GDPR security documentation

Preparation of new basic security documentation for the operator, tailored to their needs, updated in accordance with current legislation, available decision-making and interpretative practice of the authority (internal regulations for the protection of personal data), containing the guidelines described below.

The security documentation contains:

  • security policy in accordance with the Regulation, the Act, Decree of the National Security Authority No. 336/2004 Coll. on physical security and facility security, as amended (processing of security strategy in individual areas of security;
  • physical and facility security;
  • security of information systems in the IT area;
  • personnel security with a focus on personal data protection;
  • technical and organizational measures (guidelines and procedures for the processing of personal data by authorized persons);
  • processing of the scope and permitted activities in the processing of personal (sensitive) data (without processing specific access rights for job positions);
  • security risk analysis in the processing of personal data protection pursuant to Articles 25 and 32(2) of the Regulation, in accordance with the STN ISO/IEC 27002 standard – information technology, list of personal data pursuant to Article 13 of the Regulation;
  • records of processing operations, if this obligation arises for the client from the results of the basic process analysis;
  • documentation on the investigation of security incidents;
  • contingency plan;
  • templates for the registration of persons processing personal data for the controller (identification and instruction of persons processing personal data for the controller, i.e., authorized persons);
  • preparation of a tailored information obligation for data subjects, according to the individual purposes of personal data processing identified at the client's premises during the basic process analysis;
  • processing of tailor-made intermediary contracts pursuant to Article 28 of the Regulation for third parties identified in the basic analysis who process personal data on behalf of the client;
  • preparation of sample forms necessary to achieve compliance with the GDPR and the law (sample consents to the processing of personal data, guidelines, advice and recommendations on websites, etc.);
  • provision of information and explanations on the implementation of established processes and the application of procedures within the client's actual operations, consultation on recommended measures as needed.
od €500.00
The price is quoted without VAT and may be increased depending on the scope of work performed and the extent of personal data processing.

Initial consultation

Initial consultation lasting 30 minutes - discussing the company's main activities and goals.

Answering questions

Answering basic questions in the area of personal data processing purposes - 30 minutes.

Drafting of a comprehensive security documentation

Preparation of a comprehensive security documentation reflecting your needs, including preparation of a risk analysis and recommendations of technical and organisational measures for the implementation of the GDPR and the law into the processes of the organisation.

The security documentation contains:

  • Security policy pursuant to the Regulation, Act, Decree of the National Security Authority No. 336/2004 Coll. on Physical Security and Object Security, as amended, (elaboration of a security strategy in individual areas of security;
  • physical and object security;
  • security of information systems in the field of IT;
  • personal security with a focus on the protection of personal data);
  • technical and organisational measures (guideline and procedures for the processing of personal data by authorised persons);
  • processing of the scope and permitted activities in the processing of personal (sensitive) data (without processing specific access rights for job positions);
  • security analysis of risks in the processing of the protection of personal data pursuant to Article 25 and Article 32(2) of the Regulation, according to the standard STN ISO/IEC 27002 – information technology, list of personal data pursuant to Article13 of the Regulation;
  • records of processing operations, if this obligation to the customer arises from the results of basic process analysis;
  • security incident investigation documentation;
  • emergency plan;
  • templates of the registration of persons processing personal data for the controller (designation and instruction of persons processing personal data at the controller, so-called authorised persons);
  • preparation of a tailor-made information obligation for data subjects, according to the individual purposes of the processing of personal data identified by the customer during the basic process analysis;
  • processing of tailor-made intermediation contract pursuant to Article 28 of the Regulation for third parties, identified within the basic analysis, who process personal data on behalf of the customer;
  • development of model forms necessary to comply with the GDPR and the law (model consents to the processing of personal data, guidance, advice and recommendations within websites, etc.);
  • provision of information and explanations for the implementation of set processes and for the application of procedures within the real functioning of the customer, consultation on recommended measures as necessary.

Our goal is to benefit our clients

Choosing the right and reliable advisor is always a great help in improving yourself. Above all, consulting in the field of law is extremely broad-spectrum and affects almost all areas of the life of entrepreneurs and individuals, therefore the choice of a legal advisor is extremely important. In the law office Hronček & Partners, s. r. o. we pay attention to professionalism and high quality legal services with an individual approach. Our main goal is to provide legal services of the highest quality and to bring innovative and professional solutions for the client so that we become their trusted partner.

More services in the field of data protection and security

Services of the person responsible for personal data protection

On demand
The price is quoted without VAT and may be increased depending on the scope of work performed and the extent of personal data processing.

Through our own team of experts, we will provide you with a comprehensive service of a responsible person who is fully qualified to perform this function based on the conditions set out in Article 37 of the GDPR. The appointment of a responsible person has been made mandatory by the regulation for controllers.

Assessment of the impact on personal data protection

On demand

Processing of documentation for impact assessment (DPIA) within the meaning of Article 35 of the GDPR, which is special documentation that the controller is required to process only if the legal conditions are met (e.g., extensive processing of special categories of personal data, systematic monitoring of public spaces on a large scale, processing of biometric data, etc.).

GAP analysis – GDPR

€1,800.00
The price is quoted without VAT and may be increased depending on the scope of work performed and the extent of personal data processing.

Analysis of personal data processing procedures at the client processing personal data (mapping of purposes, personal data processing, legal bases, security management, information security, physical security and facility security, intermediary contracts, terms and conditions, regime measures, personnel and administrative security), which will be carried out on the basis of a personal consultation. The analysis includes proposals for securing personal data and proposals for necessary measures to be adopted and implemented by the client in order to harmonize the processing of personal data in accordance with the GDPR and the law.

Legal settings for cookies on websites

€200.00
The price is listed without VAT.

Cookie settings on websites in accordance with the amendment to the Electronic Communications Act and the GDPR. We still encounter incorrect technical settings, banner and information bar settings, and information obligations.

Training in the field of personal data protection

On demand
The total price depends on the number of people, the number of training courses, and the number of areas/agendas in which your employees need to be trained.

The training focuses on the legitimacy of personal data processing and personal data security. If interested, we can provide training tailored specifically to a given professional group.

Expert advice on specific personal data processing activities

On demand
The price depends on the scope of personal data processed in your company and the content and specifications of the project.

The issue of personal data protection is not limited to the GDPR and the Personal Data Protection Act. When setting up individual processes and processing activities, it is also necessary to comply with national legislation governing specific areas of activity of individual operators (e.g., crowdfunding, provision of installments and loans, and other sector-specific features in various areas).

Information security

On demand
The price depends on the scope of work performed.

Information security is a solution for securing information systems, information, and access to data. The information security management system is developed with regard to the culture, processes, technologies, and requirements of your company/organization. With this service, you get an information security system that complies with ISO/IEC 27000 standards and protects your business from loss and theft by ensuring the protection of all data, whether yours or your customers'.

Cyber security

On demand

In today's digital age, when most sensitive data is processed online, cybersecurity is an essential part of protecting your business. We offer comprehensive solutions to protect against cyber threats, including cybersecurity gap analysisanalysis of sector and impact criteria (NIS2), design and implementation of security measures, audits and penetration tests, continuous SOC monitoringIncident Response, employee training, and cybersecurity manager (CISO as a Service) services. We also provide insurance against cyber threats and security services outsourcing (MSSP). Our solutions guarantee compliance with NIS2, GDPR, ISO 27001 and protect your IT infrastructure from attacks, data leaks, and operational outages.

Industrial safety

On demand
The price depends on the level of secrecy and the type of access to classified information.

The subject of the service is the processing of documents in accordance with Act No. 215/2004 Coll. and relevant NBÚ decrees, the purpose of which is to ensure the processing of mandatory documentation that must be submitted to the National Security Authority in order to obtain industrial security clearance for all levels of classification (Restricted to Top Secret). The documentation may include various processing of classified information (familiarization, storage in a protected area, or, together with documentation for technical means, also processing of classified information using technical means).
We also perform security settings for technical equipment (e.g., PCs) according to the recommendations of the National Security Authority – we will set up your technical equipment for certification purposes.

Preparation and submission of security clearance applications

€7,000.00
The price is quoted excluding VAT and may be increased depending on the scope of work performed and the required level of confidentiality. Administrative fees are not included in the price.

As part of the service provided, we can comprehensively secure the entire process for issuing a license to trade in defense industry products in relation to the National Security Authority, through providing an initial consultation for the purpose of presenting the legal requirements for obtaining confirmation, analyzing the compliance of the business plan with the requirements of the relevant legislation, preparing the documentation for the entrepreneur's security project, and preparing and submitting an application for a security clearance by the National Security Authority.


Let's discuss your project together.

Company *
Povinná položka
Company ID
Name
Required
Surname *
Required
E-mail *
Required. Write the e-mail address in correct form.
Telephone number
Required
Message *
Required

More information about the processing of your personal data can be found HERE.

Povinná položka