Compaas – Compliance as a Service
Menu

Outsourced Mandates

Legally or contractually required officer roles – reliably and cost-effectively through Compaas.

Outsourced mandates by Compaas

Many mid-market companies are legally required to appoint officers – for data protection, information security, or whistleblower protection. A dedicated full-time position is often neither necessary nor economical.

Compaas assumes these roles as an external partner: with the required specialist expertise, necessary independence, and direct access to management. One dedicated point of contact, not an anonymous hotline.

Mandated roles in detail

Compaas covers the key statutory and industry-standard officer roles – flexibly combinable to your needs.

External Data Protection Officer

Under Art. 37 GDPR, many companies must appoint a Data Protection Officer. Compaas assumes this role externally and fulfils all statutory duties – from advising management to monitoring data processing.

Scope of services

  • Advising management and raising employee awareness
  • Monitoring compliance with GDPR and internal policies
  • Point of contact for data subjects and supervisory authorities
  • Annual data protection report and continuous improvement

Benefits for your organisation

  • • No full-time position required – cost-effective for mid-market companies
  • • Independence and specialist expertise from Compaas
  • • Demonstrable fulfilment of legal obligations

External Information Security Officer (ISO)

The ISO coordinates all information security measures at management level. Compaas assumes this strategic role and connects security requirements with the operational realities of mid-market companies.

Scope of services

  • Development and maintenance of the security strategy
  • Coordination between IT, business units, and management
  • Risk management and measure tracking
  • Preparation and follow-up of security audits

Benefits for your organisation

  • • Professional steering of information security
  • • Relieving IT leadership of strategic cross-cutting topics
  • • Preparation for ISO 27001 and customer requirements

Whistleblower Protection Officer

Whistleblower protection legislation requires many companies to appoint an officer. Compaas sets up reporting systems, manages whistleblower processes, and ensures proper handling.

Scope of services

  • Setup and operation of the reporting system
  • Training of reporting channel staff
  • Process monitoring and deadline control
  • Reporting to management and documentation

Benefits for your organisation

  • • Legally compliant fulfilment of whistleblower protection obligations
  • • Protection of whistleblowers and company interests
  • • External, neutral management of the reporting process

Further mandates

Depending on industry and customer requirements, additional roles may be needed – e.g. Compliance Officer, BCM officer, or industry-specific security officers. Compaas assumes these roles flexibly as required.

Scope of services

  • Analysis of required mandates
  • Assumption or support in fulfilling roles
  • Alignment with existing organisational structures
  • Regular reporting to leadership

Benefits for your organisation

  • • Flexible coverage without fixed costs for each individual role
  • • One point of contact at Compaas for multiple topics
  • • Scalable as requirements grow

Mandate process

  1. 1

    Intro call

    A no-obligation introduction: where does your organisation stand? Which standards or customer requirements are relevant? Compaas gains an initial overview.

  2. 2

    Analysis

    Gap analysis or needs assessment: Compaas identifies gaps, prioritises measures, and creates a realistic implementation plan with effort estimates.

  3. 3

    Implementation

    Joint implementation: policies, processes, technical measures, and training – pragmatic and tailored to your operations.

  4. 4

    Ongoing support

    Continuous support, internal audits, certification preparation, or outsourced mandates – Compaas remains your dedicated point of contact.

Frequently asked questions

Do I really need an external Data Protection Officer?

For many mid-market companies, yes. Under Art. 37 GDPR, appointment of a Data Protection Officer is generally mandatory if at least 20 people are permanently engaged in automated processing of personal data – or if special categories of data, extensive monitoring, or high risks require appointment. Compaas reviews in the intro call which mandates are actually relevant for your organisation – not only the DPO but also information security officer or whistleblower protection. An external officer is often the more economical solution when a full-time role is not justified but professional qualification and independence are required.

How much internal time is required?

The external officer assumes specialist responsibility for their role – advice, monitoring, reporting, and escalation where needed. Internally, you need a reliable point of contact, usually from management, IT, or administration, who provides information, supports decisions, and anchors measures in the organisation. Time commitment is typically a few hours per month – in intensive phases (e.g. introducing a whistleblower system or preparing for a data protection review) it may temporarily be higher. Compaas structures coordination efficiently and prepares topics in advance so internal meetings remain focused and short.

Can Compaas take on multiple roles simultaneously?

Yes. Compaas can serve as Data Protection Officer, Information Security Officer, and whistleblower protection officer from a single source – with aligned processes, one dedicated point of contact, and consistent reporting to management. This avoids contradictory recommendations and significantly reduces coordination effort in your organisation. Especially in the mid-market, where the same people and systems touch multiple compliance topics, this bundled support is often more efficient than three separate providers. Compaas ensures roles and responsibilities are clearly delineated and documented in a way that is traceable for authorities and internally.

Which officer roles can Compaas take on?

Compaas typically assumes the role of external Data Protection Officer (DPO), Information Security Officer (ISO), and whistleblower protection officer under the Whistleblower Protection Act. Depending on industry and contractual requirements, further roles may apply – such as BCM officer, IT security coordination, or supporting functions within ISO 27001 obligations. In the intro call, Compaas clarifies which roles are legally, contractually, or risk-based requirements. Not every role must be filled immediately; Compaas recommends staged introduction when several mandates are due at once.

What does collaboration with management look like?

External officers report regularly to management – at least annually, more often where needed. Compaas prepares reports in accessible language: current risks, open measures, incident status, and action required with clear priorities. Management remains legally responsible; the officer advises, monitors, and escalates. Compaas focuses on pragmatic recommendations that can be implemented – not lists of a hundred items but focused proposals with reasoning. Short, structured alignment meetings and written summaries ensure compliance topics remain visible at leadership level without overloading day-to-day operations.

What is the difference between an external and internal officer?

An internal officer knows the organisation from daily operations and is always on site – which can be an advantage, but requires a qualified full-time or part-time role and organisational independence that is not always easy to achieve in the mid-market. An external officer brings cross-industry experience, remains independent of internal hierarchies, and scales flexibly. Compaas combines the personal continuity of a dedicated contact with the efficiency of external support – you receive ongoing guidance without recruiting, onboarding, and cover problems during leave or illness. For many organisations from around 20 to 200 employees, this is the more economical and professionally sound solution.

How is the whistleblower protection officer integrated organisationally?

Since the Whistleblower Protection Act, many organisations must establish an internal reporting procedure and appoint a suitable officer. Compaas supports selection and setup of a reporting system, communication to employees, and confidential handling of reports. The whistleblower protection officer is organisationally separated from management and specialist departments but works closely with HR, legal, and IT when a report is processed. Compaas documents the process in an audit-ready manner and trains responsible staff in handling reports – from acknowledgement to follow-up. Where needed, Compaas can also operate existing reporting systems or set up deep links for customers.

Is there a minimum contract term?

Officer roles depend on continuity – a DPO or ISO who changes every few months does more harm than good. Compaas therefore generally works with ongoing support contracts whose terms and duration are discussed transparently in the intro call. At the same time, there is no obligation to long-term packages without value: notice periods and scope of services are clearly agreed. Many customers stay long-term because the collaboration works in practice – not because of rigid contract clauses. If your needs change, Compaas adjusts scope or supports handover to a successor.

Unsure which mandates are relevant for your organisation? Compaas analyses this as part of a no-obligation intro call.

Submit enquiry