How we work
01Records of processing
Mapping every processing activity, its purpose, lawful basis, categories of data and retention period.
02Lawful bases and consent
Reviewing bases, consent mechanisms and evidence that consent was validly obtained.
03Impact assessments
DPIA where processing is likely to result in high risk, with a documented outcome.
04Processor contracts
Data processing agreements, transfers outside the EU and safeguards.
05Data subject rights
A process for access, rectification, erasure and portability requests, within the statutory deadlines.
06Breach handling
Risk assessment and notification to the supervisory authority within 72 hours, with notification to data subjects where required.
What you get
Record of processing activities
DPIA
Processor contracts
Register of data subject requests
Breach procedure
Staff training
Measures of Annex II this service covers
02 Management of software and hardware assets
03 Risk management
04 Security of human resources and digital identities
10 Cryptography
11 Incident handling
Sectors where it is most in demand
Check for yourself before we talk
Entity categorisation check
Readiness check against the 13 measures
Incident reporting deadline calculator
Not sure where you stand?
Half an hour of conversation, with no obligation. By the end you know what needs doing and in what order.