Pharoah Technology · UK GDPR Articles 37–39 DPO service

Your appointed Data Protection Officer, on demand.

A qualified DPO appointed on your ICO Register entry. AI-augmented privacy programme. Quarterly board reports. Article 38 independence preserved. From £99/month — versus £200–£1,500 for the human-only incumbents.

No card · 60-second check
Named DPO on your ICO Register in 5 working days
Article 38 independence by design
Article 37

A DPO appointment isn't optional for the organisations it applies to. Public authorities, large-scale monitoring, and large-scale special-category processing all mandate one under UK GDPR Article 37 — and "the founder, sort of" is no longer an acceptable answer in VC diligence or on NHS supplier portals.

25,000+
Organisations already on the ICO DPO register
5 days
From signup to a named DPO on your ICO Register entry
£99/mo
Entry price — versus £200–£1,500/mo human-only incumbents
37–39
The UK GDPR Articles the service is built around

Free Article 37 necessity check

Do you actually need a DPO?

Most UK SMEs don't know if Article 37 applies. Six questions, sixty seconds, no card. We'll tell you whether you're mandated, advisable, or in the clear — and what the consequences are either way.

The three patterns we see

Why most SMEs end up without a DPO when they need one

Article 37 isn't optional for the orgs it applies to. The market gap is structural — incumbents are priced for mid-market, not 14-person health-tech SaaS.

Trap 01
"It's £700/month — we can't justify it"

DPO Centre, Bulletproof and GRCI Law all start in the £350–£700/mo range for the credible tier. For a 14-person SaaS that's the difference between two engineers and three. So the appointment gets postponed — until the NHS supplier portal asks.

Trap 02
"VC due diligence flagged the gap"

Series A diligence increasingly asks "who is your DPO?" — and "the founder, sort of" is no longer an acceptable answer. The question lands two weeks before close. Solicitor onboarding takes six. dpo.law's appointed-on-day-one model is the answer.

Trap 03
"The ICO just opened an informal enquiry"

Cookie consent. DSAR backlog. Subject complaint. The ICO doesn't always lead with a fine — they often lead with an informal enquiry asking who is responsible for data protection. "We don't have one" is the worst answer.

What you get

A real qualified DPO, on call, with AI doing the heavy lifting

The named individual on your ICO Register entry. The board-pack arriving every quarter. The DSAR that gets answered within 30 days without your team touching it.

Appointment

Named DPO Appointment

A qualified individual (IAPP CIPP/E or equivalent) appears on your ICO Register entry. Article 37 satisfied · Article 38 independence preserved · Article 39 tasks under their accountability.

DSAR

DSAR Inbox

Data subjects submit requests via your privacy page. AI triages, drafts, DPO signs. 30-day clock managed. Adopts the OpenDSR open standard for cross-vendor interop.

DPIA

DPIA Scaffolding

CNIL-methodology risk matrix. Article 36 prior-consultation flag when residual risk is high. DPO reviews and signs — never auto-signed.

Reporting

Quarterly Board Reports

Article 38(3) reporting to highest management level. KPIs, incidents, supplier privacy due diligence, recommendations. AI-generated, DPO-signed, board-ready.

Incident

Breach Hotline + ICO Liaison

Incident reported · ICO 72h clock managed · DPO leads regulator liaison · cyber.law and Supreme Capital handle tech + insurance in parallel.

Records

ROPA Maintenance

Article 30 record of processing activities, kept current quarterly. Fides-taxonomy-aligned categories. Defensible audit trail.

Output

Your privacy programme, visible at board level

One record answers the question every supplier portal, VC and regulator asks: who is your DPO, and is the programme actually running?

DPO Appointment Record
Acme Health-Tech Ltd  ·  ICO ref synced
Article 37 met
Named DPO on ICO Register Appointed · day 4
Article 38 independence check Pass · quarterly
DSAR queue (30-day clock) 2 open · 0 overdue
ROPA (Article 30) Current · Q2 refresh
DPIA — new analytics vendor In review · DPO sign-off
Next board report (38(3)) Due 30 Jun
DPO-REC-023 Board-ready · exportable

Pricing

£99–£799/mo. Versus £200–£1,500/mo for the human-only incumbents.

Sticky by design: once appointed, replacing is operationally painful. 5-year LTV £15k+ at Essentials, £45k+ at Pro.

Essentials
£99/mo

For SMEs that need a named DPO appointed and the basics covered

  • Named DPO on your ICO Register
  • DSAR support (up to 10/year)
  • Breach hotline (24h response)
  • Monthly DPO check-in
  • Annual privacy review
Start free trial
Pro
£799/mo

For VC-backed orgs that need a senior DPO on speed dial

  • Everything in Standard
  • Named senior DPO (10+ years, CIPP/E)
  • Supplier privacy due diligence (Article 28)
  • Breach response leadership · 24h SLA
  • Privacy + cyber insurance referral (Supreme Capital)
  • ICO informal-enquiry support
Start free trial

FAQ

The questions everyone asks

Straight answers on the appointment, the independence rules, and the AI.

Is the appointed DPO a real person or "an AI"?

A real qualified individual. Their name and contact details appear on your ICO Register entry. They carry Article 38 accountability. AI augments their work (DSAR triage, DPIA scaffolding, board-pack generation) — but the named human reviews and signs every regulator-facing output. That's the whole point of the Article 38 framework.

How do you justify £99/mo when DPO Centre charges £350+?

Throughput. AI handles the DSAR triage, DPIA scaffolding, ROPA refresh, board-pack drafting — work that takes a human-only firm hours per task. The named DPO reviews and signs. A trained QA reviewer stamps. The unit economics work at £99/mo because the AI takes 70%+ of the elapsed time off the DPO's plate. Same regulatory outcome at materially lower price.

What happens to Article 38 independence?

Article 38(6) says the DPO must not have conflicting other duties. Our independence firewall checks this at appointment and quarterly. Commercial incentives inside the platform (e.g. Supreme Capital insurance referrals) are firewalled from the DPO function — the DPO has no commission on them. We publish our Article 38 framework on request.

Does the appointment really go on the ICO Register?

Yes. As part of onboarding we sync the appointed DPO's name and contact details to your ICO Register entry within 5 working days. If you don't have an ICO registration yet, we walk you through the £40–£2,900/yr (annual) ICO Data Protection Fee process at the same time.

What if we get a breach?

Your DPO leads the ICO 72-hour notification process — that's an Article 39 task for them. cyber.law (our sister platform) pairs a trained QA reviewer + a Supreme Capital broker on the technical and insurance response. You get a coordinated response, not three uncoordinated phone trees.

Can I keep my existing privacy lawyer?

Yes. Article 37 is the appointed DPO role, which is separate from external legal advice. Most customers retain a privacy lawyer for litigation, contracts and regulatory advice — and use dpo.law for the day-to-day DPO function (DSAR, DPIA, breach, board reporting).

Get started

Get appointed in 5 working days. Stop deferring it.

Free Article 37 check. £99/mo to start. Named DPO on your ICO Register. Article 38 independence preserved by design.

Want this for your business?

Leave your details and we'll come back to you with what it does for your situation specifically — not a brochure.

£199 one-off when it opens — no card needed to join the list.

Talk to Pharoah Technology

Leave your details and we will come back to you.