Skip to content
A
28 services

Personal Data Protection

Compliance with Law No. 195/2024 (enters into force 23.08.2026). Full transposition of GDPR into national legislation.

All services in this category

CodeServicePrice
A.1.1Discovery audit of personal data processing

We scan servers, databases, file storage, CRM, backups; identify where and what personal data is processed.

1,320Details
A.1.2Record of Processing Activities (RoPA)

We prepare the document the controller must maintain and present to CNPDCP upon request.

1,320Details
A.1.3Classification of special categories of data

We tag data on health, biometrics, racial origin, political views, criminal records — special regime applies.

1,320Details
A.1.4Data Flow Map

Visualization: where data is transferred (third parties, processors, countries), on what basis.

1,320Details
A.2.1Privacy Policy (RO/RU/EN)

With mandatory elements per art. 13–14: controller identity, purposes, bases, retention, rights, DPO contacts.

1,320Details
A.2.2Consent forms

Explicit, separated, revocable consent forms for marketing, newsletters, third-party transfers.

1,320Details
A.2.3DPA templates with processors

Contracts with hosting, CRM, marketing platforms, accounting services.

1,320Details
A.2.4Internal policies and procedures

Personal data security policy, access regulation, incident management procedure.

1,320Details
A.2.5Cookie banner and Cookie Policy

Granular consent mechanism with cookie categories.

1,320Details
A.3.1Data encryption at rest

TDE on databases, storage volume encryption, backup encryption.

1,320Details
A.3.2Data encryption in transit

TLS 1.3 deployment, HSTS, mTLS between microservices.

1,320Details
A.3.3Pseudonymization and anonymization

Data masking for test environments, PAN tokenization.

1,320Details
A.3.4Access management (IAM)

RBAC/ABAC, MFA, key rotation, orphan account cleanup.

1,920Details
A.3.5Tamper-proof audit logs

Centralized log collection (ELK/Loki), WORM storage, event correlation.

1,560Details
A.4.1DSAR web form

Secure form with requester identification on client's site.

1,320Details
A.4.2Automated request handling workflow

Ticket system with 30-day SLA, escalation, templates, export for portability.

1,920Details
A.4.3'Right to be forgotten' mechanism

Secure deletion scripts respecting legal retention, cascading deletion across systems.

1,920Details
A.5.1Data breach response procedure (IR plan)

Documented plan: detection → assessment → notify CNPDCP within 72h → notify subjects.

1,320Details
A.5.2CNPDCP and data subject notification templates

Ready forms (RO/RU/EN) for CNPDCP filings and affected subjects.

1,320Details
A.5.3Tabletop incident exercises

Breach simulation with client's team, measurement of real response time.

1,320Details
A.6.1DPIA screening — is one needed?

Checklist per art. 36 — mass profiling, special categories, video surveillance, etc.

1,320Details
A.6.2DPIA execution

Full report with risks, mitigation measures, residual risk.

1,920Details
A.6.3Prior consultation with CNPDCP

Preparation of CNPDCP submission package if residual risk remains high.

1,320Details
A.7.1DPO-as-a-Service

Certified external DPO: CNPDCP registration, RoPA maintenance, requests, quarterly report.

Monthly480Details
A.7.2Internal DPO training

Function transfer to employee: training program, document templates, annual support.

1,320Details
A.7.3DPO audit

External annual review of the client's internal DPO operations.

Annual1,320Details
A.8.1Legal basis assessment for cross-border transfers

Check: country recognized adequate, or SCC/BCR/explicit consent needed.

1,320Details
A.8.2SCC implementation

EU template localization, integration into processor contracts (AWS, Google Cloud).

1,320Details