Case study №10 – GDPR compliance project in the metal processing sector

Client

One of our clients is a mid-sized private company, operating internationally within the metal elements and components manufacturing, with over 150 members of staff and average revenue of approximately $16 million.

Challenge

In relation to the newly adopted GDPR regulations in the EU, in effect as of 25 May 2018, the client had to implement all required procedures and policies for the purpose of being fully compliant with the new data protection rules and administrative processes and standards.

Approach

For the purpose of ensuring our client was fully compliant with the new GDPR regulations, we had to carry out in-depth analysis of the existing organisational structure and working processes within various departments. This was a necessary procedure, which was meant to identify any weaknesses, vulnerabilities and missing protocols within the personal data protection practices applied by the client as part of their routine operations and interactions with employees, clients, partners and other counterparts.
We had to familiarise ourselves with the organisational dynamic and pertinent processes, as well as provide adequate staff training and all necessary documentation, thus ensuring the smooth transition of the entity, as well as full compliance with new GDPR regulation regarding data management, internal controls and processes and general business interaction on an international level.

Results

By way of applying a detailed systematic approach, we managed to identify and correct any aspect, which could have acted as hurdles to achieving full compliance of the entity with the new GDPR regulation. During this process we managed to avoid disruptions and interruptions to the manufacturing and administrative processes of the entity.
We also prepared and delivered a customized training course for both staff and management, which introduction was meant to provide a straightforward and practical guide to the new data protection laws.

All documentation and procedures, which we developed for the client ensure full compliance with GDPR requirements and are a high-quality addition to the otherwise uninterrupted and successful business processes of the company.