BLOG - answers to common questions and problems
1. Does my company need to have a Data Protection Officer (DPO)?

This question troubles most small and medium-sized businesses – and the answer is not always a clear-cut “yes” or “no”. Try answering these five questions:
1. Is the processing of personal data your main activity (e.g. you run an online store, provide healthcare services, conduct market research)?
2. Do you systematically and on a large scale monitor individuals (e.g. a camera system covering public areas, tracking website visitor behaviour, geolocation applications)?
3. Do you process special categories of data on a large scale – health data, biometric data, data on criminal convictions?
4. Are you a public authority or a public institution (excluding courts when acting in their judicial capacity)?
5. Do you have dozens to hundreds of employees and process their data together with extensive client records?
If the answer to any of questions 1–4 is yes, GDPR requires you by law to appoint a DPO (Article 37 GDPR). If you answered “no” to all of them, you are not obliged to do so – but that does not mean a DPO is not needed. Even without a legal obligation, an external DPO is worthwhile whenever the aim is to avoid “firefighting” GDPR issues only when an inspection or complaint arrives.
How we can help: If it is not clear which category your company falls into, a free initial assessment will be provided. If the obligation applies (or if it is to be covered preventively), the role of an external Data Protection Officer can be provided in the form of a monthly flat fee tailored to the size of the company – see the DPO Service Price List.
2. Consent to the Processing of Personal Data: When It Is Really Needed

One of the most common mistakes seen in practice: companies think they need consent for everything. The opposite is true – the GDPR recognises six legal bases for processing (Art. 6 GDPR) and consent is only one of them, and moreover the most demanding one to manage.
Consent is genuinely required, for example, when:
• sending marketing emails and newsletters to people who are not existing customers,
• using marketing and analytics cookies on a website,
• publishing photos of employees or clients on social networks,
• processing special categories of data (e.g. health data), if no other exception applies.
Conversely, consent is not needed when:
• performing a contract with a client (e.g. processing their billing details),
• fulfilling a legal obligation (e.g. payroll administration),
• relying on legitimate interest that is not overridden by the rights of the data subject (e.g. routine record-keeping of contact persons at suppliers).
Why does this matter? Consent must be freely given, specific, informed and withdrawable at any time – if it is requested unnecessarily where another legal basis would suffice, it only complicates matters (it must be demonstrable, withdrawals must be managed, etc.), and moreover, if a customer withdraws consent, processing based on a contract or on law is not affected at all.
Ako vám vieme pomôcť: Pri vstupnom GDPR audite prejdeme všetky vaše spracovateľské činnosti a presne určíme, kde súhlas skutočne potrebujete a kde si len zbytočne pridávate administratívu. Pozrite si GDPR audit v našom cenníku.
3. Data Breach: What to Do in the First 72 Hours

An employee accidentally sends a sensitive spreadsheet to the wrong recipient. Someone steals a company laptop. A phishing attack arrives and results in client passwords being leaked. In such a moment, every hour counts – GDPR gives only 72 hours from the discovery of the breach to notify the Data Protection Authority.
What to do immediately:
1. Stop any further leak – change passwords, disconnect the compromised device, recall the mistakenly sent email (if technically possible).
2. Document what happened – when it was discovered, what data was leaked, how many people are affected.
3. Assess the risk for the affected individuals – is it only contact details, or also more sensitive information (health data, national ID numbers, passwords)?
4. Decide on notifying the Authority – if there is a risk for the affected individuals (and in practice there almost always is), notification is mandatory.
5. Consider whether the affected individuals must also be informed – in cases of high risk (e.g. a leak of passwords or health data), they must be informed without undue delay.
The most common mistake companies make is waiting to see “whether something happens” instead of acting immediately. When assessing a fine, the Authority considers not only the breach itself, but also how quickly and responsibly the company reacted to it.
Ako vám vieme pomôcť: Ako externá zodpovedná osoba sme vám k dispozícii presne v týchto kritických chvíľach – pomôžeme posúdiť riziko, pripravíme oznámenie Úradu aj komunikáciu voči dotknutým osobám. Ak riešite únik údajov práve teraz, kontaktujte nás čo najskôr – v núdzových prípadoch vieme reagovať aj mimo bežného rozsahu paušálu. Viac o výkone funkcie DPO nájdete v cenníku.
4. Inspection by the Office for Personal Data Protection: how it works and how to prepare for it

An inspection by the Office for Personal Data Protection of the Slovak Republic may be initiated on the basis of a complaint by a data subject, by random selection, or in connection with a reported data breach. The good news is that it is possible to prepare for it in advance.
How an inspection typically proceeds:
1. The Office sends a notice of inspection (in justified cases it may also be carried out without prior notice).
2. Authorised employees of the Office request documentation – most often records of processing activities, privacy policy, contracts with processors, evidence of consents, and internal guidelines.
3. This is followed by questions about specific processes – for example, how requests from data subjects are handled, how long CCTV recordings are stored, or whether a data protection officer has been appointed.
4. The Office prepares a report; if shortcomings are identified, it may impose corrective measures or a fine.
What most influences the outcome: In practice, the Office penalises more strictly companies that have no documentation at all than those that have minor formal deficiencies but can demonstrate that they actively address GDPR compliance. The basic “equipment” of every company should include: records of processing activities, a privacy policy, at least a basic security guideline, and evidence that employees have been instructed.
How we can help: Complete GDPR documentation is prepared in advance, before it is needed under the pressure of an inspection, and if an inspection does occur, a responsible person is available directly throughout the entire process. See the GDPR audit and DPO services in the price list.
5. Camera system in the workplace: what you may and may not monitor

A camera at the entrance is usually fine. A camera aimed directly at a specific employee’s desk is a completely different story. Where exactly is the line?
What is (generally) acceptable:
• Exterior of the building and entrance areas – protection of property and safety is a recognized legitimate interest,
• sales/client areas accessible to the public,
• warehouses, server rooms and other areas with a higher risk of theft.
What is absolutely prohibited, without exception:
• toilets, showers, changing rooms and dressing areas,
• rest and dining areas intended for employees’ private breaks,
• rooms of trade unions or employee representatives.
What is a “grey area” – monitoring directly at the employee’s workplace:
A camera aimed directly at a workstation is only permissible in exceptional cases, for serious reasons arising from the specific nature of the employer’s activities (§ 13(4) of the Labour Code), and only after the employer has discussed the introduction of monitoring in advance with employee representatives and informed the affected employees. Without this step, monitoring is unlawful, even if it would otherwise be justified.
Another rule that is often forgotten: recordings should be stored for a maximum of 3 days, unless there is a specific incident under investigation or the controller properly justifies a longer retention period.
Ako vám vieme pomôcť: Vypracujeme vám kompletnú Smernicu o používaní kamerového systému vrátane vymedzenia zakázaných zón, informačných tabúľ a dokumentácie k prerokovaniu so zamestnancami. Pozrite si naše GDPR poradenstvo a dokumentáciu v cenníku.
6. Request for Data Erasure: what to do when it comes from an employee or client

"I want you to delete all my data." This sentence can seriously unsettle a company that has no clear procedure in place. Yet it is a common right under Art. 17 of the GDPR, for which a simple process is all that is needed.
Step-by-step procedure:
1. Verify the identity of the requester – to avoid accidentally deleting (or disclosing) someone else’s data.
2. Determine exactly what the request concerns – in practice, “all data” often means a specific set (e.g. a marketing database), not necessarily everything that is recorded about the person.
3. Assess whether any of the legal exceptions apply – the right to erasure is not absolute. If the data is needed, for example, to comply with a legal obligation (accounting documents must be kept for 10 years) or to establish, exercise or defend legal claims, the erasure in that scope is refused – with justification.
4. Delete the data wherever no exception applies, including copies held by processors (e.g. e-mailing tool, cloud).
5. Respond to the requester within one month – even if the erasure is partially refused, provide information about the reasons and about the right to lodge a complaint with the Authority.
The most common mistake: the company either deletes absolutely everything (including data that must be retained by law), or, on the contrary, ignores the request. Both extremes can constitute a breach of the GDPR.
Ako vám vieme pomôcť: Ako externá zodpovedná osoba za vás vieme posúdiť každú žiadosť dotknutej osoby a pripraviť odpoveď, ktorá obstojí aj pri kontrole Úradu. Pozrite si výkon funkcie DPO v našom cenníku.
7. Newsletter and marketing: what consents your company must have

Sending newsletters or marketing offers? The law applies from two sides here – GDPR and the Electronic Communications Act. Here is what needs to be in order.
When consent is required:
When sending marketing emails to people who are not existing customers, prior consent is required. This consent must be:
• active – an unchecked box, never pre-ticked,
• separate from consent to terms and conditions or any other purpose,
• specific and understandable – clearly stating what exactly it applies to,
• just as easy to withdraw as it was to give (a working “unsubscribe” link in every email).
Exception for existing customers:
If something is already being sold to someone, similar products or services may be offered without consent (the so-called soft opt-in) – but every message must include an easy way to unsubscribe, and from the amendment effective in November 2025, a time limit also applies to how long such contacts may be used for marketing.
Practical recommendation: double opt-in (clicking a confirmation email) is not explicitly required by law, but in practice it is the best proof that consent was genuinely given by the person concerned.
How we can help: We will prepare the correct wording of the newsletter consent and set up the records that prove when and how the consent was given. See the GDPR audit and preparation of GDPR documentation in the price list.
8. Employee monitoring: where is the line with privacy

Cameras have already been addressed separately – but employee monitoring goes much further: tracking email communication, an overview of visited websites, GPS location of a company vehicle. The rules are the same for all these forms.
Three conditions that must ALWAYS be met:
1. a serious reason – monitoring must be justified by the specific nature of the employer’s activities, not just a general concern;
2. consultation with employee representatives – before monitoring is introduced;
3. informing employees – about the scope, method, and duration of the monitoring, in a demonstrable way.
If all three conditions are not met, the monitoring is unlawful, even if it is substantively justified. Moreover, even when the conditions are fulfilled, the employer may not arbitrarily interfere with the employee’s privacy – for example, by reading clearly marked private email communication.
How we can help: Complete documentation is prepared for implementing any form of employee monitoring, including the mandatory consultation process. See the Directive on the establishment and cancellation of access rights and related GDPR consulting in the price list.
9. GDPR in employee recruitment: what you are allowed to ask candidates

Recruitment is one of the areas where companies most often collect more data than they need – and sometimes even data they are not allowed to ask for at all.
What can be requested:
• identification and contact details, education, work experience, qualifications relevant to the given position,
• references from previous employers (with the candidate’s consent),
• a criminal record extract, but only if required by the nature of the position (e.g. work with children, financial roles, healthcare professionals).
What must not be requested (or only in very limited cases):
• plans to start a family, pregnancy,
• health status, except in cases where it is directly related to the ability to perform the given job,
• religious belief, political affiliation, sexual orientation.
And what about CVs after the recruitment process ends?
If a candidate is not hired, their CV cannot be kept indefinitely “just in case it might come in handy”. Either it is deleted after a reasonable period (typically around one year), or separate consent is obtained from the candidate to include it in a database of future candidates.
How we can help: We will prepare a GDPR-compliant recruitment process for you, including a consent template for CV retention and guidance for applicants. See the pricing list for HR and personnel consulting services.
10. Employment reference and recommendations: what a former employer can say about you

Leaving an employer and the new one is asking for references? Or being an employer who has received such a request? These are the boundaries that apply to both sides.
Employment reference:
If an employee requests it, the employer is obliged to issue an employment reference – a document containing an assessment of the employee’s work, qualifications, abilities, and previous experience. It must not contain any other data (e.g. personality assessment outside the work context, political or religious views). The employer is not obliged to provide other documents concerning the employee (e.g. evaluations for internal purposes).
References to a third party:
If a new (potential) employer contacts a former employer with a request for a reference, providing any information about the former employee should be based on the employee’s consent – this is the processing of personal data for a third party, not a legal obligation.
How we can help: Providing guidance on how to set up employment references and the reference-giving process in compliance with the law and GDPR. See the HR and personnel consulting services in the price list.
11. Five internal guidelines every company should have (and most don’t)

During audits, the same situation appears again and again: a company somehow operates in line with the GDPR, but has nothing documented. During an inspection, it is precisely the documentation that matters. Here is the basic toolkit that is recommended to always have ready:
1. Privacy Policy – information for clients and other data subjects, published on the website.
2. Records of processing activities – the mandatory “register” of what is processed, why, and for how long.
3. Data protection directive – the basic internal regulation covering the entire data protection system within the company.
4. Directive on establishing, changing and revoking access rights – who has access to which systems and when that access is withdrawn.
5. Directive on the use of a camera system – if any cameras are operated within the company.
The good news: these documents can be prepared once and then only updated on an ongoing basis – it is not endless administration if they are set up correctly from the start.
How we can help: A complete package of these five documents is prepared, tailored to the company’s needs. Preparation of the complete GDPR documentation can be found in the price list.
12. How to Build a Compliance Program from Scratch: 5 Steps for Small and Medium-Sized Businesses

A "compliance program" sounds like something only large corporations with their own legal department can afford. In reality, it is a gradual process that even a small company can handle – in five steps.
1. Map the risks – identify which legal areas are most relevant for the company (GDPR, labour law, or sector-specific regulation) and where the biggest gaps are.
2. Set up basic internal policies – not dozens of documents at once, but those that cover the biggest risks.
3. Train employees – even the best policy is worthless if employees do not know about it.
4. Introduce a simple control mechanism – for example, an annual compliance review to verify whether the policies are actually being followed.
5. Update regularly – legislation changes, and a program that is set up once and never revisited quickly becomes outdated.
There is no need to do everything at once – gradually building a compliance program over the course of several months is far better than having none at all.
How we can help: Guiding small and medium-sized companies through building a compliance program step by step, from the initial risk assessment to ongoing support. See the compliance advisory services in the price list.
13. Company Code of Ethics: A Formality or a Real Risk Management Tool?

The Code of Ethics has a reputation as a document a company has drafted, publishes on its website, and never returns to. Yet, when set up correctly, it is one of the most effective tools for preventing internal problems before they become a legal or reputational risk.
When a Code of Ethics truly makes sense:
• when it is linked to specific internal processes (e.g. a reporting system under the whistleblowing law), and is not merely declaratory,
• when employees are truly familiar with it – it is part of onboarding, not just a document signed “somewhere in a folder”,
• when it contains specific, practically applicable rules (e.g. on accepting gifts, conflicts of interest), not just generic phrases about “integrity and transparency”.
Difference compared to internal policies: while policies (e.g. on data protection) regulate specific processes, the Code of Ethics defines values and expected behaviour across the entire company – their combination works best.
How we can help: Support in preparing an ethical code that is not just a formality, but is genuinely connected to internal processes and the compliance program. See the compliance advisory services in the price list.