office@safebyte.io București, România ISO 27001:2023 · ISO 9001:2023
Audit and compliance

GDPR — security of processing

GDPR has a legal part and a technical one. We cover the technical and organisational side — the measures in Article 32, the impact assessment (DPIA) and breach preparedness — and we focus on what can be demonstrated, not what's written in a policy nobody follows.

Deutsch: această pagină nu e încă tradusă. Textul de mai jos e în English.

GDPR — security of processing

GDPR is often treated as a legal file, while the part that actually prevents a fine — or a breach — is left behind. We cover the technical and organisational side: the measures that effectively protect personal data and, equally important, the evidence that they work. A legal consultant tells you what the law requires; we verify whether the implementation holds up to an inspection and a real attack.

What we verify

  • Security of processing (Art. 32) — technical and organisational measures proportionate to the risk: encryption, access control, pseudonymisation, resilience and, explicitly required by the article, a process for periodically testing and evaluating their effectiveness
  • Minimisation and retention — how much you collect, how long you keep it, who reaches the data; the principles most organisations fail on
  • Impact assessment (DPIA) — for high-risk processing, conducted as a decision-making tool, not a form
  • Breach preparedness — detection and the actual ability to notify within 72 hours, exercised, not assumed

How we work and what you get

Gap analysis on security measures → control testing → evidence → roadmap. We focus on what can be demonstrated, not what’s written in a policy nobody follows. You receive an assessment of technical and organisational measures, recommendations proportionate to processing risk and a remediation roadmap.