Privacy Engineering

GDPR & Privacy
Engineering

Privacy is not a compliance checkbox — it is a design principle. We architect privacy into your systems, map every data flow, manage your regulatory relationships, and defend your posture when Nordic authorities come calling.

Typical Timeline8–16 weeks
ScopeEU/EEA/UK GDPR
CertificationsCIPP/E · CIPM
CoverageAll 5 Nordic countries
Programme Stats
0DPA audit pass rate
0Avg. time to compliance
0DPIAs completed

Nordic enforcement is accelerating. IMY, Datatilsynet NO, Datatilsynet DK, and Tietosuojavaltuutettu all issued fines exceeding €1M in the past 18 months. Non-compliance is no longer a hypothetical risk.

Nordic Data Protection Authorities

Each Nordic country has its own DPA interpreting GDPR with local nuance. Our team tracks enforcement decisions and regulatory guidance across all five authorities in real time — so our advice is calibrated to how your regulator actually operates, not just the text of the law.

🇸🇪IMYIntegritetsskyddsmyndighetenLargest fine: €75M (2023)
🇳🇴DatatilsynetNorwegian DPALargest fine: €65M (2021)
🇩🇰DatatilsynetDanish DPAActive enforcement since 2021
🇫🇮TSVTietosuojavaltuutettuIncreasing fine volume since 2022
€20MMax fine per violation
4%Of global annual turnover
72hrBreach notification window

The Problem

Most organisations are not non-compliant because they are careless. They are non-compliant because data flows were never documented when systems were built, consent mechanisms were bolted on as afterthoughts, vendor agreements were signed without data processing terms, and nobody owns the answer to the question: what personal data do we hold, where, and why?

The gap between "we have a privacy policy" and "we can demonstrate GDPR compliance to a regulator" is enormous. Regulators have moved past accepting intent — they require evidence: processing records, DPIAs, consent audit trails, breach logs, and DPA agreements. Nordic DPAs are increasingly proactive, initiating investigations based on media coverage, data subject complaints, and their own surveillance of companies' digital practices.

The cost of non-compliance is not just the fine. It is the investigation process — which can run for 12–18 months — and the reputational damage that follows a public enforcement decision. Our job is to make sure you are never in that position.

Our Approach

Every GDPR engagement starts with discovery — not with policy writing. We find out what is actually happening with personal data in your organisation before we advise on what should happen. This produces advice grounded in reality, not documentation that bears no relationship to practice.

01
Discovery

Data Mapping & Flow Analysis

We document every personal data flow — what data, collected from whom, stored where, processed how, shared with which third parties, retained for how long. Covering cloud services, SaaS platforms, on-premises systems, third-party processors, and internal tools. Most organisations discover 30–50% more processing activities than they were aware of.

02
Assessment

Gap Analysis Against GDPR Requirements

Structured assessment across all GDPR obligations: lawful basis for each processing activity, data subject rights mechanisms, privacy notice accuracy, DPA agreements with all processors, retention policy implementation, breach notification procedure, cross-border transfer compliance, and special category data handling.

03
High-Risk Processing

DPIA for High-Risk Activities

We conduct Data Protection Impact Assessments for all processing that is likely to result in high risk to data subjects — AI systems, large-scale profiling, systematic monitoring, special category data at scale, and automated decision-making with legal or similarly significant effects.

04
Engineering

Consent & Privacy Architecture

We implement — not just design. Consent management platforms configured to Article 7 requirements with audit trails. Privacy notices rewritten to be accurate and compliant. Cookie banners rebuilt to actually work the way they claim. Preference centres that give data subjects genuine control.

05
Remediation

Full Gap Remediation

We fix the gaps our assessment finds. DPA agreements updated and sent to all processors. Retention schedules implemented with automated deletion. Breach notification procedure documented, tested, and assigned to owners. Data subject rights fulfilment process operational.

What You Receive

Every GDPR programme produces a complete, regulator-ready evidence package — not a policy library that sits on a SharePoint nobody reads.

🗺

Article 30 Processing Register

Complete Record of Processing Activities maintained and updated as your environment evolves — the first document any regulator will request.

📋

DPIA Reports

Structured impact assessments for all high-risk processing with risk mitigation recommendations and residual risk sign-off process.

📄

Privacy Notices & Policies

Accurate, plain-language GDPR-compliant privacy notices for all touchpoints — website, app, HR, B2B, marketing — and internal data handling policies.

🤝

DPA Agreement Library

Reviewed and updated data processing agreements with all vendors who process personal data on your behalf — using SCCs where required for international transfers.

🍪

Consent Management Implementation

CMP platform configured with accurate cookie scanning, consent audit trail, and preference centre — compliant with GDPR Article 7 and ePrivacy requirements.

Breach Response Playbook

72-hour breach notification procedure with decision trees, regulator contact details, communication templates, and quarterly simulation exercises.

📊

Compliance Dashboard

Ongoing monitoring of your GDPR posture — drift detection, regulatory change alerts, and evidence management for ongoing compliance maintenance.

🎓

Staff Awareness Training

Role-specific GDPR training for all staff — from general awareness to specialist training for HR, marketing, IT, and customer service teams.

Privacy Maturity Model

GDPR maturity is measured not just by documentation completeness, but by how deeply privacy principles are embedded in your operations, technology choices, and organisational culture. Click each level to explore.

Initial
Managed
Defined
Measured
Optimizing
Level 01InitialCMMI-1

Where you are

No formal data mapping. Privacy notices are outdated or generic copy-paste. No DPA agreements in place. Breach response is ad hoc. Consent managed via a basic cookie banner with no documentation or audit trail. Data subject rights handled manually and inconsistently.

No data mapGeneric noticesNo DPAsAd-hoc breach response
Level 02ManagedCMMI-2

Where you are

Basic data mapping completed, often as a one-time exercise for a compliance filing. Cookie consent implemented. Some DPA agreements in place for major vendors. Privacy officer appointed but without budget or decision-making authority. Breach procedure documented but untested.

Basic mappingCookie consentPartial DPAsUnderpowered DPO
Level 03DefinedCMMI-3

Where you are

Living data register maintained. DPIA process established and applied to new high-risk processing. All vendor DPAs reviewed and current. Privacy notices accurate across all touchpoints. Breach response tested annually. Privacy by design emerging as a consideration in product development decisions.

Living registerDPIA processAll DPAs currentAnnual breach simulation
Level 04MeasuredCMMI-4

Where you are

Privacy risk quantified and reported to board with financial exposure estimates. Consent management platform operational with full audit trail. Privacy impact assessments embedded in the product development lifecycle. Vendor risk assessments include privacy scoring. Data subject rights fulfilment automated or semi-automated.

Board risk reportingPIA in SDLCConsent audit trailAutomated DSR
Level 05OptimizingCMMI-5

Where you are

Privacy is a competitive advantage — actively communicated to customers and used in sales. Automated data subject rights fulfilment with real-time data lineage tracking. Privacy engineering embedded in all product teams as a standard competency. Regulatory change monitored proactively with automatic policy update triggers.

Privacy as advantageReal-time lineageAutomated complianceProactive regulatory monitoring

ACE MATES assessment → Not sure where you sit? Our free 90-minute briefing includes a privacy maturity assessment and maps the highest-ROI actions to move you to the next level — at no obligation.

How We've Helped

◉ Case Study — Anonymised · Nordic Market
Nordic E-Commerce Platform — 3.2M active customers across 4 countries

Following an IMY inquiry triggered by a data subject complaint about targeted advertising, the client needed to demonstrate GDPR compliance within 60 days or face a formal investigation and potential enforcement action.

ACE MATES conducted a full GDPR gap assessment in 2 weeks, uncovering 47 processing activities with no documented lawful basis, 12 vendor relationships with no DPA agreement, and a consent mechanism that failed Article 7 requirements — capturing consent but not storing it in a way that could be evidenced. We remediated all critical gaps within 45 days: rewrote privacy notices across 4 languages, implemented a consent management platform with audit trail, updated all vendor DPAs, and provided representation in regulator correspondence. The IMY inquiry was closed without enforcement action.

0Processing Activities Remediated
0Days to Full Compliance
Regulatory Fines Received

Transparent Pricing

We publish indicative pricing because you deserve to understand the investment before any conversation. Final pricing depends on organisation size, number of processing activities, and geographic scope.

GDPR Assessment
€6,000 – €12,000
One-time · 4–6 weeks
  • Full data flow mapping
  • Gap assessment report (all GDPR requirements)
  • DPIA for top 3 high-risk activities
  • DPA review — up to 10 vendors
  • Prioritised remediation roadmap
  • Executive summary for board
GDPR Retainer
€2,500 / month
Ongoing · 12-month minimum
  • Continuous compliance monitoring
  • Regulatory change alerts (all 5 Nordic DPAs)
  • Quarterly review meetings
  • Unlimited DPA reviews
  • DSR fulfilment support
  • Breach response on-call
  • Annual full reassessment included
  • Priority regulator inquiry response
All prices excl. VAT. DPIA-only engagements from €3,000. Outsourced DPO service available from €1,200/month. Cross-border transfer mechanism review (SCCs, BCRs) quoted separately. Retainer clients receive priority response for regulator enquiries within 4 business hours.

Why ACE MATES

Nordic Regulatory Intelligence

We track IMY, Datatilsynet NO/DK, and TSV enforcement decisions in real time. Our advice is calibrated to how Nordic regulators actually interpret GDPR — including local derogations, sector-specific guidance, and enforcement priorities that differ significantly between countries.

CIPP/E & CIPM Certified

All GDPR engagements led by IAPP-certified privacy professionals combining legal and technical expertise. We bridge the gap between your legal team and your engineering team — producing advice that is both legally sound and technically implementable.

We Implement, Not Just Advise

Most privacy consultancies hand you a gap report and leave. We stay through remediation — configuring the consent management platform, updating the DPAs, rewriting the notices, and verifying the fixes work. You end the engagement compliant, not just aware of gaps.

Regulator-Tested Documentation

Our templates and processes have been used in regulator investigations by Nordic DPAs and have survived scrutiny. We know what IMY and Datatilsynet look for because we have been in those conversations, and we build documentation that reflects that.

Frequently Asked Questions

How long does a GDPR compliance programme take?
Assessment phase: 4–6 weeks. Full programme including remediation: 12–16 weeks for a mid-size organisation. Timeline depends on volume of processing activities, number of vendors, and how many gaps need remediation. For compliance deadlines — regulator timelines, audit requirements, customer demands — we can expedite critical elements and provide interim evidence of progress.
Do we need a Data Protection Officer?
Under GDPR Article 37, a DPO is mandatory for public authorities, organisations conducting large-scale systematic monitoring of individuals, or those processing special category data at scale. We assess whether you meet these thresholds and provide outsourced DPO services if required — a certified DPO available to your organisation at a fraction of the cost of a full-time hire.
What is a DPIA and when is it required?
A Data Protection Impact Assessment is required under Article 35 when processing is "likely to result in a high risk." This includes profiling with legal effects, large-scale processing of special category data, systematic monitoring of public areas, and processing using new technologies. Each Nordic DPA publishes a list of processing types that always require a DPIA — we assess your activities against all five authority lists.
How do we handle data transfers outside the EU/EEA?
GDPR Chapter V restricts transfers of personal data to third countries without adequate protection. Following the Schrems II decision, US transfers require Standard Contractual Clauses plus a Transfer Impact Assessment. We assess all your international data flows, implement the appropriate transfer mechanism (SCCs, adequacy decision, BCRs), and document the TIA where required.
What happens if we receive a regulator inquiry?
Regulator correspondence demands careful, measured responses. Retainer clients receive immediate support — we draft responses, prepare documentation packages, and if needed attend regulator meetings alongside your legal counsel. The most important thing is not to respond hastily: regulators record everything, and an ill-considered response can escalate a routine inquiry into a formal investigation.
Does GDPR apply to our B2B data?
GDPR applies to personal data — information relating to an identified or identifiable natural person. B2B data often contains personal data: named contacts, email addresses, phone numbers. Business email addresses where the individual is identifiable are personal data. We help you identify which of your B2B data processing activities are in scope and ensure you have appropriate lawful basis for each.

Ready to Protect Your Customers' Data?

Free GDPR readiness check — know your risk before regulators do. No commitment required.

Request GDPR Assessment →✉ Email Us