What the data-protection service covers
The GDPR documentation service —what another firm may handle for you today— covers:
- Records of processing activities (RoPA).
- Policies, clauses and legal texts (websites, forms, contracts).
- Processor agreements (art. 28) and supplier control.
- Compliant cookies and notices.
- Impact assessments (DPIA) where required.
- Breach procedure and timely notification.
Data protection ≠ paperwork
Most firms just review paperwork once a year. But protecting data for real means applying the technical and organisational measures of art. 32 —access control, encryption, backups, incident response— and being able to prove it. And that's already cybersecurity.
The important part is already in Plan Tria. The security measures that truly protect your data are included in your managed service. The GDPR documentation and the outsourced DPO are an add-on, for when you also want us to handle the paperwork and replace your current provider.
Outsourced DPO: who needs one
The Data Protection Officer (DPO) is mandatory for some companies and highly advisable for others.
- Mandatory if you carry out large-scale processing, sensitive data (health, etc.) or systematic monitoring, or you're public sector.
- Advisable to have an accountable figure and a point of contact with the authority without loading it onto an employee.
- We provide it as an outsourced DPO, independent from the team implementing the measures.
How we help
- GDPR diagnosis. What applies and where you stand.
- Documentation. RoPA, policies, clauses, cookies.
- Security measures. The real protection (art. 32), within Plan Tria.
- Outsourced DPO, if you need one.
- Maintenance and breaches. All kept up to date, with a timely response if something happens.
Already have a data-protection firm? We replace it and you unify providers: one company expert in both compliance and security, instead of two that don't talk to each other.
Frequently asked questions
Is a DPO mandatory?
Not for every company. It's mandatory in certain cases (large scale, sensitive data, public sector) and advisable in many others. We help you find out if it applies.
Will you replace my current data-protection firm?
Yes. We take on the full documentation so you unify providers and don't run two separately.
Is data protection in Plan Tria or separate?
The real protection (the art. 32 security measures) is in Plan Tria. The GDPR documentation and the outsourced DPO are an add-on.
What happens if I have a data breach?
We have the procedure ready: containment, assessment and notification to the authority within 72 hours where applicable.