Service · GDPR (security side)
GDPR: we cover the security of processing.
GDPR is mostly privacy law - lawful basis, consent, DPAs, data-subject rights, cross-border transfers, and the DPO role. That is work for privacy counsel, not us. What we do is the security half: the Article 32 technical measures that protect personal data, and the technical readiness to detect and report a breach inside the Article 33 window.
What we do (Article 32 + 33, technical)
What technical security does GDPR require?
Article 32 asks for 'appropriate technical measures.' This is that - the engineering, not the legal drafting.
Where personal data lives (technical)
We map the systems, stores, and data flows that hold personal data so it can actually be secured. The legal Record of Processing (RoPA) is built by your privacy lead; we supply the technical picture.
Encryption + access control
Encryption in transit and at rest, MFA, least-privilege access, and key management around personal-data stores.
Logging, monitoring + detection
The monitoring that lets you notice a breach quickly - the difference between a 72-hour notification and finding out from a regulator.
Penetration testing
VAPT and continuous scanning (Vexta) - the 'regular testing of effectiveness' Article 32 explicitly calls for.
Breach-response readiness (technical)
Detection, containment, and evidence-preservation runbook, plus a tabletop so the technical team is not improvising during the 72-hour clock. The legal notification wording and regulator liaison stay with your DPO/counsel.
Resilience + recovery
Backup, restore drills, and availability controls - the 'ability to restore access to personal data' Article 32 requires.
What we own vs. what stays with legal
How we scope it
How do we scope the GDPR security work?
Sized to your systems and data after a short scoping call.
Map
Where personal data lives across your systems, and where it is exposed. Output: a ranked list of technical gaps.
Secure
Encryption, access control, logging/monitoring, and resilience around those data stores.
Test
Penetration testing and scanning to confirm the measures are effective - the testing Article 32 requires.
Rehearse
A breach tabletop so detection, containment, and evidence handling are practiced before you need them for real.
GDPR FAQ
What exactly do you do vs. not do?
Can you be our DPO or write our consent flows?
Are you GDPR-certified yourselves?
What does it cost?
Need the security side of GDPR done right?
Let's scope the Article 32 work. Bring your DPO or privacy counsel for the legal side - we handle the engineering.

