Where to start with GDPR compliance ? We are often asked the question. GDPR start-up projects require a strong knowledge of the regulation, and beyond that, they require collaboration with teams that can grasp the changes linked to the regulation.
We have developed the "GDPR Starter Pack" for organizations that wish to start GDPR compliance process with a solid foundation.
GDPR Starter Pack ensure you to make benefits from foundamental elements of GDPR compliance adapted to your structure.
It is essential to establish and agree written evidences of GDPR complience. This involves both mandatory documents, strictly required by law (such as the register of processing activities or privacy policies); but also documents that indirectly demonstrate compliance with other obligations (such as compliance with the processing principles).
You will then receive three types of deliverables.
AlgoSecure writes an editable version of APR in order to be compliant with the Article 30 of GDPR.
Prior to the mapping, our consultants organize interviews with different team leaders of your company's departments in order to understand the personal data activity flows processed within each department.
Personal data mapping is formalized in a TRA. We can make this last one basing on our TRA template, your TRA template, or even within a GDPR compliance framework. Following the delivery of TRA, department are invited to check the part that concern them and their feedbacks are welcomed by our team.
AlgoSecure writes and delivers three privacy policies to you to ensure compliance with Article 13 of the GDPR. These three policies will be adapted and divided according to your particular needs.
Most of the time, they will deal with the following themes :
AlgoSecure drafts and provides you three internal procedures (with the necessary records, if any) to demonstrate compliance with Articles 12,25 and 33 and 34 of the GDPR.
Integration of the teams involvedDepartments that regularly consult and use these documents are invited to give their feedbacks and eventually suggestions regarding their drafting. This will ultimately provide information materials that they will feel comfortable working with.
As for the internal procedures, the relevant people (DPO, CISO, RSMSI, CIO, manager...) will be consulted in order to know if it is in line with the company's strategy related to information governance.
A reassuring and accessible approach
Many people are apprehensive about changes associated with GDPR compliance. We integrate a reassuring collaboration with a positive prism, which demonstrate the advantages of this compliance for the organization of work, as well as the benefits for the company and employees.
Our approach makes GDPR accessible for everyone who is responsible to enforcing it in their organization, without having to become GDPR experts themselves.
Our AlgoSecure team first collects contextual elements in order to establish basis for the compliance of your structure and define a roadmap. First discussions allow to define the framework, to fix the interviews in order to map the various personal data processed.
Mapping the flow of personal data generated by the company's activity requires an understanding of how that activity works. For this purpose, department managers (or other identified persons) participate in short workshops led by our team, with the objective of identifying all personal data flows and integrating them into the GDPR approach from the start.
Our team uses the information collected to formalize the mapping within a TRA. After checking the latter, the different privacy policies can be produced by our team. At the same time, our team reports the procedures and delivers the package to you.
The feedback meeting is the opportunity to present the delivered elements to all involved and interested persons and to review the GDPR fundamentals. This is also an opportunity to discuss about different aspects of GDPR compliance and to guide the client in his future actions regarding this topic.
To go a little further in the start of your GDPR compliance, we offer you two complementary more services.
Immediately following the production of the TAR, the AlgoSecure team will, upon request, review contracts with your personal data processors, or the entities for which you are personal data processor.
The main objective is to make sure these documents comply to GDPR obligations.
We will also be able to draft a model personal data agreement tailored to your business that you can have your partners sign in the future.
After checking the internal procedures, the AlgoSecure team can make your staff aware of the GDPR. This awareness, adapted to the target audience, will include interactions and evaluation.
You will be given the presentation materials used for the awareness raising, as well as a communication pack allowing you to raise awareness among your employees before and after the awareness raising session(s).
Our GDPR consultants all have a legal background. They have been recruited by us, are an integral part of our teams and are trained daily to develop and maintain expertise.
Our approach makes the GDPR accessible to everyone who is responsible for enforcing it in their organization, without having to become GDPR experts themselves.
In addition, our GDPR team has privileged access to their fellow consultants in the Blue Team, thus further broadening the range of skills available when using our GDPR services.
We accompany you on your RGPD issues
We audit your personal data handling processes and list the points that are not compliant with the GDPR.
Vous n'avez pas de DPO ou vous rencontrez des difficultés pour en recruter un ? Venez découvrir nos services de DPO.
Specialists in information security and pentest in Lyon, Paris, Saint-Etienne and throughout France
You've enabled "Do Not Track" in your browser, we respect that choice and don't track your visit on our website.