Summary: GDPR work does not have to be a constant, ongoing documentation project. Kristensson i Skåne offers senior consulting in GDPR and data protection, DPO support and data protection impact assessments (DPIA), focused on getting the work structured, completed and possible to maintain over time. We work with clients across Sweden and have a strong local presence in Skåne, including Malmö, Lund and Helsingborg.
GDPR has been part of Swedish organisations’ everyday life for many years. Even so, we still meet businesses where the data protection work is spread across Excel files, old inventories, governance documents, contracts and individual people’s knowledge.
That does not necessarily mean no work has been done.
Often it is the opposite.
The organisation has records of processing, data processing agreements, privacy notices, retention rules, incident routines and risk assessments. The problem is that the material has grown at different times, with different owners and without an easy way to see what is current, what needs to be done and who is responsible for the next step.
GDPR then easily becomes something you make ad hoc efforts around ahead of an audit, a new system, an incident or a customer question.
We think there is a better way.
GDPR work needs to become part of ordinary operations
Effective data protection work should of course meet the legal requirements. But it also needs to be practically possible to maintain.
The Swedish Authority for Privacy Protection (IMY) describes systematic data protection as preventive and continuous work. GDPR’s principle of accountability also means that the controller must not only follow the rules but also be able to show how compliance is ensured.
That requires structure. A few recurring questions need to be answerable:
- Which processing of personal data do we have?
- Which need to be reviewed?
- Has anything changed since the last assessment?
- Are the agreements current and is there a legal basis?
- Has retention/erasure been carried out?
- Are there processing activities with elevated risk?
- Who owns the question and when is it to be followed up next?
Our starting point is therefore that GDPR work should not be built to pass a single check. It should be built to work next month and next year too.
A senior GDPR consultant when you need to move forward
The need for a GDPR consultant can look very different.
Sometimes an organisation needs to do a proper current-state or gap analysis and understand what is actually missing. Sometimes the foundation is already there, but a larger backlog needs to be worked off. It can also involve a new IT system, a procurement, AI use, camera surveillance, international transfers or a personal data breach that requires a more qualified assessment.
The consulting support then needs to be able to go further than pointing to an article in the GDPR.
We work at the intersection of data protection, information security, IT, risk and business governance. That means we can help both with the assessment itself and with how it is to be translated into processes, systems, responsibilities and practical measures.
This is also in line with how we work in our other engagements: senior expertise combined with practical implementation, rather than advice that stops at a report.
DPO support – when the data protection officer needs more than a title
The data protection officer, or DPO, has a special role under the GDPR.
The officer should, among other things, monitor compliance, inform and advise, contribute to impact assessments and cooperate with the supervisory authority. At the same time, the ultimate responsibility for GDPR compliance remains with the controller or processor – not with the data protection officer.
That is an important distinction.
A data protection officer should be able to review, challenge and advise. The role should therefore not become the person who is at the same time expected to own and carry out all the data protection work in the organisation.
That is where external DPO support can be valuable.
We can act as specialist support for an existing data protection officer, data protection function, management or business. The support can, for example, involve complex assessments, quality assurance, DPIA, risk assessments, governance, follow-up or bringing structure to activities that otherwise risk being left undone.
The GDPR also allows a formal data protection officer to be external and fulfil the role through a service contract. Such an arrangement needs to be designed so that the GDPR’s requirements on the data protection officer’s position, competence and independence are met.
DPIA – an impact assessment before the risk becomes a problem
A data protection impact assessment, often called a DPIA, is needed when a planned processing of personal data is likely to result in a high risk to people’s rights and freedoms.
It can become relevant when, for example, new technology is introduced, large amounts of sensitive data are processed, people are systematically monitored or when several risk-increasing factors are combined.
A DPIA should normally be carried out before the processing begins. IMY also describes the impact assessment as an ongoing and documented process, not as a one-off form that is completed and then filed away.
We think that is an important starting point.
A good DPIA should help the business understand:
- What are we trying to do?
- Which personal data do we actually need?
- Which people can be affected?
- What can go wrong and how big is the risk?
- Which technical or organisational measures can reduce it?
- Are there remaining risks that mean the processing needs to be changed?
A DPIA should therefore be a basis for decisions, not just documentation for documentation’s sake.
The data protection officer should also be involved when the organisation carries out or considers carrying out a DPIA.
From one-off effort to effective maintenance
A large part of our way of working is about what happens after the first review.
We use our own system support and structured ways of working to hold the GDPR work together and make follow-up more manageable. The idea is simple: the right information should be in the right place, activities should be possible to follow up and it should be possible to see what needs to be handled next.
That makes it easier to move from a large one-off effort to a more ongoing way of working.
We also try to avoid building more administration than the business needs. Existing processes for information security, risk management, supplier governance, incident handling and change management should be used where possible.
This is particularly relevant because the GDPR also requires data protection by design and by default. Data protection therefore needs to be considered when systems, services and processes are designed – not added afterwards once the solution is already finished.
What can we help with?
Kristensson i Skåne can support the organisation on a specific question or help establish and maintain a more complete data protection programme.
The support can include, among other things:
- GDPR and data protection advisory
- current-state and gap analyses
- DPO support and specialist support to the data protection organisation
- data protection impact assessments (DPIA)
- records of processing activities
- risk assessments and prioritisation of measures
- governance documents, routines and responsibilities
- data processor matters and supplier assessments
- data protection when introducing new systems, services and AI solutions
- support during personal data breaches
- training and support for management and the business
- ongoing follow-up and maintenance of the GDPR work
The goal is not to make GDPR more complicated. The goal is to create a structure where the organisation knows what should be done, why it should be done, who is responsible and when it needs to be followed up.
GDPR consultant in Malmö, Lund and Helsingborg
Much of the data protection work can be carried out effectively remotely.
But sometimes physical presence makes a big difference – for example during workshops, current-state analyses, management meetings, DPIA work or when several parts of the business need to gather around a complex question.
Kristensson i Skåne is based in Skåne and works with clients in the region as well as nationally. When local presence is important, we can therefore work closely with businesses in, among others, Malmö, Lund and Helsingborg.
This means you can get local and personal consulting support without limiting the work to occasional meetings. Advisory, documentation and ongoing follow-up can be combined with on-site presence where it creates the most value.
Data protection does not have to become a never-ending project
GDPR work will never be entirely “finished”. Businesses change, systems are replaced, new processing activities are added and the risks change.
But that does not mean the organisation has to live with a constantly ongoing GDPR project.
With a clear current-state picture, prioritised measures, the right responsibilities and a way of working for ongoing follow-up, it is possible to reach a state where data protection is under control and part of ordinary operations.
That is the shift we want to help our clients make.
Do you need a GDPR consultant, support for your data protection officer or help with a DPIA? Contact Kristensson i Skåne and we will have a first conversation about your current state, needs and a suitable approach.
Frequently asked questions
Does Kristensson i Skåne offer a GDPR consultant in Malmö, Lund and Helsingborg?
Yes. We are based in Skåne and work with clients in the region and nationally. When local presence is important – for example during workshops, current-state analyses, management meetings or DPIA work – we can work closely with businesses in Malmö, Lund and Helsingborg, among others.
What is the difference between a data protection officer and external DPO support?
A data protection officer (DPO) monitors compliance, advises and cooperates with the supervisory authority, but the ultimate responsibility for GDPR compliance remains with the controller. External DPO support means we act as specialist support for an existing data protection officer or function, for example with complex assessments, DPIA, quality assurance and follow-up.
When is a DPIA needed?
A data protection impact assessment (DPIA) is needed when a planned processing is likely to result in a high risk to people’s rights and freedoms – for example with new technology, large amounts of sensitive data, systematic monitoring or several risk-increasing factors. A DPIA should normally be carried out before the processing begins.
Can an external data protection officer be appointed?
Yes. The GDPR allows a formal data protection officer to be external and fulfil the role through a service contract. The arrangement needs to be designed so that the requirements on the officer’s position, competence and independence are met.
Does GDPR work have to become a constant project?
No. GDPR work is never entirely finished because businesses and risks change, but with a clear current-state picture, prioritised measures, clear responsibilities and ongoing follow-up, data protection can become part of ordinary operations rather than a constantly ongoing project.
This is a general description of data protection and our services, not legal advice in an individual case.

