vDPO & GDPR compliance

GDPR is not a project. It is a continuous process.

An outsourced Data Protection Officer with software tools. Service and tooling together: DPIA, ROPA, DPA, data subject requests and liaison with AZOP, from a single source.

GDPR Art. 37-39AZOP-approved solutionsCSA · OG 14/2024
Free gap analysisQuote on request
The outsourced DPO service

An appointed DPO, without hiring

GDPR Art. 37 requires many organisations to appoint a Data Protection Officer: public authorities, schools, healthcare, large-scale processing of sensitive data. The vDPO model gives you an appointed, qualified DPO without a new position.

A DPO must not be in a conflict of interest: an IT lead who decides on processing cannot supervise themselves. An external DPO resolves this structurally.

What the vDPO takes on
  • Maintaining records of processing activities (ROPA)
  • Handling data subject requests: access, erasure, portability
  • Reporting personal data breaches to AZOP within 72 hours
  • Liaison with AZOP during audits and inquiries
  • Staff training on data protection
  • Support for DPIAs and new processing activities
Software tools · Included in the service

Compliance that lives in an app, not a binder

A document nobody opens is not compliance. Our tools keep records live, versioned and audit-ready at any moment.

🧭
DPIA wizard

Guided impact assessment under GDPR Art. 35. Structured questions, risk levels, a ready document for the evidence base.

GDPR Art. 35
📋
ROPA records

Records of processing activities under Art. 30. Continuously maintained, versioned, audit-ready.

GDPR Art. 30
📄
DPA templates

Processing agreements between controller and processor. Templates aligned with local practice.

GDPR Art. 28
🔒
Policies and notices

Privacy policy, short and full processing notices, consents. Documents that match your actual processing.

GDPR Art. 12-14
📨
Data subject requests

A guided process from intake to response within the statutory deadline. Every step documented.

GDPR Art. 15-22
🗁️
Audit log

A trail of all actions and decisions. An evidence base that shows continuity, not a one-off project.

Accountability · Art. 5(2)
How we work

Three steps to continuous compliance

01
Gap analysis
We establish the current state for free: records, agreements, policies, actual processing.
02
Set-up
We create the missing documents and processes. ROPA, DPIA, DPA, policies, DPO appointment.
03
Continuity
The vDPO takes on the ongoing role: requests, breaches, new processing, liaison with AZOP.
ℹ Data and records stay in the EU: a Croatian company as processor, EU hosting, no transfers to third countries.
Next step

Start with a free gap analysis

We assess the state of your records, agreements and policies. No obligation. Quotes are issued on request, based on the scope of processing.

Request a gap analysis
Contact
ID Shield Protect Ltd. · Zagreb
📞 +385 98 470-495
📧 info@idshield.com.hr
🌐 idshield.com.hr