Knowing what data you have before you write the policy
Every defensible GDPR program starts with a real data inventory - what personal data you collect, why you collect it, where it lives, how long you keep it, who you share it with, and the lawful basis (Article 6, and where relevant Article 9) for each activity. The Article 30 Record of Processing Activities (ROPA) is the documented output and the first thing a supervisory authority asks for.
We build the ROPA from interviews, system scans, and vendor inventories, then maintain it as your processing landscape changes - new SaaS tools, new marketing campaigns, new product features, new vendor sub-processors. The ROPA is the spine of every downstream artifact: privacy notice, DPIA, vendor DPA, retention schedule.
- Personal data discovery (structured + unstructured)
- Article 30 ROPA authoring and maintenance
- Lawful basis mapping (Art. 6 + Art. 9)
- Retention schedule and minimization review
- Vendor / sub-processor inventory

