Built to Scale|Maatwerksoftware · AI · Automatisering
APPLICABLE LAW – in force since 25 May 2018

DSGVO / GDPR
General Data Protection Regulation
EU 2016/679

The GDPR applies to any company that processes personal data of EU citizens – regardless of industry or where the company is based. Those who cannot demonstrably meet their obligations risk severe fines and reputational damage.

Compliance is not a project, but a permanent duty

Supervisory authorities actively audit and impose fines of up to €20M or 4% of global annual turnover. Clean, demonstrable documentation is your most important protection.

Regulation

EU Regulation 2016/679

€20M

Max. fine

4%

Or share of annual turnover

72 hours

Data breach notification

8 rights

Data-subject rights

dsgvo

Who must comply with the GDPR?

The GDPR applies to controllers (who decide on the purposes and means of processing) and processors (who process data on behalf of others). Both carry concrete obligations – with their own liability.

Controllers

  • Companies with customer data
  • Online shops & websites
  • Employers (HR data)
  • Associations & clubs
  • Practices & law firms
  • Public bodies
  • Marketing & newsletters
🏭

Processors

  • Cloud & hosting providers
  • IT service providers
  • Marketing agencies
  • Payroll & accounting
  • CRM & SaaS providers
  • Call centers & fulfillment
  • Analytics & tracking services

Scope of application: The GDPR applies regardless of company size, as soon as personal data of individuals in the EU is processed. Companies outside the EU are also affected if they offer goods or services to EU citizens or monitor their behavior (marketplace principle).

What does the GDPR specifically require?

The GDPR defines clear technical, organizational, and documentation obligations – binding for every controller and processor.

Technical & organizational measures (Art. 32)

Encryption, access control, pseudonymization, and system resilience. TOMs must be appropriate to the risk and documented.

Records of Processing Activities (Art. 30)

Every data processing activity must be documented in a structured way – including purposes, categories, recipients, and deletion periods.

Data Processing Agreements / AVV (Art. 28)

A legally sound data processing agreement must be concluded and maintained with every provider that processes data on your behalf.

Handling data-subject rights

Access, erasure, rectification, and portability requests must be processed on time (generally within one month).

Data Protection Impact Assessment (Art. 35)

Where processing is likely to result in a high risk to data subjects, a DPIA must be carried out and documented – e.g. for extensive profiling.

Data Protection Officer (where required)

A DPO must be appointed when core activities involve large-scale or particularly sensitive processing, or where required by law.

Deadlines & Timeline

The GDPR journey – from adoption to ongoing enforcement.

1
April 2016

GDPR adopted

Regulation (EU) 2016/679 is adopted. Companies are given a two-year transition period to implement it.

2
May 2018

GDPR becomes applicable

Since 25 May 2018, the GDPR has been directly applicable law in all EU member states – including the fine framework.

3
Ongoing since 2018

Active enforcement

Supervisory authorities continuously audit, impose fines, and publish guidelines. Compliance is an ongoing task.

Act now
4
Continuous

Accountability obligation

Controllers must be able to demonstrate compliance with the GDPR at any time (accountability, Art. 5(2)).

How we help you with the GDPR

From data-flow analysis to ongoing support – we make your data protection demonstrable and practical, in three clearly structured phases.

Phase 1

Analysis & Inventory

We map your data flows, assess the status quo, and uncover concrete gaps against the GDPR.

  • Data-flow mapping of all processes
  • Gap analysis against GDPR obligations
  • Building the Records of Processing inventory
  • Risk assessment of critical processing
2–4 weeks · report included
Phase 2

Implementation & Documentation

We implement the necessary technical and organizational measures and create all required documents.

  • Implement TOMs technically & organizationally
  • Create and conclude AVV templates
  • Privacy notices & disclosures
  • Set up consent & process design
6–12 weeks · complete documentation
Phase 3

Support & Operations

Data protection is not a one-time project. We support you permanently with audits, training, and breach response.

  • Regular audits & reviews
  • Employee training & awareness
  • Breach response within 72 hours
  • Ongoing monitoring & updates
Ongoing · monthly reports

Frequently Asked Questions about the GDPR

Is your company GDPR-compliant?

Let us check together where you stand – and which measures you need to implement now for demonstrable compliance. Free initial consultation, concrete assessment.

Schedule free initial consultation

We will get back to you within 24 hours.

© 2025 THE BARK — Vedat EGE · Oberhausen · the-bark.de