Blog · Area
GDPR
Data protection in practice — what the Regulation says, what follows from it for a controller and where things most often go wrong.
The GDPR is not only about consent forms and notices on a website. It reaches into how an organisation collects data, how long it keeps them, who it discloses them to and whether it can demonstrate all of that — because under Article 5(2) the burden of proof lies with the controller. The articles in this area are about those decisions, not about the text of the Regulation.
If you are dealing with a specific obligation rather than reading up on it, write to us and we will go through it with you.
Articles in this area
Why an IT service provider is a processor
An external technician connects to your server, opens the database and fixes a bug. It takes ten minutes and nobody treats it as…
How to correctly mark a monitored area
EDPB Guidelines 3/2019 say what has to be on the sign at the entrance to a monitored area and what it is enough to make…
How to write a data retention policy
The GDPR does not ask for a document with that name. It asks for something harder: that for every piece of data you can say how…
Tell us what you are dealing with.
Thirty minutes with a consultant who knows your industry. The output is a one-page summary with a recommended approach and an indicative scope — we send it to you even if we do not reach an agreement.