Offer · Data Protection & Privacy

Ongoing GDPR support

Senior support for the operational data protection work: records, agreements, procedures, questions and new systems. For organisations that do not need a formal data protection officer but want the GDPR in order day to day, from a few hours a quarter to regular support every week.

  • Operational support
  • With or without a DPO
  • Quarterly, monthly or weekly
  • Answers normally within a few working days

Who it is for and when

Suits organisations that process personal data but do not need a formal data protection officer, or that have one but lack someone to do the operational work.

  • You do not need a data protection officer, but GDPR questions are left lying.
  • Records, agreements and retention rules were produced once but have not been kept up to date.
  • New systems, suppliers and AI tools are introduced without anyone assessing data protection.
  • Your data protection officer also does the operational work today and needs relief to be able to review independently.

What we do

  1. Start-up and plan. We go through your processing activities, roles and existing documentation and agree what is to be kept up to date, who your contact is and which set-up suits you.
  2. Records and documentation. Records of processing activities, retention rules, privacy information and policies are kept up to date as the business, the systems or the suppliers change.
  3. Agreements and suppliers. New processors are assessed and data processing agreements reviewed before they are signed, and existing suppliers are followed up.
  4. Questions and data subject rights. Questions from the business are normally answered within a few working days, and requests for access, rectification or erasure are handled so that the answers go out within one month.
  5. New systems and incidents. We assess data protection when new systems or AI tools are introduced, decide whether an impact assessment is needed and support you in a personal data breach, from deciding whether it must be notified to the documentation afterwards.
  6. Follow-up. Check-ins at an agreed rhythm and a short report to management on what has been done, which risks exist and what remains.

Three example set-ups

Here are three examples of how the support can be set up. We propose a set-up after the first conversation and adapt the rhythm and content to your business and requirements. Every set-up includes answers to questions, normally within a few working days, help with data subject requests and support in personal data breaches.

Quarterly: a few hours a quarter

Suits organisations with few processing activities, no sensitive personal data and few new systems or suppliers.

  • A check-in once per quarter
  • The record and the privacy information reviewed once per year
  • New data processing agreements reviewed before they are signed
  • A short report to management once per year

Monthly: a number of hours a month

Suits organisations with more processing activities and suppliers, or with customers that set requirements for data protection.

  • Everything in the quarterly level
  • A check-in once per month
  • Records, privacy information and retention rules kept up to date as things change
  • New systems and suppliers assessed before they are introduced
  • Staff training once per year
  • A report to management every six months

Weekly: regular time every week

Suits organisations with many or sensitive processing activities, a high pace of change or high demands from customers, contracts and procurements.

  • Everything in the monthly level
  • Fixed time every week, on site or remotely
  • Involved in projects and purchasing from the start, including the assessment of whether an impact assessment is needed
  • Follow-up of the suppliers and of whether the procedures are followed
  • A report to management every quarter, with key figures for requests, breaches and agreements

What you get

  • A senior contact person and at least one colleague who knows the engagement
  • Records, agreements and procedures kept up to date
  • Answers to questions, normally within a few working days, and help with data subject requests
  • Assessment of new systems, suppliers and the need for an impact assessment
  • Support in personal data breaches
  • Check-ins and reports to management at an agreed rhythm

What we need from you

  • A contact person on your side who holds the data protection work together internally, often a data protection lead or coordinator.
  • That you tell us early when new systems, suppliers or processing activities are planned.
  • Access to those who own the processes and systems when we need answers.
  • That management takes the decisions only management can take, for example on policy, responsibilities and which risks are accepted.

Scope and price

An ongoing engagement whose scope follows your business and requirements: from a few hours a quarter for an organisation with few processing activities, to regular support every week where processing is extensive, the data sensitive or the demands from customers and contracts high.

Larger defined pieces of work, for example an impact assessment or a record built from scratch, are quoted separately. The data protection officer role is an engagement of its own, so that independence is kept.

The price varies from engagement to engagement and depends on the set-up and the scope. You get a proposed set-up and cost after the first conversation.

How it works

  1. A first conversation. We listen to your situation and explain how we usually set up the work. You get our assessment straight away, free of charge.
  2. A proposal with scope and price. A short written proposal with what is included, what you get, who does the work and what it costs.
  3. Delivery and ongoing work. We work together with your organisation, check in at the agreed rhythm and keep the documentation up to date throughout the engagement.

Frequently asked questions

How does this differ from an external data protection officer?

The data protection officer is an independent role under GDPR Articles 37–39 that informs, advises and reviews. Ongoing GDPR support is the operational work: keeping records, agreements and procedures up to date and helping the business day to day. If we are your data protection officer, other consultants do the operational work, so that independence is kept.

Do we need a data protection officer to buy this support?

No. Many organisations do not have to appoint a data protection officer, and the support works just as well without one. We also help you assess whether the requirement in Article 37 applies to you.

Which set-up do we need?

It depends on how many processing activities you have, how sensitive the data is and how much changes. We propose a set-up after the first conversation, from a few hours a quarter to every week, and adjust it as your needs change.

What if there is no order at all today?

Then we usually start with a GDPR current state analysis or with GDPR Start, which takes you to a working baseline. The ongoing support then keeps that level.

Reviewed by Kristensson i Skåne AB. .

Sources: EUR-Lex: Regulation (EU) 2016/679 (GDPR) · IMY (Swedish Authority for Privacy Protection): the GDPR

Would you like the GDPR in order day to day?

Contact us