GDPR Data Protection Officer

With our own professional team and we will provide you with all-inclusive service of a data protection officer who is fully qualified to perform such role under the conditions laid down in Article 37 of GDPR. Under the Regulation, controllers are required to mandate a data protection officer. However, controllers who do not meet such conditions may decide to designate a data protection officer.

On demand
The price is stated without VAT and may be increased depending on the scope of the work performed and the scope of personal data processing.

An analysis of the state of personal data protection and identification of all operations concerning personal data.

Such an analysis of the state of personal data protection with respect to GDPR is essential in order for processes to be set correctly. Based on a thorough analysis we will be able to:

  • map the flow of personal data and define all operations performed upon personal data,
  • define third parties to whom personal data is provided (under a contract or under a legal obligation).
  • identify the categories of personal data you handle (normal personal data or sensitive personal data),
  • determine whether you have adequate personal data protection in place in terms of security of personnel, buildings/facilities, and IT.

Developing a full set of all necessary documents to ensure compliance with GDPR

After the initial analysis, it is necessary to prepare all documents and forms defining all flows of personal data and processes designed to ensure the protection of personal data. The documentation shall include the following:

  • Risk Analysis that contains a quantification of all possible threats and impacts on personal data processing.
  • Security Policy that describes the basic safety precautions necessary to maintain the integrity of personal data.
  • Guidelines that serve to guide people who work with personal data,  containing a description of procedures to handle personal data or to act in different situations, when providing information to data subjects or in the event of security incidents.
  • Processing contracts for processors, which are used to ensure the protection of personal data when providing data for processing to another controller. These model contracts are prepared separately for each processor, based on the type of service that the processor renders to the controller.
  • Information obligation for you to inform all data subjects of which personal data concerning them you process, to whom you provide the data, and of the rights of the data subjects.
  • All necessary forms – consents, authorisations, records, etc. These documents are tailored for each client depending on the purpose and processing of personal data.

Implementing GDPR

Implementing GDPR, which we consider one of the most important activities in the provision of our services. We will help you put the analysis and all the documents into practice.  Setting up the protection of personal data is not just writing down the steps on paper, but mainly configuring the personal data protection system by adoption of certain security measures within the framework of:

  • Building security – we can help you with designing a solution to improve the protection of personal data exactly for the categories the processed data (payroll, accounting, medical records, video surveillance system, registry etc.),
  • Personnel Security – we will train all your employees on how to proceed with the processing of personal data, how to protect such data and how to prevent security incidents, or on the proper procedures in collecting and providing information on the processing of personal data,
  • IT security – we will help you with the design of safety measures in cyberspace and educate authorised persons in the field of social engineering so that personal data of data subjects are protected in this area, too.

Regular care, advice, consulting

Personal data protection spans across a broad range of issues and advances constantly. Regular advice served by the data protection officer will take away the burden from you to watch out for updates of new guidelines and revision of laws. Your assigned data protection officer will monitor all changes in the area of personal data protection and prepare the necessary forms accordingly, and keep you informed about current events in the area of personal data protection. The data protection officer will also perform periodic inspections and training activities in your organisation at agreed intervals to prevent any potential errors in the processing of personal data.

Our goal is to benefit the client

Choosing the right and reliable advisor is always a great help in improving yourself. Above all, consulting in the field of law is extremely broad-spectrum and affects almost all areas of the life of entrepreneurs and individuals, therefore the choice of a legal advisor is extremely important. In the law office Hronček & Partners, s. r. o. we pay attention to professionalism and high quality legal services with an individual approach. Our main goal is to provide legal services of the highest quality and to bring innovative and professional solutions for the client so that we become their trusted partner.

More services in the field of data protection and security

GDPR security documentation

€500.00
The price is stated without VAT and may be increased depending on the scope of the work performed and the scope of personal data processing.

Preparation of a new, tailor-made, basic Controller's Security Documentation, updated according to the current legislation, available decision-making and interpretation practice of the authority (internal regulations intended for the protection of personal data)

Data protection impact assessment

On demand

Processing of data protection impact assessment (DPIA) documentation pursuant to Art. 35 of the GDPR regulation, which is special documentation that the operator is obliged to process only if the legal prerequisites are met (e.g. large-scale processing of special categories of personal data, systematic monitoring of public spaces on a large scale, processing of biometric data and others).

GAP analysis – GDPR

€1,800.00
The price is stated without VAT and may be increased depending on the scope of the work performed and the scope of personal data processing.

Analysis of the processes in the processing of personal data at the customer processing personal data (mapping of purposes, processing of personal data, legal bases, security management, information security, physical security and object security, intermediary contracts, business conditions, regime measures, personnel and administrative security), which will be carried out on the basis of a personal consultation. The analysis shall include proposals for the security of personal data and proposals for the necessary measures to be taken and implemented by the Customer to bring the processing of personal data in line with the GDPR and the law. 

Legal setting of cookies on websites

€200.00
The price is shown without VAT.

Setting up a cookies on websites in accordance with the amendment to the Electronic Communications Act and the GDPR regulation. We still encounter incorrect technical settings, settings of banners and information bars or information obligations. 

Training in the field of personal data protection

On demand
The total price depends on the number of people, the number of trainings and the number of areas/agendas in which your employees need to be trained.

The training is focused on the legitimacy of personal data processing as well as the security of personal data. If interested, we can provide training aimed directly at the given professional group.

Expert advice in the processing of specific processing activities of personal data

On demand
The price depends on the scope of personal data processed in your company and the content and specifications of the project.

The topic of personal data protection does not only concern the GDPR regulation and the Personal Data Protection Act. When setting up individual processes and processing activities, it is also necessary to follow national legislation regulating the specific areas of activity of individual operators (e.g. crowdfunding, provision of installments and loans, etc.).

Information security

On demand
The price depends on the scope of the work performed.

Information security is a solution for securing information systems, information and access to data. The information security management system is evolving with respect to the culture, processes, technologies and requirements of your company / organization. ISO / IEC 27000 standards are a recognized standard in this area to help ensure that your information security policy is appropriate.

Cybersecurity

On demand

Under the Act no. 69/2018 Coll. on Cybersecurity and on Amendments to Certain Acts, an operator of essential services is required to introduce security measures, and is also obliged to verify the effectiveness of the security measures and compliance with the requirements established by this Act. An operator of an essential service is anyone who meets at least one sector-specific criterion and one impact criterion.

Industrial Security and Classified Information

On demand
The price depends on the degree of secrecy and the type of access to classified information.

The subject of the service is the processing of documents pursuant to Act No. 215/2004 Coll. and the relevant decrees of the NSA (National Security Authority), the purpose of which is to ensure the processing of documentation that must be submitted to the National Security Authority in order to obtain an industrial security certificate for the classification level Restricted or Confidential (familiarisation with classified information, hereinafter referred to as the “CI”, storage of the CI in a protected area or together with the documentation for a technical means and the CI processing through a technical means).

We also carry out the security settings of the technical means (e.g. PC) according to the recommendations of the NSU -specified for your company, we will set up your technical means for the needs of certification.


Let's discuss your project together.

Name *
Required
Surname *
Required
E-mail *
Required. Write the e-mail address in correct form.
Telephone number *
Required
Message *
Required