Once personal information has leaked, Austria's Datenschutzbehörde (DSB) wants specifics: the kind of records involved, the number of people concerned, the start date and the steps already taken. Many businesses publish a privacy statement and keep a processing register their accountant produced from a template. Few could tell, inside three days, what actually lives in their inboxes, network folders and industry software. Apply is not a law practice and does not take on the DPO role; legal assessment stays with them. Our contribution is making sure the technology matches the policies on paper, with evidence to show for it.
usual limit for replying when someone exercises their rights
€110
hourly plus VAT when no support plan is in place
100%
handled over secure remote access
Where legal ends and technical begins
Decisions that require interpreting the regulation, like legal grounds, how long to keep things or what customers are told, are yours to make together with your data protection officer or solicitor. Settings inside notebooks, the Microsoft 365 tenant or servers are ours to inspect and put right.
We trace personal information through ERP and CRM, Outlook mailboxes, file shares, website forms, payroll in BMD or DPW and those spreadsheet exports that end up scattered across desktops. The results flow into your register of processing, and not infrequently show it to be wrong.
Who processes on your behalf
Your tax adviser, the newsletter platform, the shop's hosting company, an e-signature service, the payroll bureau and Apply itself all handle data for you. Next to each name we record which information it sees and from which country, giving your legal adviser a shortlist of contracts to scrutinise.
Technical risks for a DPIA
Realistic failure points: lab results stored on a notebook without encryption, CCTV cameras on default passwords, fleet location history open to every desk, an old contractor whose login was never removed. Should you and your DPO conclude that a formal impact assessment is due, this list is where it starts.
Safeguards switched on remotely
Two-step login everywhere, drive encryption pushed via Intune, individual administrator roles instead of one communal superuser, confidentiality labels and data loss rules in Microsoft 365, plus audit trails retained according to your own policy. Our methods mirror ISO 27001, although we hold no certificate and never pretend otherwise.
Breaches and individual rights
A written routine stating who tells whom, and with which facts, once something goes wrong, so a decision on notifying the authority is possible well within the three-day limit. Alongside it sits a technical procedure for tracing, exporting or wiping everything about one individual across your estate before their deadline runs out.
Sixty minutes of staff awareness
Delivered online, using scenarios from your own working week: a bogus bill that looks like it comes from a regular supplier, the kinds of text nobody should feed into ChatGPT and similar tools, why salary statements stay out of personal inboxes, and what to do immediately after hitting send on a message to the wrong person.
Our approach
Four stages instead of a months-long audit. We tackle what is pressing and costs little before anything else; switching off a departed colleague's still-active login tends to beat any new purchase.
01
Look, don't touch
We meet your internal data protection contact by video, then receive viewing rights for the cloud tenant, servers and endpoints. No setting changes during this phase.
02
A report without jargon
It shows where each category of data is kept, which third parties handle it and where gaps exist, with a priority and an hour estimate against every point. Passages can be copied as they are into the register or the impact assessment.
03
Quick, inexpensive wins first
Within the first days, MFA is enforced, abandoned accounts are closed and anonymous sharing links disappear. Encryption, classification and data loss rules come next on agreed dates, outside office hours if a short interruption is unavoidable.
04
Re-check whenever things change
Besides a yearly review, we revisit the inventory whenever software is added, a supplier starts processing data or a user with wide-ranging rights departs. Screenshots of the relevant settings are filed as proof.
Suppose a sales rep at a haulage company in Wels has his laptop stolen from the car. With BitLocker active and its key escrowed in Entra ID, the danger to the clients whose details were on board looks entirely different. Without it, you and your DPO have to consider informing the DSB and perhaps each affected client. One Intune configuration, rolled out in a few hours, is all that stands between those two situations.
Frequently asked questions
No. The role calls for professional knowledge of privacy law, and we are engineers. What we offer is close cooperation with whoever holds it, whether an internal DPO or an external law firm: a factual inventory, technical answers and implementation of whatever they decide. If the position is vacant, we say so plainly and recommend engaging a specialist for the legal work.
It turns on what your organisation does. The GDPR criteria decide, for example large-scale processing of health data or systematic monitoring of people; Austria does not add a fixed headcount threshold. Only a legal professional can settle it for your particular situation. Designated or not, the regulation binds you just the same, and we collaborate with whichever person owns the subject, from the managing director to an office manager or HR lead.
Yes. Remote administration inevitably exposes our engineers to personal data, so as a rule we act as your processor. We are happy to sign your wording or offer ours; either way it defines access boundaries, any sub-processors, security controls and the time within which you hear from us about an incident, so the clock does not run down while you wait.
Contact support@apply.at straight away, or helpme@apply.at if you have a contract with us. Technically we can try recalling the email inside Exchange Online, withdraw shared links, freeze the mailbox and reconstruct from audit records which person viewed which item. The controller, advised by the DPO, still decides on notifying the DSB and the individuals, but does so on the basis of hard facts.
By having the procedure ready before the request lands: the locations to check (ERP, CRM, mailboxes, online shop, mailing software, backups), the person responsible and the way the result is logged. Records the law says you must retain, invoices for instance under the seven-year rule of the Federal Fiscal Code (BAO), are locked rather than wiped; your adviser confirms the specifics. Apply documents the routine and rehearses it with a dummy case.
For a small business with low-risk processing, templates such as those from the Chamber of Commerce are a sensible starting point. They remain documents, though. None of them checks whether notebooks are encrypted, whether an ex-colleague can still read mail or whether backups actually restore. Testing exactly that and repairing the gaps is our share of the work, which is why the templates and our review fit together rather than compete.
Rarely at first. The Business Premium edition of Microsoft 365 currently bundles Intune, conditional access, labelling and data loss prevention, and a surprising number of subscribers have never activated them. We bill the assessment at €110 per hour plus VAT against a scope agreed in advance, or include it in your monthly support. Anything we do suggest buying will be tied to a concrete finding.
Describe which data you handle, in which applications and who is responsible for it today. You will receive a review proposal plus the questions worth raising with your DPO beforehand.
Availability Monday to Friday, 8:00-17:00 Austrian time (CET/CEST), reply within one working day
Meetings By video on Microsoft Teams or Google Meet
Your enquiry has arrived
Our reply reaches you within one working day. Outages that leave your staff unable to work are dealt with first.
Open points get clarified. If anything is unclear, we come back with questions by mail or propose a quick Teams or Meet session.
A written offer follows. Scope, cost in euros plus VAT and an achievable start date are all spelled out plainly.
You decide at your own pace. Read the offer, ask about whatever is unclear, and only then give us your answer.
Pick your location
We could not find that town. Try another spelling, or choose whichever provincial capital lies closest; as everything is handled remotely, you get the same service in all nine Austrian states.
We only use cookies that are technically required: to run the website and to remember the location you picked. There are no advertising or tracking cookies. Details are in the privacy notice.