The GDPR talks about “appropriate technical and organisational measures” and leaves the details to you. Most IT teams only face that question after an incident: a laptop forgotten on a PKP train, a spreadsheet full of PESEL numbers mailed to the wrong address, a payroll login still active weeks after its owner resigned. Our job is to turn the vague wording into settings you can inspect: which people open which records, what the audit trail captures, and what stays encrypted when it travels outside the organisation.
The depth of work follows the data. Medical records at a clinic deserve far stronger controls than a newsletter list, and we will not build defences the risk cannot justify.
Payroll in Symfonia or enova365, the CRM, SharePoint sites, file shares, mailbox attachments, Excel exports saved on sales laptops: we find every spot where personal records actually sit. The resulting list becomes the backbone of your record of processing activities.
Personal logins
Generic accounts like “reception” or “office”, with a password everyone knows, give way to individual identities in Entra ID or Google Workspace. From then on each action belongs to a named person.
Audit trail
Microsoft 365 auditing and file share access logging get switched on, with retention periods long enough to reconstruct events weeks after a suspected breach.
Encryption
BitLocker or FileVault for laptops, protected messages for documents with health or other special category data, and TLS for all traffic heading outside.
Leavers
A routine agreed with HR so that access stops on the final day of employment, SaaS tools outside your domain included, such as the recruitment portal or the web shop admin panel.
Breach playbook
A short plan for the first 72 hours naming who judges the incident, who informs the DPO, who prepares the notification for the UODO President and which logs need securing before they roll over.
How we work together
Cheap changes with a big effect come first. Larger projects follow once the basics hold.
01
Discovery
A video call with your DPO or whoever handles data protection, combined with a remote look at your systems. You end up with an inventory of where personal data lives and how exposed each location is.
02
Early wins
At the start we remove shared logins and dormant accounts of ex-employees and enforce MFA. The impact is visible at once and costs very little.
03
Deeper changes
Encryption, auditing, a tidy permission model and limits on sharing files with outsiders arrive in planned stages, so daily work carries on.
04
Evidence pack
We hand over a description of every safeguard in place, which your DPO can attach to the GDPR records and present if the regulator comes knocking.
Many data breaches have nothing to do with hackers. Common causes are misaddressed email, lost pen drives and accounts of staff who left long ago. Solid routines and sensible configuration therefore protect you better than an expensive licence.
Questions and answers
Give them a more convenient official route, because a ban with no alternative gets ignored. A restricted OneDrive or SharePoint folder with automatic deletion after a set period usually does the job. Add a one-page instruction and, on Intune-managed phones, a rule that keeps company files out of personal apps.
Yes, provided the transfer rests on a valid basis, and the simplest route is keeping everything in EU regions. We check where your services really hold data and switch to an EU region wherever possible. Reviewing supplier contracts remains a task for your DPO or lawyer.
Write to office@apply.pl at once with “Support” in the subject line. We help cut off the source, preserve logs before they are overwritten and establish the scope, so your DPO or lawyer can decide in time on notifying the UODO President. The legal assessment stays with them.
Long enough to notice an intrusion and investigate it. Break-ins often surface only after several weeks, so the default retention in many services can fall short. We pick a period that suits the data and the storage cost, then record that decision in your documentation.
It depends on what you process, for instance large volumes of health data, and a lawyer should settle it. If a DPO is already appointed, we deal with them directly and answer their technical questions.
Hours Mon-Fri 8:00-18:00 CET, reply within one working day
Meetings Online via Teams or Google Meet
Your enquiry has reached us
You will hear back within one working day, and if you have reported an outage that is holding up work, it goes to the front of the queue.
We fill in the gaps. If anything is missing for a quote, we ask by email or suggest a quick call on Teams or Google Meet.
We put a proposal together. Scope, a price in PLN and a start date we can actually hit, with no hidden small print.
You decide in your own time. The offer lands in your inbox. Take a look, ask about any line of it, and only then make up your mind.
Where are you based?
No match for that name. Try a different spelling or pick a bigger town nearby - all our support is delivered online, so your choice has no effect on the service.
We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.