Services · Data protection · GDPR compliance

GDPR compliance in 10 clear steps

A field-tested methodology with ready-made templates and checklists. For businesses with 10–20 employees, we estimate around 40 consulting hours on our side — including a free initial consultation and on-site support. We involve your team only where your input is genuinely needed.

Graphic of connected hexagons about GDPR, data, security and documentation over a laptop keyboard
  1. 1

    Document the legal basis for data processing

  2. 2

    Create a record of processing activities

  3. 3

    Conduct a risk assessment

  4. 4

    Implement technical and organizational security measures

  5. 5

    Prepare documentation for internal processing

  6. 6

    Review and conclude data processing agreements

  7. 7

    Structure data transfers to third countries in a legally sound way

  8. 8

    Ensure data subject rights (access, erasure, objection)

  9. 9

    Prepare data breach emergency procedures

  10. 10

    Appoint a data protection officer where required

A note on step 10: Appointing a data protection officer is not mandatory for every business. Under Article 37 GDPR and section 38(1) BDSG, it is required only where at least 20 people are, as a rule, permanently engaged in the automated processing of personal data. Regardless of that headcount, large-scale monitoring of data subjects or the processing of special categories of data under Article 9 GDPR can trigger the obligation. Below those thresholds, appointment is voluntary.

Get a free consultation now

We'll assess, free of charge, where your business stands today and what needs to happen next.