Services · Data protection · GDPR compliance
GDPR compliance in 10 clear steps
A field-tested methodology with ready-made templates and checklists. For businesses with 10–20 employees, we estimate around 40 consulting hours on our side — including a free initial consultation and on-site support. We involve your team only where your input is genuinely needed.

- 1
Document the legal basis for data processing
- 2
Create a record of processing activities
- 3
Conduct a risk assessment
- 4
Implement technical and organizational security measures
- 5
Prepare documentation for internal processing
- 6
Review and conclude data processing agreements
- 7
Structure data transfers to third countries in a legally sound way
- 8
Ensure data subject rights (access, erasure, objection)
- 9
Prepare data breach emergency procedures
- 10
Appoint a data protection officer where required
A note on step 10: Appointing a data protection officer is not mandatory for every business. Under Article 37 GDPR and section 38(1) BDSG, it is required only where at least 20 people are, as a rule, permanently engaged in the automated processing of personal data. Regardless of that headcount, large-scale monitoring of data subjects or the processing of special categories of data under Article 9 GDPR can trigger the obligation. Below those thresholds, appointment is voluntary.
Get a free consultation now
We'll assess, free of charge, where your business stands today and what needs to happen next.