Mapping what happens to personal data and delivering the documents you need to be able to show: a record of processing activities, a DPIA where one is required, processor agreements and a working method for data breaches and data subject requests.
A privacy statement on your website is not the same as being in order. What trips organisations up during an inspection is accountability: can you show which data you process, on what legal basis and who else has access. That is administration, not legal fireworks, but somebody has to write it down once and keep it current.
Priced per case. An office with three people needs a different record than an organisation with fifteen systems and a handful of vendors. We size it in the discovery call, then you get a fixed price.
Three things that don't fit in a service list, but that decide how working with me feels.
You're not hiring a pair of hands that builds whatever the brief says. If I think your question isn't your real problem, I'll say so. Often there's a simpler or cheaper route, and sometimes the answer is that you shouldn't build this yet. Sparring over that choice is part of the work.
I run the whole track: choice of technology, the build, integrations with your existing systems, testing with real cases, explaining it to your team and maintenance afterwards. One point of contact, and one person responsible when something breaks. No vendors pointing at each other.
Everything I build has to survive current legislation: GDPR, the EU AI Act and the Data Act. That means agreeing up front which data the system may see, processing inside the EU, retention periods, a data processing agreement and a log of what the system did. So you can explain it when somebody asks.
An agent that answers the phone after hours, at peak moments and when everyone is already on a call. It recognises why someone is calling, books an appointment in your calendar, transfers when unsure and emails you the rest.
Read the article →The work nobody enjoys: retyping invoices, moving data from system A to system B, producing the same report every Monday. I map the steps and build the chain that runs without you.
Read the article →For when off-the-shelf doesn't fit: a portal, an internal tool, or an assistant that answers from your own documents and data. Built around your way of working, not a vendor's.
Read the article →The cheapest way to start. I come to you, and afterwards you get a report with the processes that return the most, what each costs, what it saves and what goes wrong if you approach it badly. I also run AI training for teams: what the technology can and cannot do, how to use it safely, and where the gains sit in your own work.
Read the article →For anyone using AI or shipping AI inside their own product. We determine per system which risk category it falls into, which role you hold and what that means in obligations. Then we build the dossier that goes with it.
Read the article →GDPR and the AI Act are not the only laws that touch your software. Depending on what you build and for whom, NIS2, the Cyber Resilience Act, the accessibility directives, the Data Act or DORA apply too. I work out which ones apply to you and what has to happen next.
Read the article →I attack your own software with your written permission, looking for what an attacker would find: logging in without the right password, reaching another customer's data, changing an amount in an order. Whatever works, you get on paper with the evidence attached and with the check that proves later on that it is really closed.
Read the article →Book a free thirty-minute call. You'll get an honest answer, even when that answer is “don't do this yet”.
Book your free intro call → Free · 30 minutes · no obligations