DPO-as-a-Service

Four packages, sized to obligation rather than to budget

Which package fits depends on your headcount, the sensitivity and volume of the data you hold, whether a sector regulator supervises you, and whether you profile or make automated decisions. We size it with you at discovery, at no charge.
Jumpstart
Get the obligations met and the paperwork right, once.
On request
  • You appoint your own DPO. We set them up and hand over.
Up to 20 staff, low volumes of sensitive data, one to three systems
Request a quote
One-off project · Fixed scope
Essential
Your employee holds the role. We are the program behind them.
On request
  • Your employee is the DPO. We build and run the program.
21–100 staff, or fewer with real volumes of sensitive data
Request a quote
12 months · 8 hours per month
Managed DPO
Most engagements
A named Nexthread principal is your Data Protection Officer of record.
On request
  • A named Nexthread principal is your designated DPO of record.
101–250 staff, or a regulated business of any size
Request a quote
24 months · 16 hours per month
Regulated Enterprise
A DPO, a named deputy, and a trained Compliance Officer for Privacy network.
On request
  • A named principal as DPO, plus a named deputy and a COP network.
250+ staff, multi-site, or supervised by BSP, the Insurance Commission, SEC, DOH, DepEd or CHED
Request a quote
24 months · 30+ hours per month
Why the minimum terms differ
The 24-month minimum on Managed DPO and Regulated Enterprise is not a commercial preference. NPC Advisory 2017-01 requires that where the Data Protection Officer function is outsourced, the engagement runs for at least two years, so that the function is stable.

What is included

Grouped by the four delivery phases. A number or a word in a cell is the included limit for that package; anything beyond it is quoted separately.

  • Jumpstart
    Get the obligations met and the paperwork right, once.
    Engage
    Confidential discovery and registration-threshold assessment
    DPO designation pack — board resolution, secretary’s certificate, designation letter
    A named Nexthread principal designated as your DPO of record
    Compliance Officer for Privacy network design and appointment
    Plan
    Compliance gap assessment against the five NPC pillars
    Rapid
    Records of Processing Activities (data inventory)
    ≤5 activities
    Departmental data-mapping workshops
    Privacy Impact Assessments
    Privacy risk register and prioritized 12-month roadmap
    Implement
    Privacy Management Program
    Privacy Manual, drafted to your operations
    Standard
    Privacy notice set — website, customer, employee, recruitment, CCTV
    3 notices
    Consent forms and a consent-withdrawal mechanism
    Data subject rights procedure, forms and register
    Retention and disposal schedule reconciled to Philippine statutory minimums
    Breach response plan and Data Breach Response Team setup
    Vendor and processor register, and outsourcing agreement templates
    Data Sharing Agreement drafting
    Cross-border transfer assessment and contractual clauses
    NPC registration filing and Seal of Registration deployment
    Staff privacy awareness training
    1 session
    Role-specific training for HR, IT, collections and records staff
    Monitor
    Named contact for the NPC and for your data subjects
    72-hour breach hotline and incident support
    30 days
    Breach notification filed on your behalf through the DBNMS
    Data subject request triage and response support
    Quarterly DPO report to management or the board
    Annual internal privacy audit
    Annual Security Incident Report prepared and filed by 31 March
    NPC registration renewal managed
    Monitoring of new NPC issuances with a written impact assessment
    Breach tabletop exercise
    Sector overlay — BSP, IC, SEC, DOH, DepEd, CHED or BPO
    ISO/IEC 27701 and Philippine Privacy Mark readiness track
    Regulator liaison and support during an NPC investigation
  • Essential
    Your employee holds the role. We are the program behind them.
    Engage
    Confidential discovery and registration-threshold assessment
    DPO designation pack — board resolution, secretary’s certificate, designation letter
    A named Nexthread principal designated as your DPO of record
    Compliance Officer for Privacy network design and appointment
    Plan
    Compliance gap assessment against the five NPC pillars
    Records of Processing Activities (data inventory)
    ≤12
    Departmental data-mapping workshops
    ≤4
    Privacy Impact Assessments
    2 per year
    Privacy risk register and prioritized 12-month roadmap
    Implement
    Privacy Management Program
    Privacy Manual, drafted to your operations
    Privacy notice set — website, customer, employee, recruitment, CCTV
    Consent forms and a consent-withdrawal mechanism
    Data subject rights procedure, forms and register
    Retention and disposal schedule reconciled to Philippine statutory minimums
    Breach response plan and Data Breach Response Team setup
    Vendor and processor register, and outsourcing agreement templates
    Data Sharing Agreement drafting
    1 per year
    Cross-border transfer assessment and contractual clauses
    Add-on
    NPC registration filing and Seal of Registration deployment
    Staff privacy awareness training
    2 per year
    Role-specific training for HR, IT, collections and records staff
    Monitor
    Named contact for the NPC and for your data subjects
    72-hour breach hotline and incident support
    1 incident per year
    Breach notification filed on your behalf through the DBNMS
    Add-on
    Data subject request triage and response support
    ≤5 per year
    Quarterly DPO report to management or the board
    Annual internal privacy audit
    Add-on
    Annual Security Incident Report prepared and filed by 31 March
    NPC registration renewal managed
    Monitoring of new NPC issuances with a written impact assessment
    Breach tabletop exercise
    Add-on
    Sector overlay — BSP, IC, SEC, DOH, DepEd, CHED or BPO
    Add-on
    ISO/IEC 27701 and Philippine Privacy Mark readiness track
    Regulator liaison and support during an NPC investigation
    Hourly
  • Managed DPO
    Most engagements
    A named Nexthread principal is your Data Protection Officer of record.
    Engage
    Confidential discovery and registration-threshold assessment
    DPO designation pack — board resolution, secretary’s certificate, designation letter
    A named Nexthread principal designated as your DPO of record
    Compliance Officer for Privacy network design and appointment
    Optional
    Plan
    Compliance gap assessment against the five NPC pillars
    Records of Processing Activities (data inventory)
    ≤30
    Departmental data-mapping workshops
    ≤8
    Privacy Impact Assessments
    4 per year
    Privacy risk register and prioritized 12-month roadmap
    Implement
    Privacy Management Program
    Privacy Manual, drafted to your operations
    Privacy notice set — website, customer, employee, recruitment, CCTV
    Consent forms and a consent-withdrawal mechanism
    Data subject rights procedure, forms and register
    Retention and disposal schedule reconciled to Philippine statutory minimums
    Breach response plan and Data Breach Response Team setup
    Vendor and processor register, and outsourcing agreement templates
    Data Sharing Agreement drafting
    3 per year
    Cross-border transfer assessment and contractual clauses
    NPC registration filing and Seal of Registration deployment
    Staff privacy awareness training
    4 per year
    Role-specific training for HR, IT, collections and records staff
    Monitor
    Named contact for the NPC and for your data subjects
    72-hour breach hotline and incident support
    Breach notification filed on your behalf through the DBNMS
    Data subject request triage and response support
    Quarterly DPO report to management or the board
    Annual internal privacy audit
    Annual Security Incident Report prepared and filed by 31 March
    NPC registration renewal managed
    Monitoring of new NPC issuances with a written impact assessment
    Breach tabletop exercise
    1 per year
    Sector overlay — BSP, IC, SEC, DOH, DepEd, CHED or BPO
    Add-on
    ISO/IEC 27701 and Philippine Privacy Mark readiness track
    Add-on
    Regulator liaison and support during an NPC investigation
    20 hours included
  • Regulated Enterprise
    A DPO, a named deputy, and a trained Compliance Officer for Privacy network.
    Engage
    Confidential discovery and registration-threshold assessment
    DPO designation pack — board resolution, secretary’s certificate, designation letter
    A named Nexthread principal designated as your DPO of record
    Compliance Officer for Privacy network design and appointment
    Plan
    Compliance gap assessment against the five NPC pillars
    Records of Processing Activities (data inventory)
    Unlimited
    Departmental data-mapping workshops
    Privacy Impact Assessments
    Per plan
    Privacy risk register and prioritized 12-month roadmap
    Implement
    Privacy Management Program
    Privacy Manual, drafted to your operations
    Privacy notice set — website, customer, employee, recruitment, CCTV
    Consent forms and a consent-withdrawal mechanism
    Data subject rights procedure, forms and register
    Retention and disposal schedule reconciled to Philippine statutory minimums
    Breach response plan and Data Breach Response Team setup
    Vendor and processor register, and outsourcing agreement templates
    Data Sharing Agreement drafting
    Cross-border transfer assessment and contractual clauses
    NPC registration filing and Seal of Registration deployment
    Staff privacy awareness training
    Per plan
    Role-specific training for HR, IT, collections and records staff
    Monitor
    Named contact for the NPC and for your data subjects
    72-hour breach hotline and incident support
    Breach notification filed on your behalf through the DBNMS
    Data subject request triage and response support
    Quarterly DPO report to management or the board
    Monthly
    Annual internal privacy audit
    Annual Security Incident Report prepared and filed by 31 March
    NPC registration renewal managed
    Monitoring of new NPC issuances with a written impact assessment
    Breach tabletop exercise
    2 per year
    Sector overlay — BSP, IC, SEC, DOH, DepEd, CHED or BPO
    ISO/IEC 27701 and Philippine Privacy Mark readiness track
    Regulator liaison and support during an NPC investigation
    40 hours included

Pricing is quoted after scoping, not before

Fees depend on headcount, systems, sector and data volume. The discovery call and the written proposal that follows are both free, and the proposal states a fixed scope and a fixed fee.

Nexthread Solutions is an information technology solutions provider for both hardware and software needs. Current as of July 27, 2026. Reviewed quarterly, and on each new NPC issuance.