Data map and records
Which personal data you hold, in which systems, for what purpose and for how long. The output is an Article 30 record your own team can keep current.
It usually starts one of two ways: a letter from Datatilsynet, the Danish Data Protection Agency, or a large customer who wants to see your records, processor agreements and security measures before signing. A policy sitting in a folder satisfies neither. What stands up is documentation that reflects what your systems genuinely do, backed by technical controls that support it.
We run two tracks in parallel. One is the documentation that the regulator and your customers read. The other is the technology that actually stops personal data leaking out.
Which personal data you hold, in which systems, for what purpose and for how long. The output is an Article 30 record your own team can keep current.
A register of every supplier handling data for you, from payroll to the newsletter tool, and a check that each one is covered by a valid DPA.
A sober look at what could realistically harm the people in your data, plus an impact assessment where the processing calls for one. It also rules out needless purchases.
MFA, role-based access in Entra ID, encrypted laptops and mail, access logging and DLP rules in Microsoft 365, tuned to the systems you really run.
A routine for subject access and erasure within one month, and a breach playbook so your notification reaches Datatilsynet inside 72 hours.
Short, practical sessions: what may go by email, how to recognise phishing and what to do when a file lands with the wrong recipient.
Tackling everything at once is costly and confusing. Overview comes first, documentation second, and buying or configuring whatever is truly missing comes last.
HR folders, customer database, web forms, CCTV, SaaS tools and whatever consultants or the auditor have been sent. All of it goes on the list.
We check processor agreements and whether data leaves the EU/EEA. Transfers to third countries need a legal basis, and that is where most gaps hide.
Records, risk assessment, a DPIA if needed, policies, a retention schedule and the breach procedure. Written for your business rather than lifted from a template.
We roll out the technical measures remotely, train your people and set up a yearly compliance calendar so the checks are repeated.
The fine is rarely the biggest cost. A leak of customer data costs most in lost trust, and where a breach puts people at high risk you must tell them directly as well. Explaining to a business partner why their details ended up in public costs more than the whole documentation and implementation project.
Yes. Neither the GDPR nor the Danish Data Protection Act distinguishes by size. If you have staff and customers, you process personal data. The exemption from keeping records for organisations under 250 employees is narrow and disappears as soon as processing is regular, which payroll always is. A small company has less to map, but the same kinds of documents.
Not automatically. If the provider is certified under the EU-U.S. Data Privacy Framework, or you rely on the EU standard contractual clauses together with a transfer assessment, the transfer can be lawful. It simply has to be documented. If you would rather avoid the question entirely, we can move the system to EU hosting, as described under our EU data residency solution.
For a formal review it might be. Paper does not protect data, though. The GDPR demands appropriate technical and organisational measures, and the regulator checks whether what is described has actually been done. We clearly separate what exists for the supervisory authority from what genuinely lowers the chance of a leak. You set the priorities.
With two weeks or more we can normally deliver both the documentation and the basic technical measures. If the deadline is tighter we will say so honestly and put first whatever the authority is asking about. You write the reply yourselves, while we supply the factual material about your systems.
At least yearly, and whenever you adopt a new system or supplier. Documentation that falls behind is almost as weak as none. Upkeep can be part of a managed IT agreement with us, so the annual cycle does not hinge on one busy colleague.
Tell us what personal data you work with and what is already in place. We review it and show the gap to what the regulation requires.
Thank you for getting in touch
One of our consultants already has it. Expect a reply within the working day; anything urgent goes straight to an engineer.
That city is not on our list. Check the spelling or pick the nearest larger town.