Solution · By goal

GDPR compliance

Nearly every company owns a folder of policies and a privacy notice on its website. The awkwardness begins the day a large customer sends its security questionnaire across, or the day the DPO wants to know exactly which people can open the payroll directory and since when, and no one in the room can say. Apply does not practise law and is no substitute for your DPO, whose judgement settles the legal side. Our part is the technical one, making your systems behave the way your documents claim they do, and leaving behind the evidence that they do.

72 h
deadline for telling the CNIL about a breach
100 %
review and rollout carried out remotely
EUR 95
hourly rate excl. VAT when no plan is running
8:00-18:00
Mon-Fri CET, the hours our team works

What the engagement covers

Six strands that join the written documents to the live configuration. Your DPO keeps control of lawful bases, retention periods and the wording of documents; we supply verified technical facts and put the safeguards in place.

Arrange a call online

Where the personal data actually sits

We go looking for it: inside Sage or Cegid, the CRM, Outlook mailboxes, network shares, the forms on your website, the payroll platform and the spreadsheet exports left on somebody's desktop. That list becomes raw material for the processing register your DPO maintains.

A register of your processors

Every service that touches the data: the accountancy practice, the mailing tool, the shop's hosting provider, the e-signature platform, the payroll vendor, the maintenance firm. For each one we note what it handles and from where, so that your counsel can say which processing agreement needs requesting or a second reading.

Risk assessed from the technical side

What can genuinely go wrong: an unencrypted laptop forgotten on a train, an administrator password shared between six people, a backup never once brought back, a former supplier whose access still works two years after the contract ended. Where your DPO calls for an impact assessment, these findings go into it.

Safeguards rolled out remotely

Multi-factor sign-in everywhere, device encryption driven from Intune, named roles in Entra ID in place of a single shared administrator login, confidentiality labels plus leak prevention rules in Microsoft 365, sign-in history retained over the period your policy sets. We follow the principles of ISO 27001 without claiming any certification of our own.

Breaches and individual rights

A procedure setting out who warns whom, in what order and with what information, on the day a payroll file reaches the wrong recipient. Plus the technical route for locating, extracting or deleting the records of one individual across every tool you run, inside the period the regulation allows a controller.

An hour of awareness training

One session by video, built around situations from your own trade: recognising a forged invoice issued under the name of a supplier everybody trusts, knowing what never goes into a public AI assistant, and what to do in the ten minutes after a misdirected file rather than hoping nobody noticed.

How we go about it

Facts before purchases. A great many organisations buy costly tooling and only afterwards find that their widest hole is the account of a colleague who left last year, still enabled and still collecting mail.

01

Interview and remote review

A conversation with whoever owns the subject in your organisation, then a sweep of tenants, servers and workstations: rights granted, encryption status, backup jobs, accounts nobody signs into, folders shared with the entire internet.

02

A report written for the DPO

Where the data sits, who processes it and which shortfalls matter most, each carrying an estimate of the effort involved. The layout lets it move directly into the processing register and the risk work.

03

Putting the safeguards in

Corrections go in following the order we settled on, against dated milestones. It is all remote work, and anything that takes a service offline is scheduled beyond office hours.

04

Evidence and a yearly revisit

You keep the configuration screenshots, the restore test reports and the current state of permissions. The set is refreshed every year and whenever a new tool joins the estate.

Trouble rarely begins with an inspection; almost always it begins with an incident. A complaint from a customer, a mislaid handset, a message pushed out to two hundred addresses with every one of them visible. What matters from that moment is whether you can establish, in fewer than 72 hours, which records travelled, who received them and out of which mailbox. Tooling and audit trails answer that, and getting you ready to answer it is precisely our remit.

Questions and answers

The technical chapters, yes: how passwords are set, what gets encrypted, how backup jobs run, the way access is granted and taken back, and the steps to follow once something goes wrong. Anything carrying legal weight, from the grounds on which you process to the wording shown to individuals and the length of time records are held, stays with your DPO or your solicitor. Where you have neither, we tell you so without dressing it up and suggest bringing a practice in for that side.

Appointing one is mandatory only in specific cases, and ruling on yours is a legal matter rather than a technical one. Every other duty under the regulation stands whatever you decide. Without a DPO we deal with the colleague who has inherited the subject: often the owner, the person running the office or whoever looks after human resources. Nothing is changed unless they agree to it.

We do, since administering your estate from a distance means reaching systems that hold personal records. Either your template works for us or we bring one of our own. Whichever gets signed, it spells out how far our access reaches, which further suppliers we call upon, the measures we keep in force, and how quickly an incident on our side lands with you, because a slow warning from a supplier is what burns the first day of the deadline.

Send a note to support@apply.fr straight away, or to helpme@apply.fr if you are a contract customer. From the tooling side we will try a recall inside Microsoft 365, kill the sharing link, freeze the mailbox it came from and read the audit trail to establish which people opened the attachment and at what hour. Whether the CNIL and the individuals then get told is a call for the controller alongside the DPO, taken on the strength of what those findings show.

How long a review runs hangs on headcount and on the number of applications in play; boundaries are agreed before anyone starts. Time is charged at EUR 95/hour excl. VAT, or it sits inside a Start, Business or Premium agreement. As for the safeguards, much turns on what you already pay for: a fair number of the controls come with Microsoft 365 subscriptions you hold anyway, so our first move is always to look for things that merely need turning on.

Let us see what GDPR looks like inside your systems

Tell us what data you handle, which applications hold it and who follows the subject today. We answer with a proposed review and the questions worth putting to your DPO beforehand.

When we are around
Weekdays, 8:00 to 18:00 CET; answers land inside one working day
Talking it through
A call on Teams or Google Meet, whenever writing is not enough

We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.