Skip to main content
ServicesComplianceAboutContact
Free assessment

Professional cybersecurity services. Protecting your business from modern threats.

ServicesPenetration TestingSOC as a ServiceVulnerability ManagementCloud SecuritySecurity Training
ComplianceISO 27001 ReadinessGDPR ComplianceNIS2 Directive
CompanyAbout UsContactLet's talkBlog
© 2026 IT Baseline OOD (EIK: 202950882). All rights reserved.
Privacy PolicyTerms of ServiceCookies
Compliance

GDPR compliance,without the guesswork.

We map your data, close the gaps and stand up the processes, so personal data stays protected and your compliance holds up to scrutiny.

Start with a gap analysisTalk to an expert

Fines reach 20 million euro or 4 percent of global turnover, breaches that put people's rights at risk must be reported within 72 hours, and eight data subject rights apply to any organisation serving EU residents.

What we deliver

D/01
Gap analysis

We benchmark your current processing against GDPR and map every data flow to surface where you fall short.

D/02
DPIA

Data protection impact assessments for high-risk processing, with concrete mitigation measures documented.

D/03
Records of processing

Article 30 records (ROPA) that document what you process, why, and on what legal basis.

D/04
Policies & DPA

Privacy policies, notices and data processing agreements drafted for your actual operations, not templates.

D/05
Breach response

A tested procedure to detect, assess and report a breach inside the 72-hour window.

D/06
DPO support

An outsourced Data Protection Officer function, from day-to-day advice to liaison with the regulator.

Core principles

P/01
Lawfulness, fairness & transparency

Process data on a valid legal basis and tell people plainly how you use it.

P/02
Purpose limitation

Collect data for specified, explicit purposes and don't reuse it for incompatible ones.

P/03
Data minimisation

Hold only the data you actually need for the task at hand.

P/04
Accuracy

Keep personal data correct and up to date; correct or erase what isn't.

P/05
Storage limitation

Retain data only as long as the purpose requires, then delete it.

P/06
Integrity & confidentiality

Protect data with appropriate security against loss, misuse and unauthorised access.

Questions, answered.

Who must comply with GDPR?+

Every organization that processes the personal data of people in the EU, wherever the organization is based. That includes EU companies and non-EU companies offering goods or services to EU residents.

Do we need a DPO?+

A DPO is mandatory for public authorities, organizations whose core activity is large-scale processing of special-category data, and those carrying out large-scale systematic monitoring of individuals.

What is a DPIA?+

A Data Protection Impact Assessment is required before high-risk processing. It assesses the impact on people's privacy and sets out the measures to reduce that risk.

How long do we have after a data breach?+

72 hours to notify the supervisory authority once you become aware of a breach that risks people's rights. Where the risk is high, the affected individuals must be told as well.

Fines reach 4% of turnover. Readiness costs a fraction of that.
Start with a gap analysis to see where you stand
Start gap analysis