Skip to content
HEM Bilişim
All services

Compliance

Personal data risk analysis

We establish which processing activity creates risk where, and define the mitigating measure and its owner.

  • KVKK
  • ISO 31000

Risk analysis done as a table-filling exercise ends up on a shelf. The version that works answers this: which activity could harm which person, how, and who will do what to reduce it.

Scope

01

Screening processing activities for risk

02

Defining likelihood and impact scales for your organisation

03

Flagging high-risk activities

04

Identifying mitigating measures and their owners

05

Management acceptance of residual risk

What we deliver

Risk register

Prioritised list of measures

An owned action plan with dates

Residual risk acceptance record

How we proceed

The process for this service

1

Scope

Which activities enter the analysis is decided.

2

Scales

Likelihood and impact definitions are written for your organisation so everyone reads them the same way.

3

Assessment

Activities are scored together with process owners.

4

Measures and follow-up

Measures get owners and dates; residual risk goes on record.

Questions about this service

See where you stand in 20 minutes

The free initial assessment maps your current state and tells you which step should come first. You are not committed to anything afterwards.

Look at it yourself first

A twenty-five question KVKK compliance test with per-area scores and a priority recommendation. No sign-up.

Start the compliance test

Let's look together

We discuss your current state and work out which step comes first and how long it takes.

Request a conversation