Skip to content

Services, Wiki-Artikel und Blog-Beiträge durchsuchen

↑↓NavigierenEnterÖffnenESCSchließen

GDPR Compliance

GDPR Compliance: Technical Measures per Art. 32

Art. 32 GDPR demands more than ticking boxes. We implement TOMs that genuinely protect - and test their effectiveness with penetration testing and gap analysis. From a single source, on a fixed-price basis.

ISO 27001 certified · Fixed-price commitment · GDPR expertise since 2018

Art. 32 GDPR - Four Pillars

Art. 32(1)(a)

Pseudonymisation & Encryption

Render personal data technically unreadable

Art. 32(1)(b)

Confidentiality & Integrity

Ongoing assurance through technical measures

Art. 32(1)(c)

Availability & Resilience

Backup strategy, business continuity, restorability

Art. 32(1)(d)

Regular Testing

Effectiveness testing of measures - penetration test

Trusted by our clients

500+
Security analyses
8+
Years of experience
24h
To fixed-price quote
100%
Permanent staff experts

Our Services

Technical GDPR compliance from a single source

We combine data protection expertise with offensive security know-how - unique in this form. Our services cover all technical requirements of the GDPR.

01

TOM Gap Analysis & Implementation

Systematic review of all existing technical and organisational measures against Art. 32 GDPR requirements. Implementation of missing controls: encryption, pseudonymisation, access management, backup, incident response.

Art. 32 GDPR

02

DPIA (Data Protection Impact Assessment)

Systematic assessment of high-risk processing operations per Art. 35 GDPR: description of processing, necessity and proportionality assessment, risk assessment, and concrete mitigating measures. Mandatory for video surveillance, profiling, and special category data.

Art. 35 GDPR

03

External Data Protection Officer

External DPO as a managed service per Art. 37 GDPR - immediately available, independently advising, and with contractual liability. Expert contact for supervisory authorities and data subjects. Available from EUR 800/month.

Art. 37-39 GDPR

04

Penetration Test for Art. 32(1)(d)

Regular penetration test as evidence of TOM effectiveness - directly satisfying Art. 32(1)(d) GDPR. We test whether personal data is genuinely protected against unauthorised access: web applications, databases, access controls, network segmentation.

Art. 32(1)(d) GDPR

Synergies

GDPR & ISO 27001 - integrated compliance

ISO 27001 and GDPR complement each other ideally. A certified ISMS per ISO 27001 covers large parts of the GDPR's technical and organisational requirements - and provides documented evidence for supervisory authorities.

Art. 32 - TOMs

ISO 27001 Annex A (93 controls)

Art. 32(1)(a) - Encryption

ISO 27001 A.8.24

Art. 33 - 72h breach notification

ISO 27001 A.6.8 (Incident Reporting)

Art. 17 - Right to erasure

ISO 27001 A.8.10 (Data deletion)

Art. 5(1)(f) - Integrity & confidentiality

ISO 27001 core objective

Our integrated approach

01

TOM gap analysis

Current-state assessment of all technical measures against Art. 32 GDPR and ISO 27001 controls simultaneously.

02

ISMS build-out

Build or extend the ISMS per ISO 27001 - as the documented foundation for GDPR TOMs.

03

DPIA for high-risk operations

Systematic assessment of all processing operations requiring a DPIA per Art. 35 GDPR.

04

Penetration test

Annual test of TOM effectiveness per Art. 32(1)(d) - the most important evidence for data protection authorities.

05

External DPO

On request: take on all DPO functions per Art. 37-39 GDPR as a managed service.

Why AWARE7 for GDPR compliance

What sets us apart from other providers

Pure awareness platforms don't test systems. Pure consulting firms are too far removed. AWARE7 combines both: we hack your infrastructure and train your employees: tailored to mid-sized companies, personal, without enterprise overhead.

Research and teaching as our foundation

Around 20% of our revenue comes from research projects for the BSI and the BMBF. Our studies, published at ACM and Springer conferences, analyse millions of websites and tens of thousands of phishing emails. Three of our executives are professors at German universities at the same time.

20 %

Digital sovereignty: no compromises

From first contact to final report, your data is stored on our own servers in Germany - no US cloud providers, no third-country transfers. Our AI also runs on our own hardware in Germany - with locally operated open-source models. Client and project data never reach external AI services. All staff are permanently employed, covered by social insurance and bound by uniform legal obligations.

More on digital sovereignty
100 %

Fixed price within 24h: predictable project timelines

Within 24 hours you receive a binding fixed-price quote without hourly rate risk. A well-practised team and standardised processes ensure a clear schedule with a defined start and end date.

24 h

Your dedicated contact

A personal project manager accompanies you from the first meeting to the retest. You book appointments directly with your contact person and keep the same contact throughout the project.

1:1

Peer-reviewed publications

First page of the paper: Different Seas, Different Phishes - Large-Scale Analysis of Phishing Simulations

Different Seas, Different Phishes - Large-Scale Analysis of Phishing Simulations

ACM AsiaCCS 2025

Oskar Braun, Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann

First page of the paper: A Platform for Physiological and Behavioral Security

A Platform for Physiological and Behavioral Security

NSPW 2025

Jan Hörnemann

First page of the paper: Privacy from 5 PM to 6 AM: Tracking and Transparency in the HbbTV Ecosystem

Privacy from 5 PM to 6 AM: Tracking and Transparency in the HbbTV Ecosystem

IEEE/IFIP DSN 2025

Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann

First page of the paper: Understanding Regional Filter Lists: Efficacy and Impact

Understanding Regional Filter Lists: Efficacy and Impact

PoPETS 2025

Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann

Who is AWARE7 the right partner for?

Mid-sized companies with 50-2,000 employees
Companies that need real security, without paying for a DAX-corporation provider. Fixed price, clear scope, one point of contact.
IT managers & CISOs
Who have to argue convincingly in-house and need a report in boardroom language for that, not just technical findings.
Regulated industries
Critical infrastructure, healthcare, financial services: NIS-2, ISO 27001, DORA. We know the requirements and deliver evidence that auditors accept.

Your GDPR experts

Our certified consultants combine data protection expertise with offensive security knowledge - unique in this form.

Frequently Asked

Frequently asked questions about GDPR consulting

Answers to the most common questions about our GDPR consulting offering, costs, and our approach.

Costs depend on your starting level and the desired scope of services. An initial TOM gap analysis starts from EUR 3,500 as a fixed price. A complete GDPR compliance engagement including TOM implementation, DPIA, and data protection concept typically falls between EUR 8,000 and EUR 25,000 for mid-sized organisations. We provide a binding fixed-price quote within 24 hours - no hidden consultant days.
An external Data Protection Officer (DPO) is mandatory under Art. 37 GDPR if your organisation: (1) is a public body, (2) carries out large-scale processing of special categories of data (health, biometrics, political opinions) as a core activity, or (3) carries out large-scale regular and systematic monitoring of individuals. Even without a legal obligation, we recommend a DPO - as liability protection for management and as evidence for supervisory authorities and customers.
Art. 32(1)(d) GDPR explicitly requires "a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures". A penetration test is the most effective method of satisfying this requirement. It specifically tests: can unauthorised parties access personal data? Are encryption measures effective? Are there vulnerabilities in web applications holding customer data? Are access controls correctly configured?
ISO 27001 and GDPR complement each other ideally: a certified ISMS per ISO 27001 provides evidence for Art. 32 GDPR (technical and organisational measures) and Art. 5(1)(f) (integrity and confidentiality). Specifically: ISO 27001 control A.8.24 (cryptography) corresponds to the GDPR encryption requirement; A.6.8 (incident reporting) corresponds to Art. 33 (72-hour notification); A.8.10 (data deletion) corresponds to Art. 17 (right to erasure). AWARE7 builds GDPR compliance and ISO 27001 as an integrated programme.
A Data Protection Impact Assessment (DPIA) per Art. 35 GDPR is mandatory for processing operations "likely to result in a high risk to the rights and freedoms of natural persons". Typical cases: video surveillance, profiling, processing of special categories of data, systematic monitoring of employees. The DPIA covers: description of the processing, assessment of necessity and proportionality, risk assessment, and concrete mitigating measures.
AWARE7 brings the unique combination of data protection expertise and offensive security know-how: we do not only check whether your TOMs are documented - we test whether they work. Our approach: TOM gap analysis (current-state assessment of all technical measures), penetration test for effectiveness testing per Art. 32(1)(d), DPIA for high-risk processing, external DPO as a managed service, and ongoing support with data breaches (72-hour notification to the supervisory authority). All from a single source, on a fixed-price basis.

GDPR compliance - done properly.

We implement TOMs that genuinely protect and provide a fixed-price quote within 24 hours. No open consultant days, no surprises.

Free · 30 minutes · No obligation

Rufen Sie uns an

Mo-Fr, 8:00-17:00 Uhr - persönlich und unverbindlich.

0209 8830 6764
Jetzt anrufen