AGIDAT – Datenschutz | Informationssicherheit

GDPR Consulting

Project-based GDPR advice — documentation, agreements, and processes.

What does our GDPR consulting cover?

GDPR consulting is not a one-size-fits-all product. Depending on your starting point — whether you're just getting started, rolling out new software, or preparing for an audit — what you need can look very different.

AGIDAT offers project-based GDPR consulting: focused on your specific problem, with a clear result, and without an endless consulting marathon.

Typical consulting topics

GDPR introduction and initial documentation

Don't have any data protection documentation yet, or is it incomplete? Together with you, we create:

  • Records of Processing Activities (RoPA) per Art. 30 GDPR
  • Technical and Organizational Measures (TOMs) per Art. 32 GDPR
  • Privacy notice for your website
  • Data Processing Agreements (DPAs) with service providers

New software rollouts

Every new piece of software that processes personal data requires a data protection review. We support you with:

  • Analysis of the processing activity and its legal basis
  • Reviewing the provider and concluding a DPA
  • Assessing whether a Data Protection Impact Assessment is required

Vendor review

Do your contractual partners process data on your behalf? We check:

  • Whether a DPA is required and correctly in place
  • Whether the provider offers sufficient data protection guarantees
  • Whether third-country transfers (e.g. US-based services) are permissible

Our consulting process

  1. Free initial consultation — we understand your request
  2. Proposal — fixed price or hourly rate, clearly calculable
  3. Consulting — remote or on-site, pragmatic and direct
  4. Documentation — you receive all results in writing
  5. Follow-up support — we accompany implementation on request