attackless
← Back to services
Data protection

GDPR & personal data protection

We help you turn GDPR from a compliance document into an engineering reality: mapping how personal data actually moves through your systems, hardening the technical and organisational measures (TOMs) that protect it, and building a breach-escalation workflow your team can run under pressure. We work alongside your data protection officer or external counsel — we handle the technical implementation, they own the legal interpretation, and we keep the two in sync.

Our lens on your data

The data lifecycle, secured end to end

Every control we build maps to one stage of this flow. Instead of a generic audit checklist, you get measures tied to the actual path personal data takes through your organisation.

Collect
Process
Store
Protect
Respond
How we work

Four pillars, one coordinated program

01

Technical & organisational measures

We document and harden the concrete TOMs GDPR Art. 32 requires — from pseudonymisation and data minimisation in your applications to retention schedules and vendor due diligence — so your controls hold up to both an attacker and an auditor.

02

Access & encryption controls

Least-privilege access to personal data, MFA on every path that reaches it, and encryption at rest and in transit verified end to end — not assumed from a vendor's marketing page.

03

Breach-escalation workflow

A tested, timed runbook: detection, containment, forensic triage, and the internal handoffs that get a supervisory-authority notification out inside the 72-hour window — drafted with your DPO, rehearsed with your team, ready before you need it.

04

Coordination with your DPO & counsel

We are not your data protection officer and we do not give legal advice. Every control we implement is scoped with your DPO or external counsel, so technical decisions and legal obligations stay aligned instead of drifting apart.

Broader privacy and legal questions — lawful basis, cross-border transfers, DPIAs, contracts with processors — stay with your data protection officer or counsel. We plug into that process as the technical partner, not a replacement for it.

Next step

Get a scoped GDPR technical review

Tell us about your data flows and current controls — we'll qualify the engagement and come back with a concrete plan.