What the solution covers

We run two tracks in parallel. One is the documentation that the regulator and your customers read. The other is the technology that actually stops personal data leaking out.

Plan the work

Data map and records

Which personal data you hold, in which systems, for what purpose and for how long. The output is an Article 30 record your own team can keep current.

Processor agreements

A register of every supplier handling data for you, from payroll to the newsletter tool, and a check that each one is covered by a valid DPA.

Risk assessment and DPIA

A sober look at what could realistically harm the people in your data, plus an impact assessment where the processing calls for one. It also rules out needless purchases.

Technical measures

MFA, role-based access in Entra ID, encrypted laptops and mail, access logging and DLP rules in Microsoft 365, tuned to the systems you really run.

Rights requests and breaches

A routine for subject access and erasure within one month, and a breach playbook so your notification reaches Datatilsynet inside 72 hours.

Staff awareness

Short, practical sessions: what may go by email, how to recognise phishing and what to do when a file lands with the wrong recipient.

The order we work in

Tackling everything at once is costly and confusing. Overview comes first, documentation second, and buying or configuring whatever is truly missing comes last.

01

Where the data sits

HR folders, customer database, web forms, CCTV, SaaS tools and whatever consultants or the auditor have been sent. All of it goes on the list.

02

Suppliers and transfers

We check processor agreements and whether data leaves the EU/EEA. Transfers to third countries need a legal basis, and that is where most gaps hide.

03

Documentation

Records, risk assessment, a DPIA if needed, policies, a retention schedule and the breach procedure. Written for your business rather than lifted from a template.

04

Controls and annual cycle

We roll out the technical measures remotely, train your people and set up a yearly compliance calendar so the checks are repeated.

The fine is rarely the biggest cost. A leak of customer data costs most in lost trust, and where a breach puts people at high risk you must tell them directly as well. Explaining to a business partner why their details ended up in public costs more than the whole documentation and implementation project.

Questions and answers

Yes. Neither the GDPR nor the Danish Data Protection Act distinguishes by size. If you have staff and customers, you process personal data. The exemption from keeping records for organisations under 250 employees is narrow and disappears as soon as processing is regular, which payroll always is. A small company has less to map, but the same kinds of documents.

Not automatically. If the provider is certified under the EU-U.S. Data Privacy Framework, or you rely on the EU standard contractual clauses together with a transfer assessment, the transfer can be lawful. It simply has to be documented. If you would rather avoid the question entirely, we can move the system to EU hosting, as described under our EU data residency solution.

For a formal review it might be. Paper does not protect data, though. The GDPR demands appropriate technical and organisational measures, and the regulator checks whether what is described has actually been done. We clearly separate what exists for the supervisory authority from what genuinely lowers the chance of a leak. You set the priorities.

With two weeks or more we can normally deliver both the documentation and the basic technical measures. If the deadline is tighter we will say so honestly and put first whatever the authority is asking about. You write the reply yourselves, while we supply the factual material about your systems.

At least yearly, and whenever you adopt a new system or supplier. Documentation that falls behind is almost as weak as none. Upkeep can be part of a managed IT agreement with us, so the annual cycle does not hinge on one busy colleague.

How far along are you with GDPR?

Tell us what personal data you work with and what is already in place. We review it and show the gap to what the regulation requires.

Coverage
All of Denmark, delivered remotely

This site uses only essential cookies: they keep pages working and store your chosen town. Read more in our privacy policy.