What it is
A guided half-day working session in which we sort all of the organization's material into two bins: documents with personal data, and knowledge without it. Plus the three measures that remove the biggest risk that same week.
In brief
Assess & scan
A fixed price, known up front. All prices are on one page, with what is and isn't included.
What it does
After the session you have a sorting map of your own material: what can't go into an AI service for now, and where the safe gains are. The three no-cost measures are set up right away: organization accounts instead of personal ones, two-factor authentication, and a one-page agreement on what may never go into an AI service, who signs off, and where to report a mistake.
How it helps
Most organizations ask the wrong first question: which tool is safe? The useful question is which documents can be processed with AI at all. Skip the sorting and you have to apply the strictest rules to everything — and then, in practice, nothing is allowed. Sort it, and you can safely start tomorrow with the part that has no names in it. Half a day of work, and the whole further approach is settled.
The steps
01
Beforehand: a short questionnaire about what material exists and where it's stored.
02
The session (a half day, on-site or online): we go through the material together, one question per type — does it contain a name or an identifiable person? Doubt means bin one.
03
Right after: setting up the three measures, together with whoever manages the accounts.
04
Within a week: the sorting map and the agreements sheet, ready to use.
What isn't included
A legal judgment on the lawful basis for processing; that remains work for the data protection officer or lawyer. The map does make that conversation concrete, though.