Adventure Spirit d.o.o. · Zagreb, Croatia +385 95 504 1496 info@adventurespirit.hr GRC Portal
Home›Services›External data protection officer
Services

External data protection officer

We take on the data protection officer function. An external DPO is expressly provided for by the GDPR and for most organisations is cheaper and more independent than an internal appointment. The role is held by a CIPP/E certified practitioner.

GDPR, Articles 37 to 39

How we work

01Monitoring compliance
Tracking application of the GDPR and internal rules, with regular reporting to the highest management level.
02Advice
Opinions on impact assessments, new processing, processor contracts and transfers outside the EU.
03Contact point
Towards the supervisory authority and data subjects, including access, rectification and erasure requests.
04Personal data breaches
Risk assessment and notification to the supervisory authority within 72 hours, with notification to data subjects where required.
05Training
Training for staff involved in processing, with records that can be produced.

What you get

Appointed DPO and contact
Records of processing
Impact assessments
Register of data subject requests
Annual report to management

Measures of Annex II this service covers

01 Commitment and accountability of those responsible for implementing cyber risk management measures 02 Management of software and hardware assets 04 Security of human resources and digital identities 11 Incident handling

Sectors where it is most in demand

Check for yourself before we talk

Not sure where you stand?

Half an hour of conversation, with no obligation. By the end you know what needs doing and in what order.