Information for individuals
Present purposes, legal bases, recipients, retention periods and rights in accordance with the context of collection.
We map processing activities and implement validated technical settings. This operational support constitutes neither legal advice nor certification of compliance.
4 questions to guide an initial review of your processing, tools and documents. The result does not, on its own, determine your obligations.
Your business:
Indicative guidance. The final analysis depends on actual processing, roles and applicable law. It may require a lawyer or DPO.
The GDPR cannot be reduced to a universal list of documents. Each requirement depends on processing, roles and the level of risk.
Present purposes, legal bases, recipients, retention periods and rights in accordance with the context of collection.
Identify the controller, processor and any joint controllers, then check the clauses required by Article 28.
Assess the limited exception in Article 30. An organisation with fewer than 250 people may still be required to keep records depending on its processing.
Inventory trackers and arrange information or consent according to their purpose. Consent Mode does not replace this analysis.
Check whether processing is likely to result in a high risk, in which case a DPIA is required before implementation.
Apply the criteria in Article 37. The size of the database or the presence of sensitive data alone is not sufficient to reach a conclusion.
The articles below provide reference points. Their application must remain linked to the organisation's context.
Articles 12 to 14
Information must be concise, accessible and adapted to how the data is obtained.
Article 28
The contract must govern the processing entrusted, instructions, security and the processor's assistance.
Article 30
The exception for organisations with fewer than 250 people is limited and is not a general exemption.
Articles 35 and 37
These requirements depend notably on the level of risk, core activities and scale of processing.
The regulation's official text and the authorities' recommendations are included in the references at the bottom of the page.
The schedule is defined after an inventory of processing, tools and necessary approvals.
Distinguish technical work from legal validation
Operational scoping
Map tools, flows and settings to implement.
Decisions and validation
Confirm responsibilities and seek legal advice or a DPO if necessary.
Handover
Document validated choices, tests and team practices.
Review of the website, tools, data flows and existing documents.
Scoping
Identification of roles, technical gaps and matters to refer to legal counsel if necessary.
Analysis
Tool configuration and preparation of materials based on validated decisions and texts.
According to scope
Journey checks, documentation, team training and maintenance plan.
Validation
Operational scoping can also cover your infrastructure: secure email migration and data protection on your website.
One-off operational assessment
SMEs looking to structure their practices
E-commerce, multiple countries or risky processing
Prices excluding VAT. Belgian VAT of 21% applies. Any legal or DPO services are subject to a separate scope.
Operational support in Uccle, Ixelles, Saint-Gilles, Etterbeek, Woluwe-Saint-Pierre and 14 other municipalities.
A 30-minute video call to inventory your tools, flows and operational priorities. This meeting is not a legal consultation.