Service · IT security

GDPR and data protection

The GDPR asks for “appropriate technical and organisational measures” and leaves each business to work out what that means in practice. In many Austrian SMEs the question eventually lands on the IT desk, usually without warning: a former customer asks for a copy of everything held about him, the Austrian Data Protection Authority (DSB) follows up on a complaint, or a medical practice in Linz emails a lab report to the wrong patient. That is the moment when it becomes obvious whether anyone actually knows where personal data sits and who can open it. We handle the technical half of data protection. We locate the data, tidy up the permissions, switch on logging and get your team ready for an incident. Legal assessment, contract wording and the privacy notice stay with your lawyer or data protection officer. What we deliver is a solid, verifiable base for their work, and all of it is done remotely.

72 hours
to report a personal data breach to the DSB
One month
standard deadline for answering an access request
Named accounts
instead of shared logins such as “reception”
Remote
with no interruption to daily business

Everything this covers

A newsletter list needs a different level of protection from health data under Article 9 GDPR. We size the work to the type and volume of data and do not build defences your actual risk cannot justify.

Settle the details with an engineer

Data map

We walk through the places where personal data really lives: payroll in BMD or DPW, the CRM, the ERP, SharePoint and OneDrive, network drives, mailboxes and the notorious Excel exports saved on laptops. The result feeds straight into your record of processing activities, which often still lists systems that were switched off years ago.

Role-based permissions

Front desk staff have no need to see salaries, and sales has no business in sick-leave records. Access is granted through groups in Entra ID or Google Workspace rather than person by person, so every change of role stays traceable.

No more shared logins

Accounts like “office” or “admin”, with the password on a sticky note by the screen, are replaced by personal accounts with multi-factor sign-in. Every look at a record can then be tied to one individual.

Audit logging

We activate the Microsoft 365 audit log and file access auditing on the file server, with retention long enough to show weeks later who opened a particular file.

Data subject rights

For access, erasure and portability requests we prepare the technical groundwork: saved content searches in Microsoft Purview, export routes from the CRM and a checklist of every system that must be searched.

Joiners and leavers

A process agreed with HR ensures access ends on the last working day, including cloud services that are not linked to the directory, such as the recruitment portal or time tracking.

Breach response sheet

One page for the first hours: who assesses the incident, how the data protection officer is informed, which logs are preserved and what the person drafting the DSB notification will need.

Our working method

We start where a small effort removes a large share of the risk. Bigger projects come once the basics are in place.

01

Initial review

A video meeting with whoever is responsible for data protection, plus a remote look at your environment. You receive a list of systems holding personal data and how each is protected today.

02

Quick wins

Accounts of former staff, shared logins and sign-ins without a second factor disappear within the first few days. It costs little and the effect is immediate.

03

Technical measures

Laptop encryption, logging, a permission structure and limits on external sharing, rolled out group by group so nobody suddenly finds a folder locked.

04

Written record

You get a description of every technical measure in place, phrased so it can go straight into the record of processing and any documents requested during a DSB inquiry.

What matters is not whether antivirus is installed, but whether you can show what you did. After a complaint or a breach, evidence counts: who had access, since when, which log proves it and when it was last checked. A correct setting without proof carries little more weight than no setting at all, which is why every measure we apply is recorded with a date.

Frequently asked questions

With the system list from the data map: ERP, CRM, mailboxes, network drives and backups. In Microsoft 365 a content search finds emails and documents with his name or customer number within minutes; in the ERP you need an export of the master record. You normally have one month. Your lawyer or data protection officer should read the reply before it goes out.

Write to support@apply.at straight away, or to helpme@apply.at if you have a contract with us. We try to recall the message, preserve the logs and work out the scope. With that information your data protection officer or lawyer decides whether the DSB must be notified. The 72 hours start from the moment you become aware of the breach.

Legally, processors require a data processing agreement (AVV); whether a particular adviser counts as a processor is for your lawyer to judge. On the technical side we check what access outside parties really have, whether it is personal and protected by a second factor, and whether it is still needed. We frequently find logins belonging to suppliers whose contracts ended years ago.

Storing it elsewhere within the EU is not a transfer to a third country. Microsoft, Google and AWS let you choose EU regions, depending on the service and plan, although with providers based outside the EU it is worth checking sub-processors and support access. European providers such as Exoscale in Vienna, Anexia, Hetzner or IONOS make it even simpler. We verify where mailboxes, backups and applications are actually stored and document it for your record of processing.

That depends on whether a processing activity is likely to pose a high risk to the people concerned, for example large-scale handling of health data or systematic monitoring. The DSB publishes lists that help. The decision itself is a legal one; for the assessment we supply the technical description of systems, data flows and safeguards.

Get your personal data in order

Tell us briefly which systems hold customer and staff data. We will reply with a first view of the weak spots we most often see in comparable businesses.

Availability
Monday to Friday, 8:00-17:00 Austrian time (CET/CEST), reply within one working day
Meetings
By video on Microsoft Teams or Google Meet

We only use cookies that are technically required: to run the website and to remember the location you picked. There are no advertising or tracking cookies. Details are in the privacy notice.