gdpria.eu
Data Processing Agreements, the register, the privacy statement and breach notification assistance — in plain language, with the legal articles included.
The GDPR has applied since 2018 to virtually every business, including a self-employed person with a customer database in an accounting package. In practice, nothing usually happens until someone asks for it: a major customer wants to see a data processing agreement before signing, a tender includes a privacy questionnaire, or an email was sent to the wrong recipient and suddenly the question is how many hours are left.
gdpria was built for exactly those moments. No course and no advisory process, but the documents you need at that moment, a register you maintain yourself, and a decision tree that calculates what you must do within which timeframe in the event of a data breach. Every statement is accompanied by the legal article it comes from, so you can check it and show it to someone else.
機能
The Data Processing Agreement
The agreement your customer wants to see from you, drawn up based on what you actually do — and the explanation of who in that relationship is the processor and who is the controller, because that is where things usually go wrong first when filling it in.
The Processing Register
What you process, why, on what legal basis and how long you keep it. This is the document that the Data Protection Authority requests first, and the only way you can demonstrate that you have an overview.
Breach Notification Assistance
Three clocks that are often confused: 72 hours to notify the Authority from the moment you discover it, inform those affected without undue delay if the risk to them is high, and always document in your own register — even if nothing needs to be reported. The decision tree keeps them separate.
The Privacy Statement
The text for your website, built up from what you actually process instead of from a template with placeholders in it.
The Knowledge Base
Nineteen topics with the article numbers included, from retention periods to AI in the workplace. What is there is automatically checked against the official text on EUR-Lex, so that a reference does not quietly point to the wrong article.
対象ユーザー
- Self-employed people and small businesses who have never done anything about it and now have a customer on the line asking for it
- Businesses that have just had a data breach and want to know if it needs to be reported and within what timeframe
- Entrepreneurs bidding for a contract that includes a privacy questionnaire
- Accountants and web builders who want to set this up for multiple clients
検索される方法
"Do I need to sign a data processing agreement", "notify breach within 72 hours", "processing register example self-employed" — questions that people type in at the moment it matters. In addition, a programmatic series per software package: what data is in it, what data processing agreement the supplier offers and what you still need to arrange yourself. Dutch only: one language that is correct is worth more than eleven that say the same thing.
よくある質問
I am self-employed with five clients. Does this really apply to me too?
Yes, as soon as you process personal data — and a customer database with names and email addresses is already that. What does differ is the scope: under 250 employees there is an exception to the register obligation, but this expires as soon as you process non-incidentally or use special categories of personal data, and the latter is the case with most businesses. The knowledge base explains where you stand.
An email was sent to the wrong person. Do I need to report that?
That depends on what was in it and who received it. The decision tree walks you through it and keeps the three deadlines separate: notify the Authority within 72 hours of discovery, inform those affected if the risk to them is high, and always document it in your own register. The latter also applies if the answer to the first two is no.
Is this a replacement for a lawyer?
いいえ。私たちが提供するのは文書と関連する条項の説明です。紛争が生じた場合、監督当局による調査がある場合、または異常な構成がある場合は、弁護士の検討が必要です。私たちが排除するのは、すべての企業が同じように行わなければならない部分であり、現在それには数千ユーロが費やされています。
なぜどこにでも条項番号が記載されているのですか?
理由は、主張が出所なしに検証できないからであり、また顧客または監督当局に対して、何が基づいているかを示す必要があるからです。さらに、それらは公式テキストに対して機械的に確認され、ずれた条項が検出されるため、長年の間放置されることがなくなります。
このプラットフォームの構築方法
Theos Groupの他のプラットフォームと同様に、1つの共有基盤の上に、独自の管理下で、独自の自動管理者(ここではGELOS)を備えています。管理者は日々のチェックを実行し、障害を報告し、日報を作成します。1つのシステムで学んだことは、翌週には他のすべてのシステムに反映されます。