GDPR Start
For organisations that know their GDPR work needs to be put in place but not quite where to begin. We start with a current state (gap) analysis and then take you to a working baseline: records, privacy information, a policy and procedures you can show and maintain.
Who it is for and when
Suits small and medium-sized organisations that process personal data but have no data protection function of their own, and that want a foundation they can maintain rather than a pack of documents that is left lying.
- Your GDPR work never really got going, or stopped after 2018.
- You have done a current state analysis and know what is missing, but not how to get there.
- A customer, owner or procurement asks how you handle personal data, and you want to be able to show it.
- You want to be able to run data protection yourselves afterwards, with support when needed.
What we do
- Current state (gap) analysis. We go through your processing activities, documentation, roles and procedures against the requirements of the GDPR, in a start-up meeting with management and workshops with those who know the processing, for example HR, finance, sales and IT. If you already have a current state analysis, we start from it.
- A prioritised plan. What matters most to the data subjects and to the business comes first, in an order you have time for.
- The documentation is produced. Records, privacy information, the data protection policy, the retention plan and the overview of processors are written together with you, so that they match how you actually work.
- The procedures are introduced. The procedures for personal data breaches and data subject rights are gone through with those who will use them, and management adopts the policy and the allocation of responsibilities.
- Training. Management and staff receive training adapted to your business: what applies, what they should do and whom they ask.
- Follow-up after 6 months. We go through what works, what has changed and what remains.
What you get
- A current state (gap) analysis and a prioritised plan with a timeline
- Records of processing activities with purpose, legal basis and retention period per activity
- Privacy information for customers, employees and job applicants, and for the website
- A data protection policy adopted by management
- A personal data breach procedure with a breach log and a flow for notification within 72 hours
- A procedure for data subject rights with reply templates
- A retention plan with retention periods
- An overview of processors with the status of agreements and transfers outside the EU/EEA
- A documented assessment of whether you must appoint a data protection officer
- Training for management and staff
- A follow-up after 6 months
What we need from you
- A contact person who holds the work together on your side.
- Time for workshops with those who know the processing, often HR, finance, sales and IT.
- Existing agreements, policies, lists of systems and earlier analyses.
- Management decisions on the policy and the allocation of responsibilities.
Scope and price
A defined engagement. How long it takes depends on how many processing activities you have and how much is already in place; you get a plan with a timeline after the current state analysis. The documents are delivered in formats you can maintain yourselves, for example Word and Excel or in your existing tools.
Technical security measures in your systems and impact assessments are not included. We point out where they are needed, and they can be done as separate pieces of work.
GDPR Start gives a working baseline, not a guarantee of full compliance. No serious provider can promise that. What you get is a foundation you can show and build on.
We do not set a fixed price in advance. The price is assessed after the initial current state analysis, when we know how many processing activities you have and how much is already in place, and you then get a cost proposal for the rest of the work.
How it works
- A first conversation. We listen to your situation and explain how we usually set up the work. You get our assessment straight away, free of charge.
- A proposal with scope and price. A short written proposal with what is included, what you get, who does the work and what it costs.
- Delivery and handover. We work together with your organisation, report as we go and hand over so you can maintain the result yourselves.
Frequently asked questions
How does this differ from a GDPR current state analysis?
GDPR Start begins with a current state analysis and continues to a working baseline, and we do the work together with you. If you only need a basis for a decision, a stand-alone current state analysis is enough. If you already have one, we start from it.
Are we done with the GDPR afterwards?
You have a working baseline you can show to customers, owners and the supervisory authority. Data protection is never completely done, because business, systems and suppliers change. That is why a follow-up after 6 months is included.
What happens after the follow-up?
Many run the work themselves with the foundation they have been given. If you want help keeping it up to date, there is ongoing GDPR support, from a few hours a quarter.
Would you like to get started with the GDPR?
Contact us