GDPR Consulting
Data subject request
• Handling access and erasure requests
• Verifying identity and entitlement
• Documentation in the DPMS
• GDPR deadline management
• Proof of legally compliant processing
Data protection audit
• Review of existing data protection processes
• Assessing technical and organizational measures
• Uncovering vulnerabilities and risks
• Recommendations for improvement
• Audit report as evidence for authorities
Data protection management system (DPMS)
• Setting up a structured management system
• Central management of policies and evidence
• Process control according to GDPR
• Compliance dashboard for owners
• Integration into existing company structures
Data protection policies
• Creating and maintaining internal data protection rules
• Adaptation to legal changes
• Defining roles and duties
• Employee information and awareness
• Consistent data protection governance
Data protection policies
• Immediate measures and incident handling
• Assessing the risk to data subjects
• Notification of supervisory authorities and documentation
• Root cause analysis and preventive measures
• Support with crisis communication
External data protection officer
• Acting as statutory data protection officer
• Consulting on data protection obligations
• Performing regular checks
• Point of contact for authorities and data subjects
• Ongoing reporting to executive management
Data deletion concept
• Developing legally compliant deletion policies
• Structured data deletion procedures
• Defining retention and deletion periods
• Automating deletion processes
• Proof of GDPR compliance
Contract review / drafting
• Analysis of data processing agreements (DPA)
• Adding necessary GDPR clauses
• Support with contracts with third parties
• Review of international data transfers
• Legally compliant documentation
Webcheck
• Checking websites for GDPR compliance
• Analysis of cookies, tracking and forms
• Review of the privacy policy
• Recommendations for adjustments
• Documentation of test results
Whistleblowing
• Privacy-compliant design of reporting systems
• Ensuring anonymity and confidentiality
• Policies for data processing in the whistleblowing process
• Training of those responsible
• Integration into existing compliance structures