A hospital, a call centre and a retail chain all process personal data, but the work concentrates in completely different places. Find where yours sits, and which part of the platform is worth setting up first.
The same platform, entered from a different door depending on what your organisation does all day. These are starting points rather than fixed packages.
Identification files on every customer, credit and claims histories that stay on the books for years, and a long tail of outsourced services touching them. The register grows faster than anyone expects, and third parties are where it gets complicated.
Health data sits in almost every record you keep, so the careful handling that other sectors reserve for exceptions is your normal case. Assessments and retention discipline carry more weight here than anywhere else.
Most of your work is done on behalf of clients, which puts you on the processor side of the relationship. Your clients will ask for the agreement, the clause list and your own sub-processors, usually at short notice and usually during a tender.
Loyalty schemes, abandoned carts, marketing lists and payment flows, plus whatever your website is quietly loading. This is the sector where the gap between what the privacy notice says and what the site actually does is widest.
Guest records, identity documents at check-in, booking platforms and seasonal staff who come and go. Data arrives through channels you do not control and is handled by people who change every summer.
Subscriber records, traffic and location data, and a volume of access requests that no shared inbox survives for long. Scale is the defining problem: everything you do, you do a hundred thousand times.
Student files that follow a person for years, parents and guardians attached to them, and a growing pile of online learning tools nobody formally approved. Minors raise the stakes on every one of those decisions.
Resident and customer data collected because a public task requires it, held across systems that predate anyone currently working there. The register is the hard part, and it is also the first thing anyone will ask to see.
The modules are the same whichever sector you are in, and so is the legal basis underneath them: Law 124/2024, aligned with the GDPR. What changes is the order you set them up and where the volume lands.
Business units, data categories and processing purposes are yours to define, so the register reflects how your organisation is actually structured rather than a generic template.
Alongside the rules that ship with the platform, your team can author its own, so a check that only matters in your industry becomes part of the same score as everything else.
If there is no privacy team to run this internally, the DPO service covers the role itself, with the platform underneath it rather than a folder of documents.
Tell us what your organisation does and we will walk through where the work is likely to concentrate, and what a first month of setup would look like.