GDPR
From a defensible processing register to a 72-hour breach response that holds up under pressure.
GDPR has been in force since 2018, so a buyer asking for help in 2026 usually has a trigger: a Datatilsynet enquiry, a breach, a deal under due diligence, or a DPO vacancy. I run the programme work that gives your DPO, your legal team, and your board a defensible position. Tell me which trigger brought you here and I will skip straight to what matters.
What we deliver
-
Article 30 records of processingA current register of processing activities, ready for the supervisory authority.
-
Data Protection Impact Assessment (DPIA) frameworkWhen a data protection impact assessment is required, how it runs, and what evidence it produces.
-
Data Transfer Impact Assessment (DTIA)Transfer assessments under Schrems II and Article 46, with the contract clauses and supplementary measures the data exporter needs.
-
Subject rights workflowArticles 12 to 22 operationalised, from access request to erasure, with deadlines and clear ownership.
-
DPO roleFractional or external data protection officer, contracted with a defined mandate and reporting line.
-
Breach response and notification72-hour notification readiness for Datatilsynet, with role list, decision tree, and pre-filled templates.
How we deliver this service
- In a project
A GDPR readiness review or a DTIA with defined scope and duration.
- In a role at the customer
A fractional DPO seat inside your organisation, contracted over months or years.
- As part of a service
Included in the Secured by FM CyberSecurity bundle for small and mid-sized organisations.
Recent insights on GDPR
- How long does ISO 27001 take?
The work takes weeks, the waiting takes months. What an ISO 27001 run consists of, what sets the pace, and how to plan backwards from a tender deadline.
- How we use AI to get SMBs certification-ready in four to six weeks
AI drafts the documentation, our consultants adapt it with you, and the evidence gathers itself in a GRC tool. That is how the timeline holds up.
- ISO 27001 or NIS2 first?
A customer wants ISO 27001 and NIS2 is on the way. Build one management system, let the paying deadline set the order, and the same work carries both.