# digigrow GDPR

At Digigrow we like to see GDPR as a reason to streamline business operations and to optimise online engagement strategies, data collection and usage. GDPR should be seen as an opportunity and not as a burden.

## What is GDPR?
A European Regulation to give European citizens back control over their personal data

- Came in to force in May 2016
- Became European law in May 2018
- Non-compliance can induce a fine up to €20 million or 4% of your company’s global gross revenue.

## Advantages of GDPR
- An opportunity to review and optimise your business processes
- Clean, consolidate and centralise your data
- Gain a competitive advantage through GDPR compliance

### Our Process

### Initial Consultation
We present an overview of the GDPR project process and get a high-level overview of your business. This allows you to get a feel for us and how we would work together on the project.

### GDPR Gap Analysis
We carry out onsite visits and undertake a gap analysis of your business to map out all of your data flows and to analyse exactly where and how you interact with GDPR.

### Action Plan
We analyse the collected data and develop a comprehensive report that contains a list of prioritised actions that will help you move to GDPR compliance. You’ll know exactly where to start and what to do to become compliant.

### Implementation
We can help you to implement all of the required compliance actions. This may range from developing documentation to full start to finish project management of your compliance process.

## take your first steps towards gdpr compliance with digigrow

### Does GDPR affect you?
- Any organisation or body located in the EU which is processing data
- Any processing of personal data relating to subjects who are in the EU
- Do you currently capture and hold personal data?
- Do you process personal data?
- Do you instruct others to process personal data for you?

### What is personal data?
- Any information relating to an identifiable person who can be directly or indirectly identified
  - Name
  - Identification number
  - Location data
  - Online identifier

### What does data processing mean?
- Collection
- Recording
- Organisation
- Structuring
- Storage
- Adaptation or alteration
- Retrieval
- Disclosure by transmission
- Dissemination
- Alignment or combination
- Restriction
- Erasure or destruction

### What data is subject to GDPR?
- Personal data as described above
- Sensitive personal data i.e. special categories of personal data such as genetic and biometric data
- Location data
- Online identifier

### What data is not subject to GDPR?
- Personal data used in the prevention, investigation, detection or prosecution of criminal offences
- Personal data used in border checks, asylum and immigration status

### Do I need a Data Protection Officer?
- Does your organisation regularly and systematically monitor individuals at a large scale?
- Does your organisation process special categories of data (religious beliefs, ethnic information, sexual orientation etc.) or personal data relating to convictions or offences?
- Is your organisation a public body or authority?

### Data Protection Officer (DPO) as a Service
- If your business needs a DPO but not on a full-time basis Digigrow’s DPO-as-a-Service can help you meet your obligation to protect personal information.
- On demand access to a DPO to suit your business needs.
- Correctly apply Privacy-by-Design principles to new projects.
- Data Protection Impact Assessments.
- Data breach management and procedures.
- Risk assessment and management.

From €1,000 / month depending on the size and needs of your company.

### GDPR Services
Digigrow offers a range of GDPR services for businesses of all sizes.

#### Small Business
- High level audit of your business
- Investigation into GDPR interaction
- Prioritised actions to help you become compliant

€500 - €1,000

Timeline: ½ - 1 day

#### Staff workshops
- Hands on interactive GDPR workshop with all staff
- Empower your employees to understand GDPR applied to their roles
- On-site recommendations applied to your business

€1,000 - €1,500

Timeline: ½ - 1 day

#### GDPR audit
- Initial scoping consultation
- Interview with all of the necessary stakeholders
- Detailed data mapping
- Complete GDPR gap analysis
- Prioritised action list

€2,000 – €6,000

Variable

#### Ongoing Consultation
- Ongoing GDPR support
- Regular reviews
- Documentation development

- 4 hours €300 / Month
- 8 hours €550 / Month
- 12 hours €750 / Month

#### Let's grow your business together
