GDPR compliance is not solved by a document downloaded from the internet and posted on a website. The Regulation requires you to know what data you hold, why you hold it, how long you keep it and who else has access — and the answer differs from company to company.

We work with private-sector controllers, from small firms with a contact form to organisations with complex processing. We start from what you actually do, not from a template.

When the data side needs a look

  • You are launching a product or a site that collects data and want to start properly
  • You have received a request from a data subject and are unsure what to answer
  • A security breach has occurred and the notification clock is already running
  • You have received a request or a complaint from the Romanian supervisory authority
  • You work with a supplier that processes data on your behalf
  • You transfer data outside the European Economic Area

What we cover

  • Compliance audits and the record of processing activities
  • Privacy policies, notices and consent forms
  • Processor agreements and clauses for international transfers
  • Data protection impact assessments, where they are required
  • Assistance with breach notification and in dealings with the supervisory authority
  • Ongoing advice in the role of data protection officer

How we work

We start with a data map: what you collect, from whom, on what basis, where it goes and how long it stays. The documents follow from the map, not the other way round. A set of policies written without one describes a company that does not exist.

If a breach has occurred, the conversation is urgent and takes a different order: first containment and risk assessment, then notification, then documentation. The notification deadline is short and runs from the moment you became aware.

What helps us start

  • A description of your business and of the products through which data reaches you
  • The policies and notices you use now, even if you consider them incomplete
  • The list of suppliers that touch the data: hosting, accounting, couriers, marketing
  • Any correspondence with the authority or with a data subject, if there is any