Skip to content
Security incident? Call: +48 732 059 711
GDPR

Are you processing personal data in compliance with GDPR?

We audit GDPR compliance — from processing registration to data security and consent management. We identify risks and prepare you for DPA inspection.

For whom?

  • Companies collecting and processing personal data
  • Organizations preparing for DPA inspection
  • Companies after data security incidents
  • Businesses managing customer or employee databases
  • Platforms and applications requiring GDPR compliance
What you get

Results

GDPR Compliance Review

Point by point: Article 5 (principles), Article 6 (lawfulness), Article 7 (consent), Article 9 (sensitive data), Articles 13–14 (information to person), Article 32 (security).

Data Processing Register (DPR)

We create or update Data Processing Register — documentation of all processing operations in your organization.

DPIA Risk Assessment

For high-risk processing — we conduct DPIA (Data Protection Impact Assessment). We assess compliance, necessary safeguards, impact on individual rights.

Non-Compliance Report with Actions

List of all GDPR violations, their significance (mandatory / recommended), remediation plan with timeline and estimated effort.

GDPR Procedures & Documents

We develop or improve privacy policy, data subject request procedures, security protocols, incident response plans.

How we work

GDPR Audit in 5 phases

  1. 01

    Data processing scope understanding

    We gather information about what data you collect, from whom, on what legal basis, how you process it. Data flow mapping.

  2. 02

    GDPR requirement compliance analysis

    We assess each GDPR requirement: lawfulness, information to person, consent, security, retention, deletion. We identify gaps.

  3. 03

    Security & risk assessment

    We verify if data is protected from unauthorized access. Incident risks, potential breach costs.

  4. 04

    Documentation & DPR

    We create Data Processing Register, privacy policy, data subject request procedures, controller confirmations.

  5. 05

    Report & implementation plan

    We deliver report with GDPR requirements, identified violations, remediation plan with actions and timeline. Team training.

FAQ

Frequently asked questions

Does GDPR apply to small companies?
Yes. GDPR applies to anyone processing personal data — regardless of size. Even collecting emails for a newsletter requires GDPR compliance.
What is the relationship between GDPR and national regulations?
GDPR is EU regulation. Each country has national implementation (RODO in Poland, CNIL in France, etc.). Standards are identical — GDPR under different names.
Do we need a Data Protection Officer (DPO)?
DPO is mandatory for public authorities and companies processing large volumes of sensitive data. For small companies: not always mandatory, but recommended.
What penalties apply for GDPR violation?
Administrative fines up to EUR 20 million (or 4% of global revenue). Lower fines for technical violations. Reputational costs after incidents.
How often does the DPA inspect?
DPAs conduct inspections based on complaints, risk assessment, audit programs. High-risk sectors (finance, e-commerce) are inspected more frequently. Independent audit prepares you.

Check GDPR readiness

30-minute consultation about your data and GDPR risks. We highlight main work areas.