Service · Cybersecurity

GDPR and personal data protection

The GDPR talks about “appropriate technical and organisational measures” and leaves the details to you. Most IT teams only face that question after an incident: a laptop forgotten on a PKP train, a spreadsheet full of PESEL numbers mailed to the wrong address, a payroll login still active weeks after its owner resigned. Our job is to turn the vague wording into settings you can inspect: which people open which records, what the audit trail captures, and what stays encrypted when it travels outside the organisation.

GDPR
translated into settings
72 h
window for notifying UODO
One login
per person, never shared
In stages
clean-up without downtime

Included in this service

The depth of work follows the data. Medical records at a clinic deserve far stronger controls than a newsletter list, and we will not build defences the risk cannot justify.

Talk the scope through with an engineer

Data map

Payroll in Symfonia or enova365, the CRM, SharePoint sites, file shares, mailbox attachments, Excel exports saved on sales laptops: we find every spot where personal records actually sit. The resulting list becomes the backbone of your record of processing activities.

Personal logins

Generic accounts like “reception” or “office”, with a password everyone knows, give way to individual identities in Entra ID or Google Workspace. From then on each action belongs to a named person.

Audit trail

Microsoft 365 auditing and file share access logging get switched on, with retention periods long enough to reconstruct events weeks after a suspected breach.

Encryption

BitLocker or FileVault for laptops, protected messages for documents with health or other special category data, and TLS for all traffic heading outside.

Leavers

A routine agreed with HR so that access stops on the final day of employment, SaaS tools outside your domain included, such as the recruitment portal or the web shop admin panel.

Breach playbook

A short plan for the first 72 hours naming who judges the incident, who informs the DPO, who prepares the notification for the UODO President and which logs need securing before they roll over.

How we work together

Cheap changes with a big effect come first. Larger projects follow once the basics hold.

01

Discovery

A video call with your DPO or whoever handles data protection, combined with a remote look at your systems. You end up with an inventory of where personal data lives and how exposed each location is.

02

Early wins

At the start we remove shared logins and dormant accounts of ex-employees and enforce MFA. The impact is visible at once and costs very little.

03

Deeper changes

Encryption, auditing, a tidy permission model and limits on sharing files with outsiders arrive in planned stages, so daily work carries on.

04

Evidence pack

We hand over a description of every safeguard in place, which your DPO can attach to the GDPR records and present if the regulator comes knocking.

Many data breaches have nothing to do with hackers. Common causes are misaddressed email, lost pen drives and accounts of staff who left long ago. Solid routines and sensible configuration therefore protect you better than an expensive licence.

Questions and answers

Give them a more convenient official route, because a ban with no alternative gets ignored. A restricted OneDrive or SharePoint folder with automatic deletion after a set period usually does the job. Add a one-page instruction and, on Intune-managed phones, a rule that keeps company files out of personal apps.

Yes, provided the transfer rests on a valid basis, and the simplest route is keeping everything in EU regions. We check where your services really hold data and switch to an EU region wherever possible. Reviewing supplier contracts remains a task for your DPO or lawyer.

Write to office@apply.pl at once with “Support” in the subject line. We help cut off the source, preserve logs before they are overwritten and establish the scope, so your DPO or lawyer can decide in time on notifying the UODO President. The legal assessment stays with them.

Long enough to notice an intrusion and investigate it. Break-ins often surface only after several weeks, so the default retention in many services can fall short. We pick a period that suits the data and the storage cost, then record that decision in your documentation.

It depends on what you process, for instance large volumes of health data, and a lawyer should settle it. If a DPO is already appointed, we deal with them directly and answer their technical questions.

Take control of personal data

List the systems that store information about customers and staff. We will reply with a view on where weak spots typically appear.

Hours
Mon-Fri 8:00-18:00 CET, reply within one working day
Meetings
Online via Teams or Google Meet

We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.