Data map
We track down where personal data really sits: ERP, payroll, SharePoint, shared drives, spreadsheets in mailboxes and exports saved on laptops. That list drives everything else.
GDPR asks for »appropriate technical and organisational measures« and then leaves you to work out what that means. We turn the requirement into concrete configuration in Microsoft 365, file servers and business systems: who may open which records, what gets recorded, and what is encrypted once it travels outside the company.
How far we go depends on the information you hold. A payroll system full of CPR numbers needs more care than a newsletter list, and we never build more than the risk justifies.
We track down where personal data really sits: ERP, payroll, SharePoint, shared drives, spreadsheets in mailboxes and exports saved on laptops. That list drives everything else.
Shared logins such as »reception@« with a password everyone knows are replaced by personal Entra ID accounts, so each action can be traced to a person.
The Microsoft 365 audit log and file server auditing are enabled and retained long enough to investigate an incident months later.
BitLocker on laptops, encrypted email for confidential and sensitive details, and TLS on every connection leaving your network.
A fixed routine agreed with HR, so access is withdrawn on the last working day, including SaaS tools outside the domain.
A short plan for the first 72 hours: who assesses the incident, who notifies Datatilsynet and which logs must be preserved.
We start with whatever closes the biggest gaps fastest and leave the heavier work until the foundations are sound.
A call with your data controller and a remote review of your environment produce a list of systems holding personal data and how well each is guarded today.
Shared logins, stale accounts and missing MFA are cleaned up within days. The difference is visible straight away.
Encryption, logging, a sensible permission structure and limits on external sharing are rolled out in planned stages.
You receive a summary of the measures that slots into your GDPR records and can be shown to an auditor or to Datatilsynet.
Many of the breaches reported to Datatilsynet involve no hacker at all. They are emails sent to the wrong recipient, laptops left behind and former staff whose accounts still work. That is why the most valuable fixes lie in everyday routines rather than in expensive products.
No. That agreement covers Microsoft's responsibility for the platform. How you configure access, sharing and logging is your responsibility as data controller, and that is exactly where most weaknesses appear.
No. Encryption pays off where data can slip out of your control: laptops, USB sticks, backups and emails carrying confidential details. A server in a data centre with controlled access has different needs.
Contact us at once. We help contain the leak, preserve the logs and gauge the scope, so you can decide on notifying Datatilsynet within 72 hours. The legal judgement stays with you or your adviser.
We supply the technical side and describe the measures in a form your record of processing activities can use. Legal wording belongs with your lawyer, but we make sure it matches what the systems really do.
Tell us which systems hold information about customers and staff. We will come back with a view on where the weak spots usually are.
Thank you for getting in touch
One of our consultants already has it. Expect a reply within the working day; anything urgent goes straight to an engineer.
That city is not on our list. Check the spelling or pick the nearest larger town.