• Review of existing data protection processes
• Assessing technical and organizational measures
• Uncovering vulnerabilities and risks
• Recommendations for improvement
• Audit report as evidence for authorities
• Setting up a structured management system
• Central management of policies and evidence
• Process control according to GDPR
• Compliance dashboard for owners
• Integration into existing company structures
• Creating and maintaining internal data protection rules
• Adaptation to legal changes
• Defining roles and duties
• Employee information and awareness
• Consistent data protection governance
• Immediate measures and incident handling
• Assessing the risk to data subjects
• Notification of supervisory authorities and documentation
• Root cause analysis and preventive measures
• Support with crisis communication
• Acting as statutory data protection officer
• Consulting on data protection obligations
• Performing regular checks
• Point of contact for authorities and data subjects
• Ongoing reporting to executive management
• Developing legally compliant deletion policies
• Structured data deletion procedures
• Defining retention and deletion periods
• Automating deletion processes
• Proof of GDPR compliance
• Analysis of data processing agreements (DPA)
• Adding necessary GDPR clauses
• Support with contracts with third parties
• Review of international data transfers
• Legally compliant documentation
• Checking websites for GDPR compliance
• Analysis of cookies, tracking and forms
• Review of the privacy policy
• Recommendations for adjustments
• Documentation of test results
• Privacy-compliant design of reporting systems
• Ensuring anonymity and confidentiality
• Policies for data processing in the whistleblowing process
• Training of those responsible
• Integration into existing compliance structures