Data Protection & Privacy
Kristensson i Skåne AB helps organisations build and improve their data protection work under the GDPR. Support can include current-state and gap analysis, records of processing activities, impact assessments, policies, personal data breaches and ongoing data protection advice. The work is done by consultants who combine legal competence with a technical security background.
In today’s data-driven landscape, organizations face growing expectations and legal requirements to protect personal information. We offer comprehensive Data Protection & Privacy services to protect your business and keep customer trust, and to bring your processing into line with the GDPR. Our team helps you establish robust privacy practices that align with your business goals and meet regulatory standards. We cover the full privacy spectrum, from GDPR program implementation and data governance to ongoing privacy operations, privacy by design, and breach response, so you can operate with confidence. Below are the key areas of our Data Protection & Privacy offerings.
In brief
- Who
- Organisations that process personal data, which is most companies and organisations
- What
- GDPR programmes, ongoing data protection support and an external data protection officer, DPIAs, records of processing activities, breach preparedness
- How
- Current state, prioritised plan, implementation and maintenance, together with your organisation
Common situations
This is how it usually starts. If you recognise yourselves in one of them, we know roughly where to begin.
You process personal data but have no data protection officer
We assess whether you need to appoint one, and take the role or support the person you appoint.
Read about the external DPO →A customer or a procurement requires a DPIA and documentation before signing
We carry out the impact assessment and produce what is requested, on time and in the right form.
Read about DPIAs →You do not really know where all the personal data is
Mapping, records of processing activities and retention rules that work in everyday life.
Read about records and data lifecycle →An incident, a customer or the authority has put the spotlight on data protection
Assessment of whether the breach is notifiable and, where it is, notification to the supervisory authority without undue delay and where feasible within 72 hours. Documentation that holds and a plan that reassures management.
Read about breach preparedness →Offers in data protection
Six ways to start. Each offer can be bought on its own or combined into a coherent data protection programme.
GDPR current-state and gap analysis
Where do you stand against the GDPR today? A documented current state, identified gaps and a prioritised action plan that management can decide on.
You get: a documented current state, identified gaps, a prioritised action plan and a review with management.
Scope: defined engagement, a few days to about a week depending on sizeRead more → Ongoing supportExternal data protection officer (DPO)
We act as, or support, your data protection officer: day-to-day questions, follow-up, data subject rights and reporting to management.
You get: an appointed officer or support for your own, ongoing advice, follow-up and reporting to management.
Scope: ongoing, a number of days per monthRead more → StructureRecords of processing activities and data lifecycle
Article 30 records, data mapping, retention and deletion policies and routines for secure archiving and deletion.
You get: mapping, records of processing activities, retention and deletion rules and routines for deletion.
Scope: defined engagement with handover to youRead more → Projects and systemsImpact assessments (DPIA) and privacy by design
DPIAs for high-risk processing and privacy built into projects and systems from the start.
You get: completed DPIAs with documented measures and residual risk, and a method for privacy by design in your projects.
Scope: per assessment, or as part of a projectRead more → PreparednessPersonal data breaches
Procedures to detect and assess breaches, and to notify the supervisory authority without undue delay and where feasible within 72 hours when the breach is notifiable, exercises and documentation that show you are in control.
You get: a breach procedure with roles and a 72-hour flow, an exercise and documentation that holds.
Scope: defined engagement, exercise as an optionRead more → SuppliersData processing agreements and suppliers
Review of processors, agreements and ongoing follow-up so that your partners keep the same level of privacy as you do.
You get: reviewed agreements, risk-assessed suppliers and a follow-up routine.
Scope: defined engagement, or part of ongoing supportRead more →How the work is done
Current state and gaps
We go through your processing activities, documentation, roles and routines against the requirements of the GDPR, and identify the gaps and the risks.
Priorities and plan
An action plan with realistic timelines, the most critical compliance gaps first, agreed with management.
Implementation
Records of processing, governing documents, routines for data subject rights, DPIAs and breach handling are put in place together with your organisation.
Management and follow-up
DPO support, training, supplier follow-up and recurring reviews, so the work holds over time.
Want to know how we work in each step? Read the detail further down the page →
Frequently asked questions
What is the difference between a controller and a processor?
The controller decides why and how personal data is processed and carries the main responsibility under the GDPR. The processor handles personal data on behalf of the controller, according to instructions and a data processing agreement. Both have obligations, but the controller is accountable to the data subjects and the supervisory authority.
What legal basis do we need to process personal data?
All processing of personal data needs a legal basis under the GDPR, for example contract, legal obligation, legitimate interest or consent. The organisation must also be able to demonstrate purpose, proportionality, transparency and compliance with the basic principles.
When is a data protection impact assessment, DPIA, required?
A DPIA is required when processing is likely to result in a high risk to the rights and freedoms of individuals, for example sensitive data, extensive monitoring or new technology with a large impact.
How does data protection relate to information security?
Data protection requires appropriate technical and organisational security measures. Information security helps the organisation protect personal data against unauthorised access, loss, incorrect changes and unlawful use.
How can we improve our GDPR work in practice?
Start with records of processing activities, clear roles, legal bases, data processing agreements, procedures for data subject rights, breach handling and regular follow-up of risks and controls.
Can Kristensson coordinate NIS2, CRA, GDPR and ISO 27001?
Yes. Kristensson can help the organisation identify common requirements, reduce duplicate work and at the same time handle the requirements that are specific to each regulation or standard. Data protection then becomes part of coherent governance instead of a separate track.
Do we have to appoint a data protection officer?
Yes, if you are a public authority or body, if your core activities involve regular and systematic monitoring of individuals on a large scale, or if you process special categories of personal data or data on criminal convictions on a large scale. Other organisations may appoint a DPO voluntarily. We help you assess whether the role is required and how it should be staffed.
How is an external data protection officer priced?
It varies from engagement to engagement. The set-up depends on the size of the organisation, how many and how sensitive the processing activities are and how much ongoing support you need. We go through the arrangement that suits you in a first conversation.
What is the difference between a data protection officer and a data protection lead?
The data protection officer is an independent role under the GDPR that informs, advises and monitors compliance. The person who owns and drives the practical data protection work in the business is often called the data protection lead or coordinator. The roles complement each other and should be kept apart to avoid conflicts of interest.
How we work with data protection, in detail
For those who want to know how we set up the work in each part. Jump to a section in the menu, or read from the top. About 7 minutes of reading
GDPR Program Support & Implementation
We design and execute GDPR compliance programs tailored to your organization. This begins with a thorough assessment of your current data protection posture to identify gaps and risks. Based on this analysis, we develop a clear remediation roadmap with prioritized activities and realistic timelines, ensuring focus on the most critical compliance gaps first.
Our experts help establish all the foundational elements of a privacy program, from drafting privacy policies and procedures to creating records of processing activities (GDPR Article 30 registers) and other required documentation. We assist in defining roles and responsibilities (including Data Protection Officer considerations) and securing management support, so your GDPR initiative is well-governed and resourced from the start.
In brief
- Assessment of the current data protection posture, gaps and risks
- Remediation and improvement plan with priorities and realistic timelines
- Privacy policies, procedures and records of processing activities (Article 30)
- Roles and responsibilities, including the data protection officer, and anchoring with management
Ongoing Privacy Operations
Data protection is not a one-time project – we provide ongoing support to maintain and improve your privacy program. This can include serving as or supporting your Data Protection Officer. The role is advisory and monitoring: the DPO informs, advises and monitors compliance, and reports to the highest level of management. The GDPR allows the DPO to hold other tasks as long as they do not create a conflict of interest, but whoever monitors the data protection work should not also be taking the decisions about the processing. We implement structured privacy governance (e.g. annual compliance plans) to ensure continuous control, review, and improvement. Regular check-ins and reports to leadership keep everyone informed of the privacy program status.
The operational data protection work is a separate engagement, distinct from the DPO role. We can maintain records of processing activities, administer data subject requests (access, deletion, rectification), and support risk management where applicable. Where we take the DPO role, the operational work is carried out by someone else, so that the independence holds. We also coordinate periodic training and awareness programs to keep your staff educated on privacy practices, making data protection an integral part of your company culture. Additionally, we assist in vetting and monitoring third-party processors – reviewing supplier contracts and data processing agreements to ensure your partners uphold the same privacy standards.
In brief
- We act as or support your data protection officer (DPO), in an advisory and monitoring role
- Annual compliance plans, follow-up and reports to management
- Records of processing activities, data subject rights and risk management in everyday operations
- Training and awareness, review of processors and agreements
Data Governance & Lifecycle Management
Understanding your data is key to protecting it. We help you create a comprehensive inventory of personal data in your systems – mapping what data you have, where it resides, and how it flows between processes. By establishing clear data governance processes, including data classification and ownership, we help you manage personal data consistently and lawfully throughout its lifecycle. These practices give you visibility into your information assets and support compliance efforts like fulfilling data subject rights and reporting obligations.
Our services cover the full data lifecycle, from collection to deletion. We develop and implement retention policies that define how long personal data should be kept and when it must be disposed of. To enforce these policies, we introduce procedures and technical measures for secure archiving and deletion (so data is not kept longer than necessary). This includes setting up routines for regular data clean-up and ensuring that backups and archives are managed in compliance with GDPR. By applying data minimization and timely deletion of data, you reduce risk and storage costs while meeting regulatory requirements. Our data governance approach not only keeps you compliant, but also improves data quality and integrity – so you can trust that the information you retain is accurate, relevant, and well-protected.
In brief
- Inventory and mapping of personal data and data flows
- Data classification, ownership and consistent handling across the lifecycle
- Retention and deletion policies and secure archiving and deletion
- Data minimisation that reduces both risk and storage cost
Privacy by Design & Technology Integration
We integrate Privacy by Design principles into your product development and IT projects from the outset. Our consultants work with your teams to ensure that any new system, application, or process is built with data protection in mind. Concretely, this means we identify potential privacy risks early and specify controls to mitigate them – for example, ensuring that applications only collect necessary data, that sensitive information is encrypted, and that access to personal data is restricted on a need-to-know basis. We establish review checkpoints (such as privacy impact assessments in project workflows or a privacy review board) so that privacy considerations are addressed before new initiatives go live. By weaving privacy into design and procurement processes, we prevent issues and costly rework down the line.
For projects or processes that involve higher-risk personal data uses, we conduct Data Protection Impact Assessments (DPIAs) to evaluate and address those risks. Our team guides you through DPIAs – from analyzing how data is used to recommending safeguards – ensuring you meet GDPR requirements and industry best practices when deploying new technologies. We also advise on and help implement privacy-enhancing technologies, such as anonymization/pseudonymization techniques, encryption solutions, and consent management tools. Through these measures, privacy and security are built into your IT environment by default, supporting compliance and boosting customer confidence in your digital services.
In brief
- Privacy requirements and controls specified early in projects and procurement
- Checkpoints such as DPIAs in project flows and a privacy review board
- Data protection impact assessments (DPIAs) for high-risk processing
- Privacy-enhancing technology: pseudonymisation, encryption and consent management
Breach Preparedness & Accountability
Being prepared for a data breach is a crucial part of privacy protection. We help you develop and refine incident response plans specifically for personal data breaches, often in coordination with your broader IT security incident plans. This includes defining clear procedures to detect and assess potential data breaches, containment steps to minimize damage, and communication protocols to notify the proper authorities and affected individuals when required. GDPR’s 72-hour breach notification rule is strictly accounted for in our plans – we prepare you to gather the necessary information quickly and report incidents to regulators within the required timeframe. Through simulations and tabletop exercises, we can test your breach response process so that your team is ready to act decisively and calmly in the event of a real incident.
We instill a strong sense of accountability in your privacy program, helping you document and provide evidence of compliance in everything you do. Our consultants establish governance practices to record decisions and actions related to data protection – aligning with GDPR’s accountability principle that requires organizations to prove their compliance efforts. We keep the necessary documentation in place and up to date, from processing activity records and consent logs to privacy policies, risk assessments, and training records. If regulators or auditors come knocking, you will have a well-organized trail of how you manage data protection. We also perform periodic compliance audits and gap assessments to verify that controls are working as intended and to recommend improvements. By continuously monitoring and enhancing your privacy measures, we help you not only meet legal requirements but also build trust with customers and partners through transparency and diligence.
In brief
- Incident response plans for personal data breaches, coordinated with IT security
- Procedures to detect, assess, contain and communicate
- The GDPR 72-hour rule built into the set-up and tested through exercises
- Documentation and evidence that demonstrate compliance (accountability)
With Kristensson i Skåne AB as your data protection partner, you gain a trustworthy advisor committed to safeguarding personal data and supporting your compliance journey. Our senior privacy specialists bring extensive experience across various industries, ensuring that our solutions are both pragmatic and aligned with best practices. We tailor our services to your unique needs – whether you are establishing a privacy program from scratch or refining mature processes – and always aim to empower your organization to confidently protect sensitive information. Want to know what it would look like for you? Contact us and we will tell you more. Read more about how we work and about external data protection officer.
Want to know more about how we can strengthen your data protection?
Contact us