Skip to main content

Quick navigation

What are you looking for?

Suggestions

Enter at least two characters.

GDPR & DIGITAL CONTRACTS

GDPR framework,
controlled implementation.

We map processing activities and implement validated technical settings. This operational support constitutes neither legal advice nor certification of compliance.

Illustration of the data protection framework.
Document rules and responsibilities. Editorial illustration.
Art. 5
Principles
Lawfulness, transparency, minimisation
Art. 28
Processing by third parties
Clauses based on actual roles
Art. 30
Register
Applicability to examine
Art. 35/37
DPIA and DPO
Conditional obligations
INTERACTIVE TOOL

Which GDPR points
need examining?

4 questions to guide an initial review of your processing, tools and documents. The result does not, on its own, determine your obligations.

Your business:

Points to examine

8 points

    Indicative pathway: Scoping and implementation

    Discuss your situation

    Indicative guidance. The final analysis depends on actual processing, roles and applicable law. It may require a lawyer or DPO.

    Checkpoints

    6 topics to put into context.

    The GDPR cannot be reduced to a universal list of documents. Each requirement depends on processing, roles and the level of risk.

    01

    Information for individuals

    Present purposes, legal bases, recipients, retention periods and rights in accordance with the context of collection.

    02

    Roles and processors

    Identify the controller, processor and any joint controllers, then check the clauses required by Article 28.

    03

    Records of processing activities

    Assess the limited exception in Article 30. An organisation with fewer than 250 people may still be required to keep records depending on its processing.

    04

    Cookies and trackers

    Inventory trackers and arrange information or consent according to their purpose. Consent Mode does not replace this analysis.

    05

    Impact assessment

    Check whether processing is likely to result in a high risk, in which case a DPIA is required before implementation.

    06

    Data protection officer

    Apply the criteria in Article 37. The size of the database or the presence of sensitive data alone is not sufficient to reach a conclusion.

    Official framework

    What the GDPR actually requires.

    The articles below provide reference points. Their application must remain linked to the organisation's context.

    Articles 12 to 14

    Transparency

    Information must be concise, accessible and adapted to how the data is obtained.

    Article 28

    Processors

    The contract must govern the processing entrusted, instructions, security and the processor's assistance.

    Article 30

    Register

    The exception for organisations with fewer than 250 people is limited and is not a general exemption.

    Articles 35 and 37

    DPIA and DPO

    These requirements depend notably on the level of risk, core activities and scale of processing.

    The regulation's official text and the authorities' recommendations are included in the references at the bottom of the page.

    Method

    A gradual framework, adapted to the scope.

    The schedule is defined after an inventory of processing, tools and necessary approvals.

    The visual guide

    Distinguish technical work from legal validation

    • Operational scoping

      Map tools, flows and settings to implement.

    • Decisions and validation

      Confirm responsibilities and seek legal advice or a DPO if necessary.

    • Handover

      Document validated choices, tests and team practices.

    Technical support constitutes neither legal advice nor certification of compliance.
    1. 01

      Operational mapping

      Review of the website, tools, data flows and existing documents.

      Scoping

    2. 02

      Priority assessment

      Identification of roles, technical gaps and matters to refer to legal counsel if necessary.

      Analysis

    3. 03

      Implementation

      Tool configuration and preparation of materials based on validated decisions and texts.

      According to scope

    4. 04

      Testing and handover

      Journey checks, documentation, team training and maintenance plan.

      Validation

    Transparency

    What is included,
    and what is not.

    Included in the support

    • Operational mapping of the website, tools and flows
    • Inventory of processing activities to document
    • Technical review of detectable cookies and trackers
    • Banner configuration according to validated choices
    • Support with structuring privacy information
    • Inventory of processors and their available clauses
    • Support with records where applicable
    • Reduction of unnecessary external requests
    • Documentation of the settings implemented
    • 1-hour team training on operational practices

    Optional or available separately

    • Legal advice or certification of compliance
    • Outsourced DPO role
    • Full legal DPIA or validation of whether one is necessary
    • In-depth technical security audit (additional option)
    • Legal drafting or validation of terms of sale, terms of use and contracts
    • GDPR disputes and litigation (specialist lawyer)
    • Guarantee of no inspections or penalties

    Operational scoping can also cover your infrastructure: secure email migration and data protection on your website.

    Investment

    Three levels of support.

    Express audit

    One-off operational assessment

    650 €
    Excluding VAT · Review + 90-day plan
    • Review of 6 areas
    • List of points to address
    • Costed action plan
    • 1-hour presentation
    • No implementation
    Implementation

    Scoping and implementation

    SMEs looking to structure their practices

    €2,500 to €5,500
    Excluding VAT · According to scope
    • Everything in Express audit
    • Consent journey configuration
    • Inventory of processor clauses
    • Documentation support
    • 1-hour team training

    Enhanced support

    E-commerce, multiple countries or risky processing

    From €8,500
    Excluding VAT · Complex profile
    • Everything in Scoping and implementation
    • Coordination with a DPO or legal counsel
    • Multi-country mapping
    • Additional security audit
    • 6 months of operational support

    Prices excluding VAT. Belgian VAT of 21% applies. Any legal or DPO services are subject to a separate scope.

    Frequently asked questions

    Understand the GDPR framework.

    Is my website really subject to the GDPR?
    The GDPR applies notably to processing carried out in the context of the activities of an establishment in the Union. It may also apply to an organisation outside the Union when it offers goods or services to people located there or monitors their behaviour. A website being accessible from Europe is therefore not enough, on its own, to reach a conclusion.
    Are six contracts mandatory for every Belgian digital SME?
    No. Documents and contracts depend on the processing, roles, sales journey and other applicable rules. Privacy information, clauses with a processor under Article 28, records, cookies, terms of sale and terms of use do not all have the same conditions. Consent Mode is a Google tool, not a general GDPR obligation. Electronic invoicing in Belgium falls under yet another framework.
    How much does operational support cost in Brussels?
    Three levels are offered: Express audit at €650 excluding VAT, scoping and implementation from €2,500 to €5,500 excluding VAT depending on tools and journeys, then enhanced support from €8,500 excluding VAT for complex environments. Validation by a lawyer or DPO may be necessary and is not included by default.
    What is a DPA and with whom should one be concluded?
    Article 28 requires a contract or other legal act when processing is entrusted to a processor. The provider's actual role must therefore be established first. The clauses must notably cover the subject matter, duration, instructions, confidentiality, security and assistance. This contract does not, on its own, resolve all issues relating to international transfers.
    Are Google Fonts necessarily non-compliant?
    Loading a font from a third-party server creates a request to that provider and must be analysed alongside the other data flows. Self-hosting can reduce this external request, but is neither GDPR certification nor a sufficient solution for the whole website.
    Does my SME have to appoint a DPO?
    Article 37 notably requires this appointment for a public authority or body, or where core activities involve regular and systematic monitoring on a large scale, or large-scale processing of special categories of data or criminal data. There is no general threshold of 5,000 people per day. The presence of sensitive data alone is not sufficient: core activities and scale must be assessed.
    What penalties does the GDPR provide for?
    Depending on the category of infringement, Article 83 notably provides for a maximum of up to €20 million or 4% of total worldwide annual turnover for the preceding financial year, whichever is higher. This maximum is not an automatic fine. The authority considers the circumstances of the case and also has other corrective powers.

    Free GDPR scoping session.

    A 30-minute video call to inventory your tools, flows and operational priorities. This meeting is not a legal consultation.