Skip to content

Consulting · Data protection

Data protection is organisation, not boilerplate.

Most businesses have a privacy notice and little else. We record which data is actually processed where and turn it into something you can work with day to day and when a request arrives.

Context

Why the privacy notice is the smallest of your problems

In small businesses data protection is usually treated as a text problem: notice on the website, checkbox in the form, done. The actual requirement sits next to that. You need to know which personal data you process, for what purpose, on what legal basis, who processes it on your behalf, and when it gets deleted.

That sounds like bureaucracy until something happens: an applicant requests access, a customer wants to be erased, a provider reports a breach. Without an overview you search for days and still answer incompletely.

The second blind spot is processors. In a normal business that quickly means ten to twenty services: accounting, newsletter, appointment booking, messaging, cloud storage, HR administration. Each needs an agreement under Article 28 GDPR and clarity about which data ends up there.

The third is deletion. Without defined periods nothing ever gets deleted, and then the data holdings breach storage limitation while commercial and tax retention duties run in parallel. Bringing both together is legwork, but it is one-off legwork.

This engagement does that legwork with you and leaves you with documents you can maintain yourself. What it is not: a legal review. Where it becomes a legal question, we name it and you take advice.

What the engagement covers

What happens during the consulting days

Survey of processing activities
Which personal data arises where: customers, prospects, applicants, staff, suppliers. For each activity the purpose, categories of data, recipients and storage location.
Record the processors
All services in use, with the question whether an Article 28 GDPR agreement exists, where processing happens, and whether data goes to a third country.
Set deletion periods
Per category of data, balancing storage limitation against statutory retention duties, and stating where deletion has to happen so nothing survives in a backup or a secondary system.
Name and prioritise gaps
Where consent is missing, agreements are missing, or data is processed without a basis. Sorted by risk, not alphabetically.
How it runs

How the engagement runs

  1. Initial call, free of charge, about 30 minutes We check whether a data protection officer is appointed, what already exists and what triggered this.
  2. Day 1: on-site survey Working through area by area which data arises and which systems it lands in. This almost always surfaces services nobody had on their list.
  3. Analysis between the on-site days We produce the records of processing, the processor list and the draft deletion concept. This time is not billed as a consulting day.
  4. Day 2: walkthrough and periods We go through the drafts, set the deletion periods and prioritise the open points.
  5. Report and handover You receive records, processor list, deletion concept and a list of measures, all in editable form.
What you get

What you hold at the end

Records of processing under Article 30 GDPR
In editable form, so you can maintain it yourself when new services are added.
List of processors
With the status of the Article 28 GDPR agreement, place of processing and a note on third-country transfers.
Deletion concept with periods
Per category of data the period and the place where deletion has to happen, including backups and secondary systems.
Prioritised gap list
What is missing, how urgent it is, and what the next step would be.
Not included

What is not part of this engagement

No legal advice
We do not assess legal questions and do not review contracts legally. Where it becomes a legal matter, we name the point and you take legal advice.
No external data protection officer
That appointment is a separate, ongoing role with its own duties and is not part of this engagement.
No data protection impact assessment
Where an assessment under Article 35 GDPR might be required, we say so. Carrying it out is a separate undertaking.
No changes in the systems
Setting up deletion routines, implementing consent technically or rebuilding access rights are separate services.
Effort and price

Effort and price

Usually two to three consulting days

A business without an HR department and with a manageable system landscape is covered in two days. With many services, several sites or extensive HR administration it becomes three. 1,250 euro per consulting day of eight hours, plus VAT, travel and, where required, accommodation.

1,250 euro per consulting day of 8 hours, plus VAT, travel and, where required, accommodation.

What that means in figures

Consulting days Fee, net
1 1,250 euro
2 2,500 euro
3 3,750 euro
4 5,000 euro
5 6,250 euro

1,250 euro per consulting day of 8 hours, plus VAT, travel and, where required, accommodation.

Frequently asked

Data protection: Frequently asked

What does the data protection survey cost?

1,250 euro per consulting day of eight hours, plus VAT, travel and accommodation where required. Two to three days is typical, so 2,500 to 3,750 euro net.

Does this replace a data protection officer?

No. Whether you must appoint one depends among other things on how many people are constantly engaged in processing and on the type of data. The survey creates the basis any officer needs anyway, but it does not replace the role.

Is this legal advice?

No, and that is an important boundary. We record, structure and name gaps. The legal assessment, for instance whether a legal basis holds or an agreement suffices, belongs to legal advice.

We already have a privacy notice. Is that not enough?

The notice is the outward-facing part. What is additionally required is the internal documentation: records of processing, agreements with processors, a deletion concept and the ability to fulfil data subject rights. That is usually what is missing.

How long may we keep customer data?

It depends on the category. Tax-relevant records are subject to commercial and tax retention periods, other data must be deleted once the purpose ends. The deletion concept settles both per category instead of guessing broadly.

What happens if a supervisory authority asks?

With records, processor list and deletion concept you can answer in a structured way instead of searching. Those three documents are typically the first ones requested.

Talk it through first

A 30-minute call clarifies whether an engagement is the right instrument. If it is not, we say so there.

Last reviewed: