GDPR compliance is not solved by a document downloaded from the internet and posted on a website. The Regulation requires you to know what data you hold, why you hold it, how long you keep it and who else has access — and the answer differs from company to company.
We work with private-sector controllers, from small firms with a contact form to organisations with complex processing. We start from what you actually do, not from a template.
When the data side needs a look
- You are launching a product or a site that collects data and want to start properly
- You have received a request from a data subject and are unsure what to answer
- A security breach has occurred and the notification clock is already running
- You have received a request or a complaint from the Romanian supervisory authority
- You work with a supplier that processes data on your behalf
- You transfer data outside the European Economic Area
What we cover
- Compliance audits and the record of processing activities
- Privacy policies, notices and consent forms
- Processor agreements and clauses for international transfers
- Data protection impact assessments, where they are required
- Assistance with breach notification and in dealings with the supervisory authority
- Ongoing advice in the role of data protection officer
How we work
We start with a data map: what you collect, from whom, on what basis, where it goes and how long it stays. The documents follow from the map, not the other way round. A set of policies written without one describes a company that does not exist.
If a breach has occurred, the conversation is urgent and takes a different order: first containment and risk assessment, then notification, then documentation. The notification deadline is short and runs from the moment you became aware.
What helps us start
- A description of your business and of the products through which data reaches you
- The policies and notices you use now, even if you consider them incomplete
- The list of suppliers that touch the data: hosting, accounting, couriers, marketing
- Any correspondence with the authority or with a data subject, if there is any
