Personal data
GDPR audit and data protection impact assessment (DPIA)
Every organisation processes personal data, and where processing is likely to result in a high risk the GDPR requires a prior impact assessment. We check whether processing is lawful and protected and prepare the assessments that are required.
Scope and price are confirmed in writing before work starts.
Discuss your caseThe benefit for your organisation
- You know which processing of personal data is lawful and which has gaps.
- Processing likely to result in a high risk has an impact assessment before it starts.
- You can show the data-protection authority how you comply.
GDPR audit
Records of processing, legal bases, notices, processor contracts, security, breaches, data-subject requests and retention. A report and a plan.
from €2 900up to 100 staff · 2–3 weeks
Impact assessment (DPIA)
For one processing operation likely to result in a high risk: description, necessity and proportionality, risks to people and measures. Where residual risk stays high: preparing prior consultation with the authority.
from €1 900per processing operation
What the GDPR requires
- The controller must be able to demonstrate compliance (Art. 5(2) and 24) and keep records of processing (Art. 30). The limited exemption for organisations under 250 staff does not apply where processing is not occasional, carries a risk or includes sensitive data (Art. 30(5)).
- Processing needs a legal basis (Art. 6), information for people (Art. 13–14), processor contracts (Art. 28) and appropriate security (Art. 32).
- Personal-data breaches are notified to the authority within 72 hours unless unlikely to result in a risk, and people are informed where the risk is high (Art. 33–34).
- Where processing is likely to result in a high risk, an impact assessment is carried out before it starts (Art. 35); national authorities publish lists of operations that require one. Where residual risk stays high, prior consultation is required (Art. 36).
Examples where we check whether an assessment is needed
- Large-scale or public-area video surveillance.
- Employee monitoring and biometric access control.
- Profiling or automated decisions affecting people, including with AI.
- Health and other sensitive data at scale.
After the review we can implement the agreed measures or coordinate your team or a suitable partner. Implementation is quoted separately.
Need a standing data protection officer too? We offer it as an external role. AI use is covered by the AI use and governance review.
Base scope and what you provide
- Audit: one legal entity of up to 100 staff, up to 15 processing activities, up to 5 core systems and up to 2 sites or units.
- Impact assessment: one processing operation, one core system, up to 2 meetings and one round of corrections.
- You provide existing records, notices, processor contracts and a description of the systems. The timeline starts when we receive them.
- One meeting to present the result and one round of corrections. Documents in Bulgarian or English.
Boundaries
- The audit and assessment are not a legal opinion; a specific legal question is commissioned separately.
- Decisions on processing and accountability remain with the controller.
General information, not a legal opinion.