
- Fill in our questionnaire. The questions are in plain language, with no legal terms, and ask about the personal data your company collects and uses.
- Once you have completed it, we will send you a list of the actions and documents your business needs to put in place to comply with the GDPR.
- We will go through the list with you in a free consultation. After that consultation, we will send you our proposal for helping you get GDPR-ready, with a fixed, specific price for the services.
- Once the legal services agreement is signed, we carry out a GDPR audit, usually as an interview with one or more responsible people in your company. The audit establishes which data protection obligations apply to you, whether the company needs to appoint a data protection officer, and what risks arise from the personal data it collects, uses and stores.
- We deliver a complete set of GDPR documents and an action plan setting out the steps the company should take to remove or reduce the risks connected with collecting, using and storing personal data.
Contact us
Check it yourself
A practical step-by-step guide is on Privacio, a site built by Linden: Records of processing activities: Article 30 fields in plain terms. You can also check whether your organisation needs a record of processing activities with the Privacio tool (in Lithuanian).
Frequently asked questions
Which data protection documents does an organisation actually have to have?
There is no universal list: it depends on what you do. A typical set includes internal data protection procedures, records of processing activities, consents and notices to data subjects, data protection clauses for contracts with individuals, a data processing agreement with service providers, a website privacy policy, a cookie notice, documents governing the use of video cameras, documents for handling personal data breaches, a register form for individuals’ requests, and a document recording the decision to appoint, or not to appoint, a data protection officer.
What does a GDPR audit examine, and how is it carried out?
The audit is carried out as an interview with the responsible people in the organisation, usually remotely. Its aims are to make an inventory of all the personal data processed; to establish which GDPR obligations apply, whether there is a proper legal basis, which documents are missing, whether a data protection impact assessment is needed and whether a data protection officer must be appointed; and to identify the most vulnerable areas and the risks arising from contracts with processors. The set of documents and the action plan are prepared on the basis of the audit.
Does an organisation with fewer than 250 employees have to keep records of processing activities?
The Regulation does contain such an exemption, but it is narrow and in practice hardly anyone qualifies for it. It does not apply if the processing is likely to result in a risk to people’s rights, if the processing is not occasional, or if it covers special categories of data or data relating to criminal offences. Processing employee or customer data is ongoing, so the exemption no longer applies. The records must be made available to the supervisory authority on request.
When do we need to sign a data processing agreement with a service provider, and what must it cover?
Whenever a service provider processes personal data on your behalf: accounting, IT maintenance, server hosting, GPS tracking, payroll administration. The agreement must set out the subject matter and duration of the processing, its nature and purpose, the type of personal data, the categories of data subjects, and the obligations and rights of the controller. The processor may process the data only on the controller’s instructions.
When is a legitimate interest assessment needed, and what does it prove?
When you process data on the basis of legitimate interest, one of the lawful bases set out in the GDPR. It is a written document proving that, before the processing began, the balance between the organisation’s interest and the individual’s right to privacy was assessed. If a dispute or an inspection arises, it is the main evidence that the processing was lawful. In practice it takes a questionnaire and collecting information about the purposes, scope and sources; there is no need to visit every department.
How do we justify how long personal data is kept?
The retention period follows from the purpose; it is not chosen for convenience. Data is kept in a form that allows identification for no longer than is necessary for the purposes for which it is processed. In practice the period is justified either by a legal obligation to keep the document or by the limitation period that applies to claims that may arise from the relationship. The chosen period must be written down, and you must be able to explain it.
Does every personal data breach have to be reported to the supervisory authority?
Not every one. A breach must be reported without undue delay and, where feasible, no later than 72 hours after becoming aware of it, unless it is unlikely to result in a risk to people’s rights and freedoms. But all breaches must be documented, including those that are not reported: the facts, the effects and the remedial action taken. Where the risk is high, the people affected must also be told about the breach separately.
How quickly must we answer a request to access or erase personal data, and may we charge a fee?
You must answer without undue delay and in any event within one month of receiving the request. The period may be extended by a further two months, taking into account the complexity and number of requests, provided you inform the person of the extension within the first month. The information and actions are free of charge. If you do not act on the request, you must explain why within the same month and tell the person of their right to complain to the supervisory authority.
Is it enough to copy the text of the GDPR into our privacy policy?
No. A privacy policy must say what your organisation does: what data it collects, for what purposes, on what legal basis, to whom it discloses it, how long it keeps it and whom to contact. The Regulation requires a concise, transparent, intelligible and easily accessible form, using clear and plain language. Copied text from the Regulation does not meet this requirement and often does not match actual practice, and that mismatch is exactly what an inspection finds.
How often should GDPR documents be reviewed and updated?
The Regulation does not set a specific period, but it requires measures to be reviewed and updated where necessary. The practical trigger is a change in what you do: a new system, a new service provider, a new department, new cameras, a new marketing tool. A set of documents nobody has touched for several years almost never matches real practice, and it is precisely whether documents match practice that the supervisory authority checks.
What technical and organisational security measures does the supervisory authority expect?
The Regulation requires a level of security appropriate to the risk, and the State Data Protection Inspectorate (VDAI) has set out its specific expectations in its guidelines on security measures and risk assessment. There, the measures are grouped by level of risk and linked to the requirements of ISO/IEC 27001, 27002 and 27701. Higher-risk areas, such as health data, are subject to stricter requirements.
How does a supervisory authority inspection work, and how long does it take?
An inspection may start following a complaint or on VDAI’s own initiative. An investigation or inspection on its own initiative lasts no longer than 4 months from the decision to carry it out; it may be extended, but to no more than 6 months in total. A complaint must be examined within 4 months, with an overall limit of no more than 6 months. The first thing requested is documents: the records of processing activities, procedures and justifications.
Will the supervisory authority’s decision about our organisation be made public?
Yes. Since 1 January 2025, VDAI publishes its decisions adopted after an investigation or inspection, or after examining a complaint, on its website within 5 working days, and they remain there for 10 years. Where no infringement is found, the organisation’s identity is not disclosed when the decision is published. This means an inspection can lead not only to a fine but also to a public, long-lasting record.
How do we tell whether we are a data controller or a data processor?
What decides it is not the title of the contract but who determines the purposes and means. If you process data on behalf of another person and on their instructions, you are a processor. Typical processors are hosting providers, GPS system suppliers, accounting service providers and IT subcontractors. A processor may not process the data other than on the controller’s instructions and, when it receives a request or complaint, must pass it on to the controller. The answer determines who writes the privacy policy, who answers data subjects and which agreement needs to be signed.
How long does a GDPR audit take?
Usually a few weeks from the agreement to the document set. The timing depends not on our work but on how quickly we receive answers about the actual practice in your organisation.
Will we have to appoint a data protection officer after the audit?
Not because of the audit. You will find out whether the obligation applies to you under Article 37 GDPR. That is one of the questions the audit answers.
Do you work with public sector bodies?
Yes. Public and budgetary institutions make up a large share of our work in this area, and stricter rules apply to them, starting with the obligation to appoint a data protection officer.