Solution · By task

GDPR compliance

Most firms own a binder labelled “data protection policy”. Trouble starts when a client sends over a security questionnaire, or the DPO asks who can open the HR folder, and nobody has an answer. We are not a law firm, so the legal judgement stays with your DPO or lawyer. What we take on is the technical half: making sure your systems actually behave the way the paperwork says they do.

72 h
to notify a breach to the Polish regulator, UODO
100 %
review and safeguards delivered remotely
PLN 190
per hour excl. VAT outside a plan
Mon-Fri 8-18
team working hours, CET

What the package covers

Six pieces that tie documents to configuration. Your DPO settles lawful bases and wording; we bring hard facts about the systems and switch on the safeguards.

Arrange an online call

Where personal data really sits

We trace it through Comarch Optima, the CRM, Outlook mailboxes, shared drives and web forms. That inventory becomes the raw material for the record of processing activities your DPO keeps.

Vendors needing a processing agreement

Every outside service touching data goes on the list: the accounting office, newsletter tool, shop hosting, e-signature app. Each entry notes where processing happens, so your lawyer knows which contracts to check.

Technical risk assessment

An honest look at likely failures: a stolen laptop with an unencrypted disk, one shared password for the shop admin panel, backups nobody has ever restored. The findings also feed a DPIA if your DPO decides one is needed.

Safeguards set up remotely

MFA on every account, BitLocker enforced through Intune, proper Entra ID roles instead of one shared “admin”, sensitivity labels and DLP rules in Microsoft 365, and access logs kept for as long as your policy says.

Breaches and individual requests

A runbook naming who alerts whom, and in what order, when the payroll file lands in the wrong inbox. Plus a technical routine for finding and erasing one person’s records across every system within the deadline the GDPR sets.

A session for your staff

One hour online, built on examples from your own business: spotting a fake invoice from a “supplier”, what never to paste into an AI chat, and the first few minutes after a file goes to the wrong person.

How the work runs

Facts first, purchases later. Plenty of companies buy expensive tools before noticing that their biggest gap is a former employee’s account that still signs in.

01

Interview and review

A call with whoever owns GDPR internally, then a remote pass over tenants, servers and laptops: permissions, encryption, backups, dormant accounts.

02

Report for the DPO

The data map, the vendor list and a ranked list of gaps. It is written so your DPO or lawyer can drop it straight into the record and the risk analysis.

03

Putting safeguards live

We configure the fixes in the agreed order and timeframe. The work is remote, and any change that needs a pause is scheduled outside your team’s working hours.

04

Evidence and yearly refresh

You keep configuration snapshots, restore-test reports and a permissions list. It is worth refreshing the whole set once a year and whenever a new system arrives.

GDPR trouble often starts with an incident rather than with the policy. For example: a customer complaint, a lost phone, a mailing sent to a hundred people in “To” rather than “Bcc”. What matters then is whether, within 72 hours, you can work out which data leaked and to whom. That is a technical question, and it is the one we prepare you for.

Questions and answers

The technical chapters, yes: passwords, encryption, backups, granting access and incident handling. The legal content, such as lawful bases, privacy notices and retention periods, belongs to your DPO or lawyer. If you have neither, we will say so plainly and suggest handing that part to a law firm.

Not every company is required to appoint one, and whether yours is should be answered by a lawyer. The GDPR duties apply either way. In that case we simply work with the person who looks after data in practice, typically the owner, the office manager or whoever runs HR.

Yes, because remote administration gives us access to systems holding personal data. We can use your template or offer ours. It sets out our level of access, the sub-processors we rely on and how fast we tell you about an incident, so your 72 hours are not spent waiting on us.

Email office@apply.pl straight away with “Support” in the subject line. On the technical side we can attempt a recall in Microsoft 365, kill the shared link and check the logs to see who opened the file and when. Whether to notify UODO or the people affected is a call for the controller and the DPO, but they make it using our findings.

The length of the review depends on headcount and the number of systems, and we agree the scope before starting. It is billed at PLN 190/hour excl. VAT or covered by an ongoing support plan. The cost of the safeguards depends on your starting point: some tools may already be included in the Microsoft 365 licences you pay for, so before suggesting any purchase we check what can simply be switched on.

Let us check how GDPR looks inside your systems

Tell us what personal data you handle, which software you use and who looks after GDPR today. We will reply with a proposed review and a few questions worth putting to your DPO first.

Hours
Mon-Fri 8:00-18:00 CET, reply within one working day
Meetings
Online via Teams or Google Meet

We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.