Source consolidation
We audit every data source and standardize definitions, so every department starts from the same numbers.
- Data audit and clean-up
- Shared definitions for every metric
- One source of truth across the company
Data Management
We scan and classify the personal data across your systems, build the data catalog and set up the process you answer requests through — so the legal deadline does not depend on who is on holiday.
Who this is for
Compliance usually gets bought under pressure. It is cheaper before.
It is in the operational systems, and also in files each department keeps separately. Nobody holds the complete list.
Someone asked what data you hold on them. The answer took a while, was assembled by hand from several places, and nobody is confident it was complete.
The documents exist and they are correct. What is missing is the link between them and the actual systems: what gets deleted, when, and who checks.
Being compliant is not enough. You have to be able to show how, and that takes a catalog and a record, not a statement.
What you’re losing now
The fine is the argument you already know. The cost you pay anyway, every month, is a different one.
Someone asks IT, someone searches the files, someone checks the archive. The work starts from scratch each time, because nobody documented where they looked last time.
The Regulation requires a response within one month of receiving the request, extendable by at most two further months for complex ones. The clock does not stop while you search your systems.
The policy says data is deleted after a period. With no link to the actual systems it stays there, and the volume grows every month.
What you get
Six deliverables. Three tell you where you stand, three keep you there.
Databases and files are scanned for personal data, and whatever is found is classified by category and by sensitivity.
What personal data exists, in which system, on what legal basis it is processed and who is responsible. The document every audit question is answered from.
Where you stand today, chapter by chapter, against what the Regulation requires. The order in which things get fixed comes out of this.
Not the document — the rule that runs: what is deleted, after how long, from which system, with a record left behind.
Access, erasure, rectification, portability. Who receives the request, which sources the answer is collected from, who approves it and within what time — written once, repeatable every time.
What gets fixed now, what can wait, what needs a decision. With the effort estimated for each, so you can choose.
How we work
You cannot declare compliance over data you have not found yet.
Duration:
You tell us which systems you run, whether requests have already come in, and whether a data protection officer is appointed. The scanning scope comes out of that.
Duration:
Systems and files are scanned, the catalog is built and compliance is assessed chapter by chapter. You end this step with the score and the remediation plan.
Duration: Ongoing
The process for answering requests is set up and the retention rules are switched on. After that they run on their own.
Exact timing depends on how many systems fall inside the scope and how scattered the data is — we agree these with you upfront.
Evidence
An access request starts a manual search through systems and files, and the legal clock runs while the search goes on.
The request starts from a catalog that already says where the data is. Collecting it is a step in a process, not an investigation.
The comparison describes what changes in how you work, not the measured outcome of any particular project.
What stops you
From the same stage
Consolidation brings the data together, quality makes it trustworthy, GDPR defines what you are allowed to do with it.
We audit every data source and standardize definitions, so every department starts from the same numbers.
Identify errors, duplicates and inconsistencies in your data before they become costly business decisions.
Next step
Tell us which decision you want to make better. We’ll tell you whether we can help, and how, concretely.