Millecam

GDPR: from privacy statement to a working programme

GDPR is European privacy legislation, applicable to virtually every organisation that processes personal data, but a privacy statement on the website is not the same as a working privacy programme.

Who is this relevant for?

No record of processing activities or DPIA process

The organisation processes personal data, but has no up-to-date record of processing activities and no process to assess new processing activities.

DPO obligation, no internal candidate

A legal DPO obligation applies, but no one on the team has the time, independence or background to take on that role.

Wanting structure after an incident

A complaint, data breach or audit has revealed that privacy has been handled ad hoc until now.

What Millecam does

A GAP analysis against GDPR obligations, followed by building a record of processing activities, a workable DPIA process, and reviewing or drafting data processing agreements: with attention to what's practically feasible for an SME, not a compliance programme built for a multinational.

What you actually get

  • GAP analysis against GDPR obligations
  • Record of processing activities, built and kept maintainable
  • Working process and template for DPIAs (Data Protection Impact Assessments)
  • Data breach notification procedure within the legal 72-hour deadline
  • Review or drafting of data processing agreements with suppliers
  • Tailored privacy policy and statements, no boilerplate
  • Team awareness training on the key obligations

How a GDPR journey unfolds

Step 1

GAP analysis

Where you stand today against GDPR obligations.

Step 2

Build-up

Record of processing activities, DPIA process and procedures in place.

Step 3

Ongoing support

Through DPO-as-a-Service you keep a fixed point of contact.

More about the approach

Result

A privacy programme that holds up under a complaint, audit or data breach, not just a folder of documents that never gets consulted.

Why Millecam

One fixed point of contact, no rotating team. Direct contact with the person doing the work: no junior consultant, no escalation chain. More about Robin.

Ready to get started?

A no-obligation thirty-minute conversation is enough to determine whether, and how, Millecam can help.

Discuss your GDPR journey