Investment focusCompliance, testing and certificationSell a data protection consultancy
Compliance, testing and certification · Sell a data protection consultancy

Selling a data protection consultancy: we take over the whole company with team and mandates

With every new mandate, the record of processing activities is the first thing missing, and the first data breach is sure to come on a Friday afternoon.

We buy external data protection officers and information security service providers with 150 or more mandates as an officer platform for DPO, ISO and the EU AI Act. What the planned removal of Section 38 BDSG means for value, we answer in the questions below.

Confidential. Only the three partners see your enquiry.
Last updated: September 23, 2026 · +49 40 89741812
External data protection officer at an employee training session
AI-generated image
Confidential from the first minute
Does this sound familiar?

Two situations we know

300 mandates and the Section 38 worry

You wonder what your company is worth if the obligation goes. We tell you, mandate by mandate.

DPO plus ISO plus reporting channel

You have turned data protection into an officer platform. That is exactly what we buy.

Your day-to-day, as we know it

This is what happens in your business before anyone talks about succession

72 hours and counting

A data breach must be reported within 72 hours under Art. 33 GDPR. The client often only gets in touch on the third day.

Pile of DPAs

Every new service provider at the client needs a data processing agreement under Art. 28. The review lands on your desk.

Access requests

A former employee requests access. The deadline is one month, and the data sits in five systems.

Then came NIS2

Many clients had to register with the BSI. Suddenly the ISO is in as much demand as the DPO.

Record of processing activities of a client company
AI-generated image
How we measure your company

The metrics we look at in the first call

We look at the numbers you use to run your business yourself. The right column shows our acquisition criterion.

MetricWhat it tells usOur benchmark
Number of ongoing DPO and ISO mandatesShows the breadth of your recurring business.We look for at least 150 mandates.
Retainer share of revenueShows how much revenue comes predictably through flat fees.The higher, the better.
Certified DPOs and ISOs on the teamShows whether mandates are served without the owner.We look for at least 5 certified people.
Hours per mandate versus flat feeShows which mandates pay off and which do not.Analysis per mandate, annually.
Mandate losses per yearShows whether clients stay after the initial documentation.With reasons for termination, three years.
What actually changes after the acquisition

Step by step

We automate the desk work. Professional decisions and customer contact stay with your people.

TodayBuild the record of processing activities for a new mandate
With GTPProcessing activities are pre-filled from questionnaires and system lists. The DPO checks purposes and legal bases.
TodayReview the service provider's DPA
With GTPDeviations from the template are flagged. The DPO gives the approval.
TodayAnswer a data subject request
With GTPDeadlines, data search and draft reply run in a structured way. The DPO decides on scope and redactions.
TodayUpdate the activity report and technical and organizational measures
With GTPThe draft is built from the year's incidents and measures. The officer assesses and signs.
Your systems stay in use:veriniceOneTrust
AI potential in the segment

How much desk work can really be automated here

This is GTP's assessment. We show it upfront so you can see what we will work with after the acquisition.

01

Semi-automatic record of processing activities

A model generates entries for the record of processing activities from system lists, questionnaires and existing templates.

02

Data processing agreements checked against the rules

The document check automatically compares data processing agreements with Art. 28 and flags missing clauses.

03

Create training per mandate

Training production creates briefings and tests per industry with a text generator.

What limits the technology here

Client data is highly confidential, the officer is professionally liable, and the EU AI Act requires human oversight from August 2026.

What this means for you

Bring your mandate book in a structured form, and we will assess automation potential and Section 38 risk mandate by mandate.

Sources TÜV Rheinland Consulting: obligations for high-risk AI from August 2, 2026, including data governance, logging and human oversight (2026). Federal Statistical Office: 26% of companies use AI, 23% of those with 10 to 49 employees (2025).

What we want to see

The documents we need

After the first call and the non-disclosure agreement, these five documents are enough for a solid offer.

  • Mandate list with DPO or ISO role, flat fee and term
  • Template contracts for officer mandates with liability provisions
  • Certificates and training records of the officers
  • Overview of reported data breaches and contacts with authorities for clients
  • Hours analysis per mandate for the last two years
What we buy

Our acquisition profile for this segment

Criteria

  • 150 or more mandates on term contracts
  • At least 5 certified DPOs or ISOs
  • Churn below 10%
  • EBITDA €0.5m to €5m
  • Most clients above 50 people or subject to a DPIA obligation

Value drivers

  • Mandates with an Art. 37 obligation (sensitive data, monitoring)
  • ISO and NIS2 services in the portfolio
  • Contract terms longer than 24 months

Value reducers

  • Very small mandates below 20 people (Section 38 exposure)
  • Standard flat fees below €100 per month
  • Mandates that depend on a single person
How you can tell we know your business

Three facts you can quote

  1. 01The federal and state governments plan to remove Section 38 BDSG by 12/31/2026 (conference of state premiers 12/04/2025, dr-datenschutz.de 06/2026).
  2. 02The NIS2 Implementation Act affects about 29,500 companies, about 11,000 had not registered by 07/31/2026 (secjur, mars solutions 2026).
  3. 03Software providers with a DPO service such as heyData and DataGuard grow with venture capital.
Market range, third-party source

What comparable companies trade at in the market

Size classEBITDA multiple
Micro-cap, revenue below €5m
The relevant class for most succession cases in this segment
3.5x to 5.5x
Small-cap, revenue €5m to €50m5.0x to 7.0x

Category business services (B2B). Source: DUB KMU-Multiples Q2/2026. The DUB figures show asking prices and price expectations on a business marketplace. They do not include completed transactions. The range comes from an independent third party and is not an offer from GTP.

From multiple to cash

The multiple gives the enterprise value. What reaches your account depends on four items:

Net financial debt
Loans, leases and shareholder accounts are deducted, cash is added.
Working capital
We assume a normal level. An account emptied before the sale reduces the price.
Investment backlog
Vehicles, measuring equipment and software due in the next two years are deducted from the price.
Payment structure
Part of the price is paid only after signing, through a rollover or a performance-based component.
What lowers the value

If one of these points applies, the value drops:

  • The owner personally holds the key customers
  • Short remaining terms or contracts that can be terminated at any time
  • If a large share of revenue depends on one customer, the price goes down.
  • No second management level that runs the business without the owner

We calculate your value in the first call using your numbers. We go through the four items openly with you, even if the result is below your expectations.

All market data and the regulatory timeline for compliance, testing and certification

Frequently asked questions

What owners in this segment ask

Will the DPO obligation be dropped, and what does that mean for the price?

Probably yes, though not right away. Very small mandates lose value. Mandates with GDPR obligations, an ISO role or a reporting channel remain valuable. We value the mandate book on that basis.

How do you compete with DataGuard and heyData?

With personal service. Software delivers templates. We deliver site visits, advice and liability, plus our own automation for records of processing and DPAs.

Do you buy solo DPOs?

No. At least 5 specialists. Providers such as ad hoc datenschutz take over individual mandates.

How fast?

Response usually within 72 h, indicative offer in 2 to 4 weeks, mandate analysis as a separate step.

More questions about the sale and the process

Dr. Sebastian Herfurth, Partner at Generation Tech Partners
Why we buy this segment
Your clients have obligations to meet, and your business makes sure they do. We buy businesses that do this reliably. Professional responsibility stays with the people who carry it today.

I am responsible for the purchase agreement and the handover. For businesses that need a license or accreditation, the deal structure decides whether the approval survives the change of ownership.

For M&A advisors, tax advisors and succession advisors

Response on your client usually within 72 hours

Acquisition profile, teaser metrics and our commitments for all 24 segments are on a separate page. We only approach your client through you.

Our team, the process at a glance, press and common questions about selling are on our main site.

First step

Talk to a buyer who knows your segment

A 30-minute call is enough to know whether we fit. Afterwards you get a written assessment with reasons.

Request a confidential first call

Or call us: +49 40 89741812

ConfidentialOnly the three partners see your enquiry. An NDA is possible in advance on request. We share nothing with third parties.
Back
Request a confidential first call