Actually complying with data protection

Record of processing activities, legal texts, processor agreements, risk analysis and a data breach procedure.

Data protection and GDPR compliance

What is included

  • Record of processing activities and risk analysis
  • Legal texts for the website and forms, and processor agreements
  • Procedure for handling rights requests and notifying breaches

What is included and what is not promised

Data protection fines rarely arrive from an inspection: they arrive because somebody complains. What is then reviewed is whether documentation existed and was applied, not whether there was a badge on the website.

What it includes: record of processing activities and risk analysis; legal texts for the website and forms, and processor agreements; procedure for handling rights requests and notifying breaches. What it does not include: it does not include acting as external data protection officer, contracted separately as a recurring service.

Documents you will need

  • A description of the data you process and why.
  • A list of suppliers with access to data.
  • Your website's current legal texts if any.

Indicative timing

We answer your enquiry within 1 working day and send the written quote within 2 working days.

Once your documents are complete, we prepare the file between 5 and 15 working days.

Full compliance usually closes within a few weeks, depending on how many processing activities and suppliers must be documented.

See the pricing page for how we charge this kind of matter.

How it works

Estimated duration: 15 days.

  1. Assessment

    We look at which data you process, with which tools and what you already have: processing records, legal texts, supplier contracts.

  2. Calendar and quote

    We ask for the list of processing activities, the suppliers with access to data and your website. Agreed price for the adaptation.

  3. Preparation and filing

    We draft the processing records, the website and form texts, and the data processor contracts.

  4. Reminders

    We leave you the procedure to handle rights requests and breaches, and tell you what to review when you change tools or activity.

What to have at hand

  • A description of the data you process and why
  • A list of suppliers with access to data
  • Your website's current legal texts if any

Frequently asked questions

I have had a data breach.

There is a very short deadline to notify the authority. Write today, not tomorrow.

A complaint has been filed against me.

It is answered within a deadline. We take it on even if we did not do the earlier compliance work.

Do I need a data protection officer?

Only in certain cases. We check before selling you something you are not required to have.

Related services

People who come for “Data protection and GDPR compliance” often need one of these Business and self-employed procedures too. If your case mixes several, it goes in a single file with a single quote.

See everything we do in Business and self-employed

Your case

Tell us what your business needs, its legal form and whether a deadline is close.

Step 1 of 3 Your case
Step 2 of 3 Details for your quote

This lets us tell you what can be done and what it costs without asking again. Leave blank anything you do not know.

For instance: DGT, Tax Agency, Jaén Town Council.

Step 3 of 3 Contact details

We only ask for the basics so we can reply with context.

You can attach up to 5 files of up to 10 MB each: PDF or photos. If you do not have them to hand, send the request anyway.

Request a quote

Tell us about your case and which documents you already have. We tell you what fits, what is missing and what it costs.

Tell us your case