GDPR DOCUMENTATION BUNDLE  (English)
=====================================
Provided by ETHYX  ·  Legally reviewed by a certified Data Protection Officer (CIPP/E)  ·  Version 1.1, July 2026

WHAT'S INSIDE
This bundle is the core set of GDPR documentation almost every SME needs. Six
documents that work together as one system:

  1. ropa-template-smb-en-de.xlsx
     Record of Processing Activities (Art. 30). The master register everything
     else connects to. Bilingual workbook - use the "ROPA Register (EN)" sheet.

  2. privacy-notice-template (EN).docx
     Privacy notice for your website (Art. 13-14). Modular: keep the optional
     modules that apply to you, delete the rest.
     PDF version: privacy-notice-template (EN).pdf

  3. tom-checklist-art-32 (EN).pdf
     Technical & organisational security measures (Art. 32). Fill it in and it
     becomes the security annex your DPAs and ROPA refer to.

  4. data-processing-agreement-template (EN).docx
     Data Processing Agreement (Art. 28) to sign with each processor. Its Annex 2
     points to the TOM checklist above.
     PDF version: data-processing-agreement-template (EN).pdf

  5. dpia-template (EN).docx
     Data Protection Impact Assessment workflow (Art. 35). Use it before any
     high-risk processing.
     PDF version: dpia-template (EN).pdf

  6. loeschkonzept-template-en-de.xlsx
     Data retention & deletion rules (Löschkonzept, Art. 5(1)(e), 17, 18).
     One deletion rule per data type - period, trigger, owner. Bilingual
     workbook - use the "Deletion Rules (EN)" sheet.

SUGGESTED ORDER
  Start with the ROPA (1) - it maps your processing. Then write the privacy
  notice (2) from the ROPA's purposes, document your security measures (3),
  sign DPAs with your processors (4), run DPIAs where processing is high-risk
  (5), and derive your deletion rules (6) from the ROPA's retention fields.

This bundle is guidance, not legal advice. Have it reviewed by a qualified DPO
before relying on it. ETHYX - ethyx.eu
