PRACTICE
Privacy & GDPR
Privacy programmes that work in practice. For boards that need to demonstrate the norm is followed, not just that it exists.
From register to evidence
The General Data Protection Regulation demands demonstrability, not documents. Processing records, DPIA templates, and processor agreements are the form; the question that matters is whether the organisation can prove it follows the norm in fact, at the moment a regulator, disciplinary panel, or data subject asks.
Where privacy is elaborated on paper but not followed in practice, the risk of actual measurement by a regulator arises. Rijker Advisory builds privacy programmes that pass that test.
Sport, healthcare, financial services, and the public sector each have their own accents. Work is aligned with sectoral frameworks without losing the core of the GDPR.
RGAM applied to privacy
- 01ReadDiagnosis of existing privacy organisation, processing records, DPIA portfolio, and daily practice.
- 02StructurePolicy, procedures, processor agreements, DPIA frameworks, retention schedules, authorisation structure.
- 03SystemTooling, DSR set-up, breach response, cross-border transfer mechanisms, ROPA maintenance.
- 04CultureAwareness, reporting willingness, data conduct, board-level example behaviour.
- 05IntegrityIndependent test of whether the privacy programme holds up under audit, incident, or regulatory inquiry.
What we deliver
- DPO-as-a-Service: formal and operational fulfilment of the Data Protection Officer role, on part-time or interim basis. Delivered by a registered DPO (NRFG, registration number 685).
- DPIA frameworks and delivery, including reassessments upon system changes and AI implementations.
- Processor agreements: drafting, review, negotiation, and management including sub-processor monitoring.
- Cross-border transfer mechanisms: SCCs, TIAs, supplementary measures, and post-Schrems II assessments.
- Breach response: investigation, notification obligations, data subject communication, liability, and remediation.
- Records of processing activities (ROPA): set-up, maintenance, and integration with broader risk and compliance frameworks.
- DSR set-up: request handling, identification, exemptions, and client communication.
- Privacy training and awareness programmes tailored per audience.
Frameworks
Work is delivered within the frameworks of the GDPR, UAVG, EDPB guidance, sectoral codes (including GBAV for sport, NEN 7510 for healthcare, and DNB and AFM oversight for financial services), and HIPAA where cross-border healthcare work applies.