Skip to content

Data Management

GDPR compliance, without the manual effort

We scan and classify the personal data across your systems, build the data catalog and set up the process you answer requests through — so the legal deadline does not depend on who is on holiday.

Who this is for

Does any of this sound familiar?

Compliance usually gets bought under pressure. It is cheaper before.

You do not know where the personal data is

It is in the operational systems, and also in files each department keeps separately. Nobody holds the complete list.

A request has already arrived

Someone asked what data you hold on them. The answer took a while, was assembled by hand from several places, and nobody is confident it was complete.

You have policies written but not applied

The documents exist and they are correct. What is missing is the link between them and the actual systems: what gets deleted, when, and who checks.

A client or an audit asked you to prove it

Being compliant is not enough. You have to be able to show how, and that takes a catalog and a record, not a statement.

What you’re losing now

What you lose to compliance done by hand

The fine is the argument you already know. The cost you pay anyway, every month, is a different one.

One access request mobilises half the company

Someone asks IT, someone searches the files, someone checks the archive. The work starts from scratch each time, because nobody documented where they looked last time.

The clock starts on the day of the request

The Regulation requires a response within one month of receiving the request, extendable by at most two further months for complex ones. The clock does not stop while you search your systems.

Retention stays on paper

The policy says data is deleted after a period. With no link to the actual systems it stays there, and the volume grows every month.

What you get

What you actually receive

Six deliverables. Three tell you where you stand, three keep you there.

01 Personal data scanning and classification

Databases and files are scanned for personal data, and whatever is found is classified by category and by sensitivity.

02 A data catalog

What personal data exists, in which system, on what legal basis it is processed and who is responsible. The document every audit question is answered from.

03 A compliance score

Where you stand today, chapter by chapter, against what the Regulation requires. The order in which things get fixed comes out of this.

04 Retention policies applied in the systems

Not the document — the rule that runs: what is deleted, after how long, from which system, with a record left behind.

05 A process for data subject requests

Access, erasure, rectification, portability. Who receives the request, which sources the answer is collected from, who approves it and within what time — written once, repeatable every time.

06 A remediation plan, by priority

What gets fixed now, what can wait, what needs a decision. With the effort estimated for each, so you can choose.

How we work

Inventory first, compliance after

You cannot declare compliance over data you have not found yet.

  1. First call

    Duration:

    You tell us which systems you run, whether requests have already come in, and whether a data protection officer is appointed. The scanning scope comes out of that.

  2. Scanning, catalog and scoring

    Duration:

    Systems and files are scanned, the catalog is built and compliance is assessed chapter by chapter. You end this step with the score and the remediation plan.

  3. Request handling and monitoring

    Duration: Ongoing

    The process for answering requests is set up and the retention rules are switched on. After that they run on their own.

Exact timing depends on how many systems fall inside the scope and how scattered the data is — we agree these with you upfront.

Evidence

What changes in how you work

Before

An access request starts a manual search through systems and files, and the legal clock runs while the search goes on.

After

The request starts from a catalog that already says where the data is. Collecting it is a step in a process, not an investigation.

The comparison describes what changes in how you work, not the measured outcome of any particular project.

What stops you

The questions you ask before you sign

How much does it cost?
The 30-minute call is free. It ends with a proposal at a fixed price for the whole project — not an hourly rate, and not an estimate that keeps moving.
How long before we see something useful?
First results appear in 2–4 weeks. Exact timing depends on how many sources you have and how clean they are — and we agree that before we start, not along the way.
What happens to our data?
It stays with you. Our tools connect to your database, read its structure and build the reporting measures there — nothing is copied or stored on our side. You get a Power BI report file with the metrics defined, which you connect to your own source; the data in it is yours and never passes through us. The exception is prediction: a model needs history, so there we keep aggregated values and model statistics, not individual records and no confidential data. Before we get any access, we sign a confidentiality agreement and a GDPR data processing agreement.
We already have a lawyer for GDPR. Why would we need you?
We do not give legal advice and we do not replace your lawyer. They establish what is required; we find where the data actually sits in your systems, build the catalog and make the rules run. Those are two different jobs, and the second one is still there after the best legal opinion.

From the same stage

The rest of the foundation

Consolidation brings the data together, quality makes it trustworthy, GDPR defines what you are allowed to do with it.

Source consolidation

We audit every data source and standardize definitions, so every department starts from the same numbers.

  • Data audit and clean-up
  • Shared definitions for every metric
  • One source of truth across the company
Learn more

Data quality

Identify errors, duplicates and inconsistencies in your data before they become costly business decisions.

  • Automated audit and profiling
  • Custom validation rules
  • Clean-up and standardization
  • Continuous quality monitoring
Learn more
Back to Data Management

Next step

A 30-minute conversation, no strings attached

Tell us which decision you want to make better. We’ll tell you whether we can help, and how, concretely.