Solution · Goal

GDPR compliance

Once personal information has leaked, Austria's Datenschutzbehörde (DSB) wants specifics: the kind of records involved, the number of people concerned, the start date and the steps already taken. Many businesses publish a privacy statement and keep a processing register their accountant produced from a template. Few could tell, inside three days, what actually lives in their inboxes, network folders and industry software. Apply is not a law practice and does not take on the DPO role; legal assessment stays with them. Our contribution is making sure the technology matches the policies on paper, with evidence to show for it.

72 hrs
window for notifying the DSB of a breach
1 month
usual limit for replying when someone exercises their rights
€110
hourly plus VAT when no support plan is in place
100%
handled over secure remote access

Where legal ends and technical begins

Decisions that require interpreting the regulation, like legal grounds, how long to keep things or what customers are told, are yours to make together with your data protection officer or solicitor. Settings inside notebooks, the Microsoft 365 tenant or servers are ours to inspect and put right.

Arrange a Teams meeting

Finding the data for real

We trace personal information through ERP and CRM, Outlook mailboxes, file shares, website forms, payroll in BMD or DPW and those spreadsheet exports that end up scattered across desktops. The results flow into your register of processing, and not infrequently show it to be wrong.

Who processes on your behalf

Your tax adviser, the newsletter platform, the shop's hosting company, an e-signature service, the payroll bureau and Apply itself all handle data for you. Next to each name we record which information it sees and from which country, giving your legal adviser a shortlist of contracts to scrutinise.

Technical risks for a DPIA

Realistic failure points: lab results stored on a notebook without encryption, CCTV cameras on default passwords, fleet location history open to every desk, an old contractor whose login was never removed. Should you and your DPO conclude that a formal impact assessment is due, this list is where it starts.

Safeguards switched on remotely

Two-step login everywhere, drive encryption pushed via Intune, individual administrator roles instead of one communal superuser, confidentiality labels and data loss rules in Microsoft 365, plus audit trails retained according to your own policy. Our methods mirror ISO 27001, although we hold no certificate and never pretend otherwise.

Breaches and individual rights

A written routine stating who tells whom, and with which facts, once something goes wrong, so a decision on notifying the authority is possible well within the three-day limit. Alongside it sits a technical procedure for tracing, exporting or wiping everything about one individual across your estate before their deadline runs out.

Sixty minutes of staff awareness

Delivered online, using scenarios from your own working week: a bogus bill that looks like it comes from a regular supplier, the kinds of text nobody should feed into ChatGPT and similar tools, why salary statements stay out of personal inboxes, and what to do immediately after hitting send on a message to the wrong person.

Our approach

Four stages instead of a months-long audit. We tackle what is pressing and costs little before anything else; switching off a departed colleague's still-active login tends to beat any new purchase.

01

Look, don't touch

We meet your internal data protection contact by video, then receive viewing rights for the cloud tenant, servers and endpoints. No setting changes during this phase.

02

A report without jargon

It shows where each category of data is kept, which third parties handle it and where gaps exist, with a priority and an hour estimate against every point. Passages can be copied as they are into the register or the impact assessment.

03

Quick, inexpensive wins first

Within the first days, MFA is enforced, abandoned accounts are closed and anonymous sharing links disappear. Encryption, classification and data loss rules come next on agreed dates, outside office hours if a short interruption is unavoidable.

04

Re-check whenever things change

Besides a yearly review, we revisit the inventory whenever software is added, a supplier starts processing data or a user with wide-ranging rights departs. Screenshots of the relevant settings are filed as proof.

Suppose a sales rep at a haulage company in Wels has his laptop stolen from the car. With BitLocker active and its key escrowed in Entra ID, the danger to the clients whose details were on board looks entirely different. Without it, you and your DPO have to consider informing the DSB and perhaps each affected client. One Intune configuration, rolled out in a few hours, is all that stands between those two situations.

Frequently asked questions

No. The role calls for professional knowledge of privacy law, and we are engineers. What we offer is close cooperation with whoever holds it, whether an internal DPO or an external law firm: a factual inventory, technical answers and implementation of whatever they decide. If the position is vacant, we say so plainly and recommend engaging a specialist for the legal work.

It turns on what your organisation does. The GDPR criteria decide, for example large-scale processing of health data or systematic monitoring of people; Austria does not add a fixed headcount threshold. Only a legal professional can settle it for your particular situation. Designated or not, the regulation binds you just the same, and we collaborate with whichever person owns the subject, from the managing director to an office manager or HR lead.

Yes. Remote administration inevitably exposes our engineers to personal data, so as a rule we act as your processor. We are happy to sign your wording or offer ours; either way it defines access boundaries, any sub-processors, security controls and the time within which you hear from us about an incident, so the clock does not run down while you wait.

Contact support@apply.at straight away, or helpme@apply.at if you have a contract with us. Technically we can try recalling the email inside Exchange Online, withdraw shared links, freeze the mailbox and reconstruct from audit records which person viewed which item. The controller, advised by the DPO, still decides on notifying the DSB and the individuals, but does so on the basis of hard facts.

By having the procedure ready before the request lands: the locations to check (ERP, CRM, mailboxes, online shop, mailing software, backups), the person responsible and the way the result is logged. Records the law says you must retain, invoices for instance under the seven-year rule of the Federal Fiscal Code (BAO), are locked rather than wiped; your adviser confirms the specifics. Apply documents the routine and rehearses it with a dummy case.

For a small business with low-risk processing, templates such as those from the Chamber of Commerce are a sensible starting point. They remain documents, though. None of them checks whether notebooks are encrypted, whether an ex-colleague can still read mail or whether backups actually restore. Testing exactly that and repairing the gaps is our share of the work, which is why the templates and our review fit together rather than compete.

Rarely at first. The Business Premium edition of Microsoft 365 currently bundles Intune, conditional access, labelling and data loss prevention, and a surprising number of subscribers have never activated them. We bill the assessment at €110 per hour plus VAT against a scope agreed in advance, or include it in your monthly support. Anything we do suggest buying will be tied to a concrete finding.

Let us check how GDPR looks inside your systems

Describe which data you handle, in which applications and who is responsible for it today. You will receive a review proposal plus the questions worth raising with your DPO beforehand.

Availability
Monday to Friday, 8:00-17:00 Austrian time (CET/CEST), reply within one working day
Meetings
By video on Microsoft Teams or Google Meet

We only use cookies that are technically required: to run the website and to remember the location you picked. There are no advertising or tracking cookies. Details are in the privacy notice.