← All kits
For software and technology companies selling to enterprise · GDPR

The full GDPR set procurement asks for.

An enterprise buyer sends a 40-question data-and-security form, and the deal stalls while you scramble to answer it.

A complete, deployable programme — eight documents you brand and sign, and six live consoles that build and keep your registers: everything an enterprise buyer wants before they sign. Answer the form in an afternoon instead of a fortnight.

NEW · JULY 2026Eight documents + six live consoles — RoPA, DPIA, DSAR, breach, LIA and TIA — in one download.

✓ 14-day money-back guarantee. one-off €690 · ordered by email, invoiced same day · ZIP in your inbox on payment · fully editable · single-business licence

RoPA Builder console from the GDPR Compliance Kit — the Article 30 record with live activity counters
Actual screen · RoPA Builder console · v1.0, June 2026 build
What’s inside

Everything you deploy, in one download.

Editable Word masters with styled PDF previews — plus self-contained HTML consoles that run in your browser, offline. Built to a single standard and cross-referenced where it counts.

6 interactive tools8 documents · Word + PDF previewoffline HTML · CSV exportversion-dated

Interactive tools (6) — the part you’ll use every week

  • RoPA Builder — build and keep your Art. 30 record of processing, live
  • DPIA Console — screen, run and record impact assessments
  • Data Subject Request Console — track DSARs against the clock
  • Breach Response Runbook — the 72-hour drill, documented as you go
  • Legitimate Interests Assessment — run and record LIAs
  • Transfer Impact Assessment — assess and file transfer safeguards

Documents (8) — brand, fill, sign

  • Data Protection Policy
  • Privacy Notice
  • Employee Privacy Notice
  • Cookie Consent Notice
  • DPA — Art. 28 terms; EU SCCs & UK Addendum incorporated by reference
  • Sub-processor List
  • Retention Schedule
  • Security Measures Summary (Art. 32)

How the tools work

  • A single HTML file each — double-click, it opens in your browser
  • Runs in your browser: nothing is uploaded — what you type never leaves your machine
  • Save a session and pick it up later; export registers to CSV
  • Print a dated PDF readout for your audit file

What you download

  • One ZIP, delivered to your inbox on payment — usually within the hour
  • Documents as editable Word masters plus a styled PDF preview of each
  • Tools as self-contained HTML files — no install, no account
  • Version-dated · single-business licence (no resale or redistribution)
Proof, not promises

Judge the work before you pay.

An actual document page from the shipped kit is below — and the free tool runs on the same expert layer, so the sharpest preview is to run it.

First page of the Data Processing Agreement styled preview from the kit
Actual page · DPA preview (Word master included)
free · no sign-up

Don’t take our word for it — try the thinking.

The free GDPR Readiness Scorecard runs on the same senior expertise that built this kit — a live read of your own position, not a teaser. The free check is the kit’s thinking, without the kit’s documents. If the diagnosis is this specific, that’s what the treatment is like.

Run the free GDPR Readiness Scorecard →

On this page: an actual console screen (top) and an actual document page from this kit. More samples on request.

A full GDPR programme, built bespoke, runs into the thousands.

RoPA, DPA, privacy notice, breach runbook and the assessments — assembled and cross-referenced by someone who has done it at scale. The same set, yours to deploy now, for €690.

Why you can rely on it
EXPERT
BUILT

Fifteen years, 10,000+ contracts and corporate documents, and both sides of M&A went into this kit — including a recent USD 40M+ software exit. It was built from casework, and it's maintained like casework: cited, dated, updated when the law moves.

Cited to source · version-dated · current as of July 2026

Want it done for you, or scoped to a large data estate? See the GDPR Gap Assessment.

See the assessment

Kit fee credited in full against the GDPR Gap Assessment · not sure which fits? Book a free intro call ›

The GDPR menu

Wherever you are with GDPR, here’s what fits.

Pick the one that matches where you are — each stands alone, buy in any order or on its own. Your team does the work with our templates; that’s why this costs a fraction of a consultancy.

Check yourself — free
GDPR Readiness ScorecardA dynamic read across your bases and transfers in minutes.Open ›
Get assessed
GDPR Gap Assessment · €4,900Nine domains scored, gaps rated, a prioritised roadmap.Open ›
Get the documentsyou’re here
GDPR Compliance Kit · €690The full policy, notice, DPA and register set — deployable.On this page
Get it done, keep it current
Enterprise · Fractional · a free intro callHands-on remediation, ongoing upkeep, or a free scoping call.Open ›
A specific DPA on the table?
Expert Contract ReviewSenior review and negotiation of the contract in front of you.Open ›
Questions

Before you buy.

We already have a privacy policy — isn’t that enough?

A privacy notice is one document of many. Procurement and DPAs ask for your RoPA, your Art 32 security measures, your sub-processor list, your breach process and your transfer safeguards. The kit is the whole set, cross-referenced — not one document doing the work of ten.

Is it current?

Yes. Every document cites its Articles and is version-dated, and reflects the post-Schrems II transfer position (EU SCCs and the UK Addendum, incorporated by reference). You receive the version current at purchase.

Can I edit everything?

Yes — the documents are working Word files, not locked PDFs. The RoPA, DPIA, DSAR and the other consoles are live browser tools: save a session, export CSV, print a dated PDF for your audit file.

Isn’t this just legal advice in a box?

No — it’s a set of expert-built template documents and guidance you deploy yourself, not legal advice and not a review of your business. The documents are drafted to market-standard positions for a typical software and technology company and are yours to adapt. Buying them creates no lawyer–client relationship or privilege, and Xprofesso LLC is not a law firm.

What you’re buying: deployable, editable source documents — policies, privacy notice, DPA and the RoPA/register set — plus guidance to implement them, built by a senior practitioner.

What it isn’t: a check of your specific setup, confirmation the documents are sufficient for your facts or jurisdiction, or an opinion on enforceability. Want your actual position checked? That’s the GDPR Gap Assessment. Need a formal opinion or a filing? That’s a licensed lawyer.

Direct line · reply within one business day

A question before you buy?

One message — no account, no call required. It lands in our Proton inbox.

Proton (Switzerland) · no ad-tech · purged after 12 months

Prefer to talk it through? Book a free 20-minute intro call ›

Answer the security review in an afternoon.

€690, one-off. In your inbox within the hour of payment, fully editable, backed by a 14-day money-back guarantee.