Three engagements. GDPR Readiness Assessment is a fixed-scope two-week phase with the budget agreed before work starts: scope confirmation, Article 30 RoPA in your data-mapping tool, gap analysis against Articles 5, 6, 12–22, 25, 28, 30, 32, 33–34, 35 and 44–49, remediation roadmap, executive briefing. Implementation Pack is a fixed-scope six-to-eight-week phase, budget agreed up front: DPA template for processors and sub-processors, Article 35 DPIA template plus one worked DPIA, Article 32 technical measures implementation, Articles 12–22 data-subject rights workflows in your product, SCC and TIA pack for EU-to-third-country transfers, breach response runbook, public privacy notice. Ongoing DPO-as-a-Service is a monthly retainer with transparent scope: quarterly evidence refresh, regulator monitoring (EDPB, ICO, CNIL, BfDI, AEPD, Garante guidance), DSAR triage support, breach support, vendor DPA reviews up to 10/month, annual audit dry run. Budgets are agreed in writing before any work begins — fixed scope per phase, no enterprise markup.