Compliance
Personal data risk analysis
We establish which processing activity creates risk where, and define the mitigating measure and its owner.
- KVKK
- ISO 31000
Risk analysis done as a table-filling exercise ends up on a shelf. The version that works answers this: which activity could harm which person, how, and who will do what to reduce it.
Scope
Screening processing activities for risk
Defining likelihood and impact scales for your organisation
Flagging high-risk activities
Identifying mitigating measures and their owners
Management acceptance of residual risk
What we deliver
Risk register
Prioritised list of measures
An owned action plan with dates
Residual risk acceptance record
The process for this service
Scope
Which activities enter the analysis is decided.
Scales
Likelihood and impact definitions are written for your organisation so everyone reads them the same way.
Assessment
Activities are scored together with process owners.
Measures and follow-up
Measures get owners and dates; residual risk goes on record.
Questions about this service
Our products supporting this service
Other services in the same pillar
- KVKK compliance programme
- Policies, procedures and texts
- VERBIS registration and updates
- Outsourced data protection officer
- Data subject request management
- Retention periods and disposal
- Cross-border data transfers
- Awareness training
- Compliance audit
- ISO 27001 implementation and audit readiness
- ISO 27701 privacy information management system
See where you stand in 20 minutes
The free initial assessment maps your current state and tells you which step should come first. You are not committed to anything afterwards.
Look at it yourself first
A twenty-five question KVKK compliance test with per-area scores and a priority recommendation. No sign-up.
Start the compliance testLet's look together
We discuss your current state and work out which step comes first and how long it takes.
Request a conversation
