← Expertise

GDPR

The GDPR governs how you collect, use and protect personal data. More than seven years in, the rules are well established — and enforcement, fines and individual claims keep growing.

The essentials

What GDPR requires

At its core, GDPR asks you to have a lawful basis for processing, to be transparent, to keep data secure, and to be able to show all of this on request.

Records & lawful basis

A clear record of processing and a defensible lawful basis for each use of data.

Rights & requests

Processes to handle access, deletion and other data-subject requests on time.

Security & breaches

Appropriate safeguards and a tested plan for handling incidents within 72 hours.

How we help

Practical, defensible compliance

We make GDPR workable — focusing on the controls that actually reduce risk rather than paperwork for its own sake.

01

Map

We map your data flows and identify gaps and risks.

02

Fix

Policies, records, contracts and processes brought up to standard.

03

Maintain

Support for requests, audits and new processing as you grow.

Questions & answers

Do we need a DPO?

Not always — it depends on your processing. We help you assess whether one is required.

What about international transfers?

Transfers outside the EU need a valid mechanism such as SCCs and a transfer assessment. We handle both.

How big can fines be?

Up to 4% of global annual turnover for the most serious breaches.