Parendum Compliance

General Data Protection Regulation (EU) 2016/679

GDPR compliance you can show, not just claim.

A 10-minute assessment of your records, legal bases, notices, rights handling, processors, transfers, security and breach readiness. Every gap cites the article. Subscribers get the documents pre-filled for their company and track progress as they fix things.

Start the free GDPR assessmentFree score, no sign-up. Documents and tracking €39/month.

Why now

Customers ask for evidence

Procurement teams ask for your record of processing, DPA, breach procedure and security measures. Having them ready shortens sales cycles.

Regulators look at documentation

Most GDPR enforcement against small and mid-size companies starts with a complaint, and the first question is always: show us your records, notices and legal basis.

Generic templates don't fit

A privacy notice that lists purposes you don't have, or misses the ones you do, is itself a transparency failure. Ours are generated from your answers.

What subscribers get

Editable Word documents generated from your answers, regenerated whenever you reassess.

00

Gap assessment report

Score per area, every gap with its article, the fix and a roadmap.

01

Privacy notice

Arts. 13-14: purposes and legal bases per activity, recipients, transfers, retention, rights, authority.

02

Record of processing activities

Art. 30, pre-filled from your answers, with a processor section if you process for clients.

03

Data subject request procedure

Access, erasure, objection and portability, with reply templates and a request log.

04

Breach procedure

72-hour notification (Art. 33), communication to individuals (Art. 34), notification form and breach register.

05

Data processing agreement

The Art. 28(3) clauses for processors that don't offer their own.

06

DPIA

Art. 35 impact assessment, pre-filled for the high-risk processing we detect.

07

Legitimate interests assessment

Purpose, necessity and balancing test for each activity relying on Art. 6(1)(f).

08

Retention schedule

Storage limitation (Art. 5(1)(e)) by record type, with a deletion log.

09

Transfer register and TIA

Chapter V: every transfer outside the EEA, its mechanism, and a transfer impact assessment.

Questions

+Does GDPR apply to a small company?

Yes. GDPR applies to any organisation established in the EU that processes personal data, and to organisations elsewhere that offer goods or services to people in the EU or monitor their behaviour. Some obligations, like the record of processing, have limited exemptions for organisations under 250 employees; the assessment checks whether they apply to you.

+Is this legal advice?

No. It is a structured self-assessment with templates generated from your answers. For high-risk processing, have the documents reviewed by a lawyer.

+Estonia specifics?

Yes: the Estonian Personal Data Protection Act (age of digital consent 13), the Data Protection Inspectorate (AKI) and its breach notification channel, and the Electronic Communications Act rules on direct marketing.

+We are outside the EU.

If you offer goods or services to people in the EU or monitor them, GDPR applies and you may need an EU representative (Art. 27). The assessment covers this.