What does our GDPR consulting cover?
GDPR consulting is not a one-size-fits-all product. Depending on your starting point — whether you're just getting started, rolling out new software, or preparing for an audit — what you need can look very different.
AGIDAT offers project-based GDPR consulting: focused on your specific problem, with a clear result, and without an endless consulting marathon.
Typical consulting topics
GDPR introduction and initial documentation
Don't have any data protection documentation yet, or is it incomplete? Together with you, we create:
- Records of Processing Activities (RoPA) per Art. 30 GDPR
- Technical and Organizational Measures (TOMs) per Art. 32 GDPR
- Privacy notice for your website
- Data Processing Agreements (DPAs) with service providers
New software rollouts
Every new piece of software that processes personal data requires a data protection review. We support you with:
- Analysis of the processing activity and its legal basis
- Reviewing the provider and concluding a DPA
- Assessing whether a Data Protection Impact Assessment is required
Vendor review
Do your contractual partners process data on your behalf? We check:
- Whether a DPA is required and correctly in place
- Whether the provider offers sufficient data protection guarantees
- Whether third-country transfers (e.g. US-based services) are permissible
Our consulting process
- Free initial consultation — we understand your request
- Proposal — fixed price or hourly rate, clearly calculable
- Consulting — remote or on-site, pragmatic and direct
- Documentation — you receive all results in writing
- Follow-up support — we accompany implementation on request