
  • Availability & response times. “The Provider shall acknowledge data protection queries within [X] business hours and shall be reachable for personal data breach support within [X] hours, including for the notification assessment under Article 33 GDPR, which requires notification to the supervisory authority without undue delay and, where feasible, within 72 hours.”
  • Confidentiality & conflicts. “The DPO shall be bound by secrecy and confidentiality, shall maintain no conflict of interest, and shall disclose any client or engagement that could compromise independence.”
  • Termination & handover. “On termination, the Provider shall deliver a documented handover, return all records, and cooperate in updating the DPO details communicated to the Garante.”

Garante notification & documentation to keep

Retain the Garante notification receipt, the written appointment or service contract, conflict-of-interest declarations, and a record of the DPO’s independence and reporting line. On any change of DPO, update the details communicated to the Garante promptly and archive the previous confirmation. This documentation is your first line of defence in any supervisory inquiry.

Conclusion

The in-house vs external DPO Italy decision in 2026 rewards clarity over hedging. For many Italian SMEs and mid-market companies, an external DPO delivers the independence the Garante expects, predictable cost, cross-sector experience and, where the provider is insured, additional liability protection, without recruitment or continuity risk. The in-house model tends to suit organisations with continuous, high-risk processing and the resources to guarantee a conflict-free role reporting directly to the board. Whichever path you choose, act now: confirm your Article 37 position, communicate the DPO’s details to the Garante, and put a documented appointment or service agreement in place. Explore Data Protection Lawyers, Italy and the expert profile for tailored support.

This content is for general information and does not constitute legal advice. Contact a qualified lawyer for specific advice.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Susanna Greggio at GTA Studio Legale, a member of the Global Law Experts network.

Sources

  1. Regulation (EU) 2016/679 (GDPR), official text
  2. Legislative Decree No. 101/2018 (Italy)
  3. Garante per la protezione dei dati personali
  4. European Data Protection Board (EDPB)
  5. Agenzia per l’Italia Digitale (AgID)
  6. Consiglio Nazionale Forense
  7. Regulation (EU) 2024/1689 (EU AI Act)
  8. European Commission, Data Protection overview

FAQs

When is a DPO mandatory under Italian law?
A DPO is mandatory under Article 37 GDPR where you are a public authority, where your core activities require regular and systematic large-scale monitoring, or where your core activities involve large-scale processing of special category or criminal data. The Garante interprets these triggers to capture common activities such as large-scale HR monitoring, CRM profiling, systematic CCTV and AI-driven profiling. Legislative Decree No. 101/2018 provides the Italian implementing context.
Yes, provided the lawyer meets the expertise requirement, maintains genuine independence, and has no conflict of interest, for example, they should not simultaneously advise on and set the processing purposes they are meant to monitor. Lawyers acting as DPO must also observe their professional ethics rules, including those on conflicts of interest under the forensic code of conduct. Document the independence and conflict checks in the engagement.
As indicative benchmark estimates, SMEs typically pay in the region of €1,000–€3,000 per month (roughly €8,000–€25,000 per year), while larger companies commonly pay €3,000–€10,000+ per month, with additional ad-hoc fees for breach response and DPIAs. These figures vary with scope, sector risk and service-level commitments, and should be validated against current quotations.
The controller or processor must publish the DPO’s contact details and communicate them to the Garante through its official online service, using recognised digital identity credentials, entering the controller/processor details and the DPO’s direct contact data. You must keep the confirmation and update the communication whenever the DPO or their contact details change. Confirm the current procedure and fields directly on the Garante’s website before filing.
Insist on a defined scope tied to Article 39, an independence clause, guaranteed response times, confidentiality and data-handling obligations, documented conflict-of-interest checks, professional indemnity insurance, and clear termination and handover provisions, including cooperation on updating the DPO details communicated to the Garante.
With an in-house DPO, the employer generally bears the organisational exposure and individual professional cover is limited. A reputable external DPO may carry professional indemnity insurance, which can shift and cap part of the risk, one of the underrated considerations in the in-house vs external DPO Italy decision. Note that under the GDPR, accountability for compliance remains with the controller or processor and cannot be transferred to the DPO.
The EU AI Act has widened the DPO’s expected competence to include advising on high-risk automated systems, profiling and AI data governance. Whether in-house or external, your DPO should be able to engage with AI-related processing, factor this into recruitment or provider selection.
By Awatif Al Khouri

posted 3 hours ago

By Awatif Al Khouri

posted 3 hours ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

In‑house vs External DPO in Italy (2026): When to Appoint, Costs & Garante Expectations

Send welcome message

Custom Message