DSGVO / GDPR
General Data Protection Regulation
EU 2016/679
The GDPR applies to any company that processes personal data of EU citizens – regardless of industry or where the company is based. Those who cannot demonstrably meet their obligations risk severe fines and reputational damage.
Supervisory authorities actively audit and impose fines of up to €20M or 4% of global annual turnover. Clean, demonstrable documentation is your most important protection.
Regulation
EU Regulation 2016/679
€20M
Max. fine
4%
Or share of annual turnover
72 hours
Data breach notification
8 rights
Data-subject rights

Who must comply with the GDPR?
The GDPR applies to controllers (who decide on the purposes and means of processing) and processors (who process data on behalf of others). Both carry concrete obligations – with their own liability.
Controllers
- Companies with customer data
- Online shops & websites
- Employers (HR data)
- Associations & clubs
- Practices & law firms
- Public bodies
- Marketing & newsletters
Processors
- Cloud & hosting providers
- IT service providers
- Marketing agencies
- Payroll & accounting
- CRM & SaaS providers
- Call centers & fulfillment
- Analytics & tracking services
Scope of application: The GDPR applies regardless of company size, as soon as personal data of individuals in the EU is processed. Companies outside the EU are also affected if they offer goods or services to EU citizens or monitor their behavior (marketplace principle).
What does the GDPR specifically require?
The GDPR defines clear technical, organizational, and documentation obligations – binding for every controller and processor.
Technical & organizational measures (Art. 32)
Encryption, access control, pseudonymization, and system resilience. TOMs must be appropriate to the risk and documented.
Records of Processing Activities (Art. 30)
Every data processing activity must be documented in a structured way – including purposes, categories, recipients, and deletion periods.
Data Processing Agreements / AVV (Art. 28)
A legally sound data processing agreement must be concluded and maintained with every provider that processes data on your behalf.
Handling data-subject rights
Access, erasure, rectification, and portability requests must be processed on time (generally within one month).
Data Protection Impact Assessment (Art. 35)
Where processing is likely to result in a high risk to data subjects, a DPIA must be carried out and documented – e.g. for extensive profiling.
Data Protection Officer (where required)
A DPO must be appointed when core activities involve large-scale or particularly sensitive processing, or where required by law.
Deadlines & Timeline
The GDPR journey – from adoption to ongoing enforcement.
GDPR adopted
Regulation (EU) 2016/679 is adopted. Companies are given a two-year transition period to implement it.
GDPR becomes applicable
Since 25 May 2018, the GDPR has been directly applicable law in all EU member states – including the fine framework.
Active enforcement
Supervisory authorities continuously audit, impose fines, and publish guidelines. Compliance is an ongoing task.
Act nowAccountability obligation
Controllers must be able to demonstrate compliance with the GDPR at any time (accountability, Art. 5(2)).
How we help you with the GDPR
From data-flow analysis to ongoing support – we make your data protection demonstrable and practical, in three clearly structured phases.
Analysis & Inventory
We map your data flows, assess the status quo, and uncover concrete gaps against the GDPR.
- Data-flow mapping of all processes
- Gap analysis against GDPR obligations
- Building the Records of Processing inventory
- Risk assessment of critical processing
Implementation & Documentation
We implement the necessary technical and organizational measures and create all required documents.
- Implement TOMs technically & organizationally
- Create and conclude AVV templates
- Privacy notices & disclosures
- Set up consent & process design
Support & Operations
Data protection is not a one-time project. We support you permanently with audits, training, and breach response.
- Regular audits & reviews
- Employee training & awareness
- Breach response within 72 hours
- Ongoing monitoring & updates
Frequently Asked Questions about the GDPR
Is your company GDPR-compliant?
Let us check together where you stand – and which measures you need to implement now for demonstrable compliance. Free initial consultation, concrete assessment.
Schedule free initial consultationWe will get back to you within 24 hours.
