Взгляд внутрь
Этот безопасный просмотр показывает, для чего нужен инструмент, не выполняя действий, требующих аккаунта.
Что умеет Офис защиты данных
Data protection is rarely hard because a single document is complicated. It is a slog because so many pieces interlock: the privacy policy references your processors, the processors need a data processing agreement, the DPA assumes technical and organisational measures, and your records of processing have to reflect all of it cleanly. The Privacy Office lays these eleven tools side by side so you stop jumping between eleven tabs and three templates.
It starts with the statements. The privacy policy generator builds your policy block by block: contact form, hosting, analytics, newsletter, social media. The cookie policy generator produces the matching cookie table with purpose, provider and lifetime, and the GDPR cookie banner delivers a consent banner with real opt-in that only loads once the visitor has actually agreed. Three tools, one coherent set of texts for your website.
As soon as external processors are involved, you need contracts. The DPA generator creates a data processing agreement under Art. 28 GDPR that you present to your processors or have them countersign. Alongside it, the TOMs generator documents your technical and organisational measures - access control, encryption, permissions and backups - in a structure a supervisory authority recognises immediately.
The heart of any GDPR documentation is the records of processing activities under Art. 30. The Art. 30 helper walks you through it processing by processing: purpose, legal basis, categories of data subjects, recipients, deletion deadlines. The purpose library hands you ready-worded purposes and matching legal bases that you add to the register with one click, and the workspace keeps every processor with its DPA status in one place, so you can see at a glance where a contract is still missing.
Where risk is involved, the data protection impact assessment comes into play. The DPIA quick check asks you a few short questions about whether your processing is likely to carry a high risk and therefore requires a full assessment under Art. 35. Not a legal opinion, but an honest traffic light that tells you whether you need to look more closely.
At the end comes deletion, and that is exactly what gets forgotten most often. The deletion concept generator sets out when which data is deleted, with the statutory retention periods per data type. The retention planner keeps the concrete deletion dates in view and adds them to the Fristenwächter, from eight years for invoices to the prompt deletion of a rejected job application. Together they make sure data does not linger forever just because nobody thought about it.
Honest about the technology: some tools run on our server, for example the text blocks of the privacy policy. Your Art. 30 register and your retention dates are stored in your account so they are not lost when you sign out. The individual tools stay reachable on their own; the office is just the shared workbench on top. So you can always open a single tool without needing the whole suite.
And the honest note up front: the Privacy Office does not replace legal advice. It takes the dull grind off your plate and gives you seriously good groundwork, but for tricky cases, international data transfers or special categories of personal data, get a look from a lawyer or your data protection officer. We are on your side, not your liability shield.
Функции
Eleven GDPR tools, one workbench
From privacy policy to deletion concept, all in one place, sorted into statements, contracts, registers and assessment.
Privacy policy block by block
Contact form, hosting, analytics, newsletter, social media - only the blocks you actually use.
Cookie policy plus opt-in banner
Matching cookie table and a consent banner that only loads once the visitor has really agreed.
DPA and TOMs that fit together
Data processing agreement under Art. 28 and the technical-organisational measures in an authority-proof structure.
Art. 30 records with a purpose library
Capture processing activities in a clean structure and reuse ready-worded purposes with their legal basis.
Processors with DPA status
Every processor in one place, showing at a glance where a contract is still missing.
DPIA check and retention under control
An honest traffic light for the impact assessment plus a deletion concept with statutory retention periods and concrete deletion dates per data type.
Saved in your account, not just the browser
Your register and retention dates stay in your account, also after signing out and on a second device.
Как это работает
- 1
Start with the statements
Build the privacy policy, cookie policy and banner first. That is what visitors see before anything else.
- 2
Generate contracts and TOMs
Create the DPA for your processors and document your technical-organisational measures.
- 3
Maintain the registers
Enter your Art. 30 processing activities, use the purpose library and list your processors.
- 4
Assess and settle deletion
Run the DPIA quick check and set the deletion concept and retention deadlines so data does not linger forever.
- 5
Get it reviewed
For tricky cases, have the result reviewed by a lawyer or your data protection officer.
Кому это нужно
Частые вопросы
Does the Privacy Office replace legal advice?
No. It takes the grunt work off your plate and gives you a very good starting point, but it is not legal advice. For special categories of data, international data transfers or unclear cases, a lawyer or your data protection officer should take a look.
Can the individual tools be used separately?
Yes. Each of the eleven tools stays reachable and registered on its own. The Privacy Office is just the shared workbench on top. So you can open only the DPA generator or only the retention planner if that is all you need.
Do I need records of processing activities?
In the vast majority of cases, yes. Art. 30 GDPR requires it in principle from every controller, with narrow exceptions for small organisations without risky or regular processing. The Art. 30 helper walks you through the required entries.
When do I need a data protection impact assessment?
When a processing activity is likely to carry a high risk to the rights of data subjects, for example large-scale profiling or special categories of data. The DPIA quick check gives you an honest first read on whether a full assessment under Art. 35 is required.
Are my entries stored anywhere?
We store the Art. 30 register and the retention dates in your account so nothing gets lost. Some generators send your entries to our server to build the text and do not store them there. Most drafts stay in your browser only.
Does the suite cover deleting data too?
Yes, and this is the part most often forgotten. The deletion concept generator sets the deletion rules with the statutory retention periods, and the retention planner keeps the concrete deletion dates per data type in view, from eight years for invoices to the prompt deletion of rejected applications.
Похожие инструменты
Генератор заявления о защите данных
Erstelle einen anpassbaren Entwurf für deine Website mit 10+ Vorlagen, 20+ Drittanbieter-Dien…
Генератор политики cookie
Erstelle eine Cookie-Richtlinie orientiert an TDDDG § 25, DSGVO Art. 6/7 und ePrivacy-Richtli…
Генератор AVV (договор об обработке данных)
Erstelle einen anpassbaren AVV-Entwurf mit Bausteinen zu Art. 28 DSGVO, 9 TOM-Kategorien, 8 V…
Генератор TOMs
Erstelle dein TOMs-Dokument nach DSGVO Art. 32. Fragebogen ausfüllen, PDF herunterladen, fertig.
Помощник по Art. 30 DSGVO
Erstelle dein Verarbeitungsverzeichnis nach DSGVO Art. 30. Alle Pflichtangaben, fertig zum Au…
Генератор концепции удаления данных
Erstelle einen prüfbaren Entwurf für Datenkategorien, Fristen und Löschmethoden. Vor dem Eins…
Начнём с Офис защиты данных?
Без установки. Входит в Pro. Открывай прямо в браузере.
Открыть сейчас