gdpria.eu
Data Processing Agreements, the register, the privacy statement and breach notification assistance — in plain language, with the legal articles included.
GDPR has applied since 2018 to virtually every business, including a self-employed person with a customer database in accounting software. In practice, nothing usually happens until someone asks for it: a major customer wants to see a Data Processing Agreement before signing, a tender includes a privacy questionnaire, or an email was sent to the wrong recipient and the question suddenly becomes how many hours are left.
gdpria was built for precisely those moments. No courses and no advisory process, but the documents you need at that moment, a register you maintain yourself, and a decision tree that calculates what you must do within which timeframe in the event of a data breach. Every statement is accompanied by the legal article it comes from, so you can check it and show it to someone else.
What it does
The Data Processing Agreement
The agreement your customer wants to see, drawn up on the basis of what you actually do — and the explanation of who in that relationship is the processor and who is the controller, because that is where things usually go wrong when filling it out.
The Processing Register
What you process, why, on what legal basis and how long you keep it. This is the document the Data Protection Authority requests first, and the only way you can demonstrate that you have an overview.
Breach Notification Assistance
Three timelines that often get mixed up: 72 hours to notify the Authority from the moment you discover it, inform those affected without undue delay if the risk to them is high, and always record it in your own register — even if nothing needs to be reported. The decision tree keeps them separate.
The Privacy Statement
The text for your website, built up from what you actually process instead of from a template with blanks in it.
The Knowledge Base
Nineteen topics with article numbers included, from retention periods to AI in the workplace. What is there is automatically checked against the official text on EUR-Lex, so a reference does not quietly point to the wrong article.
For whom
- Freelancers and small businesses who have never done anything about it and now have a customer on the line asking for it
- Companies that have just had a data breach and want to know if it needs to be reported and within what timeframe
- Entrepreneurs bidding for an assignment that includes a privacy questionnaire
- Accountants and web developers who want to set this up for multiple clients
Where it is found
"Do I need to sign a Data Processing Agreement", "report a breach within 72 hours", "processing register example self-employed" — questions that people type in at the moment it matters. In addition, a programmatic series per software package: what data it contains, what Data Processing Agreement the supplier offers and what you still need to arrange yourself. Dutch only: one language that is correct is worth more than eleven that say the same thing.
Frequently asked questions
I am a freelancer with five customers. Does this really apply to me too?
Yes, as soon as you process personal data — and a customer database with names and email addresses is already that. What does differ is the scope: below 250 employees, an exception to the registration requirement applies, but this lapses as soon as you process non-incidentally or use special categories of data, and the latter is the case with most businesses. The knowledge base explains where you stand.
An email was sent to the wrong person. Do I need to report that?
That depends on what was in it and who received it. The decision tree walks you through it and keeps the three timeframes separate: notify the Authority within 72 hours of discovery, inform those affected if the risk to them is high, and always record it in your own register. The latter also applies if the answer to the first two is no.
Is this a replacement for a lawyer?
No. We provide the documents and explanations with the articles included; in case of a dispute, a supervisory authority investigation, or an unusual structure, a lawyer should review it. What we eliminate is the part that every company has to do the same way and for which thousands of euros are now being charged.
Why are there article numbers everywhere?
Because a claim without a source cannot be verified, and you must be able to show a customer or a supervisory authority where something is based. They are also automatically checked against the official text, so that a shifted article stands out instead of remaining unnoticed for years.
How this platform is built
Like every platform of Theos Group: on one shared foundation, in own management, with its own automatic administrator — here GELOS — that runs the daily rounds, reports malfunctions and writes the daily report. What we learn from one system is in all the others the following week.