A full audit of personal-data processing, a risk map and a documentation package to demonstrate GDPR and ISO 27701 conformity to regulators and auditors - ahead of turnover-based fines and enforcement action.

Any data controller or processor. If a company collects data of clients, employees or users, it must comply with applicable data protection regulations such as GDPR, maintain records of processing activities and appoint an officer responsible for organising personal-data processing.
Under GDPR the maximum fine for a serious violation is up to $20 mln or 4% of global annual turnover, whichever is higher. Regulators may also order processing to stop and impose reputational and contractual consequences. Personal-data breaches must be notified to the supervisory authority, in many regimes within 72 hours of becoming aware of the incident.
The audit and preparation of the document package take 4-6 weeks: weeks 1-2 - diagnostics, 3-4 - gap analysis and risks, 5-6 - documents and records of processing. The exact schedule is fixed after the express diagnostics.
8-12 internal policy documents: the personal-data processing policy, a regulation, procedures, instructions, records of processing activities, consent templates, a data classification act with assigned protection levels and prepared records of processing aligned with GDPR and ISO 27701.
Yes. We prepare or update the records of processing activities and help appoint the officer responsible for organising processing. Preparing these records is part of the full audit.
Yes. Support is available on a retainer basis: updating the policies, monitoring compliance and supporting regulatory and audit inspections, including the procedure for notifying of incidents within 72 hours.