Data Protection Compliance
Compliance Is Not Writing a Notice — It Is Fixing the System
In many organisations data protection compliance is considered complete once a privacy notice is posted on the website. What the regulation actually demands is knowing where personal data sits, not keeping it longer than necessary, and protecting it technically against unauthorised access.
Beyond producing legal texts, we work with a team that can also build the technical side: compiling the data inventory, enforcing retention periods in the system, establishing access logging and enabling the monitoring required to detect a breach.
Key Capabilities
Personal Data Inventory
Which system holds which personal data, for what purpose and for how long — every processing activity is documented.
Registry Filing & Policy Set
Regulatory registry notification is prepared, and retention and disposal policies, privacy notices and consent forms are written around the organisation's real processes.
Implementing Technical Safeguards
Permission matrix, encryption, logging and backup regimes are applied, with access restrictions enforced at database and application level.
Data Subject Request Process
Process and infrastructure are established to serve data subject requests, so all of one person's data can be found in a single query.
Retention Periods & Automatic Disposal
Retention periods are encoded by data type, and expired records flow automatically into deletion or anonymisation.
Breach Detection & Response Plan
Unusual access is monitored through anomaly detection, with a ready response plan for the 72-hour notification obligation.
Where It Is Used
- Commercial organisations processing customer data
- Healthcare providers and private hospitals
- Human resources and employee data management
- E-commerce and marketplace platforms
- Educational institutions and student records
- Any business operating CCTV
- Users of access control and biometric data
- Public institutions and municipalities
How We Work
Current State & Gap Analysis
Systems, processes and existing documentation are reviewed and gaps ranked by regulatory significance.
Inventory Compilation
Processing activities are documented through departmental interviews and data flow diagrams prepared.
Document Set & Technical Implementation
Policies and notices are drafted while technical safeguards are applied to systems and tested in parallel.
Training & Sustainability
Staff awareness training is delivered and a periodic review calendar and responsibility structure established.
A Gap Between Document and System Shows Up in an Audit
If your policy says data is kept for two years but the database still holds nine years of records, that is not compliance — it is documented non-compliance. So we write the texts to match system reality and adjust the system to match the texts.