I help mid-sized AEC companies get a complete GDPR construct that runs smoothly and easy to maintain.
Melodie Lange
Privacy & Security Consultant
Top 3 reasons for GDPR fines
How well prepared is your company to avoid fines?
How much time and effort is it costing you to deal with unresolved privacy issues?
I developed my GDPR Roadmap to help architecture, engineering, and construction companies finally bring structure, clarity, and control to their GDPR obligations.
The Roadmap provides a strategic, step-by-step plan to complete all essential tasks efficiently, using synergies, the right sequence, and a clear focus.
Using my methodology, I help AEC companies build a complete, audit-ready GDPR setup that reaches a strong level of compliance maturity, all within 9 months.
Interested?
Risk-oriented best practice solutions.
One request at a time. Pause or cancel at any time.
What's included:
- Any GDPR-related requests
- Unlimited number of requests
- Average 48-hour response time
- One monthly 45-minute call
- One request at a time
Double the requests. Pause or cancel at any time.
What's included:
- Any GDPR-related requests
- Unlimited number of requests
- Average 48-hour response time
- Two monthly 45-minute call
- Two requests at a time
The GDPR Roadmap
Full done-with-you GDPR implementation program.
100% confidence in your compliance
50% less GDPR workload longterm
Up to 30% more compliance achieved in the first 30 days
100 % audit-ready documentation
Before Working With Me
After Working With Me
“We have spent years and thousands of euros, but are still not compliant.”
“We finally reached GDPR compliance and can prove it.”
“We don’t even know where to start. Everything feels overwhelming.”
“We have a clear plan and know exactly what to do and how to get it done.”
“We have no proof of compliance, so we waste hours with questionnaires.”
“We can provide clients proof of compliance within minutes.”
“GDPR takes up too much of our time.”
“GDPR no longer disrupts our day-to-day work.”
“Our consultant gave us templates, but no real help”.
“We get expert and hands-on support that delivers results.”
“GDPR issues constantly delays projects, decisions and new ideas.”
“GDPR is second-nature to us. No stress or delays”.
“GDPR feels like pointless paperwork. Everyone is fed up.”
“All the required documentations are clear, easily implemented and useful.”
With my methodology, your company will have a complete, audit-ready GDPR setup within 9 months, guaranteed.
The process is structured with clear milestones, ensuring steady progress without overwhelming your team.
Audit & Strategy:
Expect around 4 hours for the audit itself, followed by a 60-minute strategy session to review findings and next steps. Both management and your main contact for the project (e.g. your data protection coordinator) are involved in this process.
Roadmap:
During the implementation phase, you should plan for around 3 hours per week for internal coordination and follow-ups. This includes a weekly 45-minute call and the completion of the agreed tasks.
Unlimited Consulting:
Once the system is in place, you will be required to invest less than one hour per week to stay compliant.
I don’t just advise. I actively support and implement the process together with you.
My GDPR Roadmap finally makes data protection strategic, manageable, and achievable.
With a clear structure, fast results, and the goal of saving time and resources in the long run instead of endless recommendations, I deliver real progress and lasting compliance with minimal effort.
No consultant can guarantee absolute GDPR compliance, because compliance is not a one-time event.
Compliance relies on continuous decisions, employee behavior, and how new tools or processes are introduced in your company over time.
What I can guarantee is that by the end of the process, your company will have a complete, audit-ready GDPR setup with all required documentation, processes, and roles in place.
You’ll reach a high level of compliance maturity and have a system your team can maintain with minimal effort.
That means clarity, control, and confidence, instead of ongoing uncertainty and stress.
Here is what I need from your part in order to achieve the desired results:
A dedicated point of contact who can be available for approx. 2-3 hours per week to help ensure progress. I’m happy to support you in selecting the right person.
Your DPC should ideally attend regularly (approx. 80% attendance is sufficient). This keeps us aligned, avoids roadblocks, and ensures steady progress.
Your IT department should be available for up to 2 hours per week to respond to questions, provide system overviews, and share relevant security information.
Relevant departments will need to complete questionnaires or provide specific information so data protection tasks can be implemented correctly.
Please make sure that these tasks are clearly assigned internally and completed on time. I’ll support you with realistic timelines, templates, and practical guidance.
Whether it’s approving a document, providing brief feedback, or making a decision, I prepare everything to make it as easy as possible for you, such as eady-to-use templates, clear yes/no questions (where applicable) and concise decision summaries.
Most points can be resolved within 7 days; for more complex matters, 14 days is perfectly fine.
I’ve designed the process to be efficient and easy to follow. You’ll always know exactly what’s expected and when and I’ll help eliminate any confusion along the way.
The GDPR Roadmap is a structured, done-with-you solution designed to get you from overwhelmed to confidently set up in under 9 months. Here’s exactly what’s included:
Weekly 45-Minute Strategy Calls
These calls ensure continuous progress, answer questions, and help you stay on track with GDPR compliance.
Complete Documentation
I’ll create and review all necessary GDPR documents (Data Protection Policy, Data Subject Request procedures, etc.) to ensure everything is in place and easily maintainable.
Compliance Reviews & Updates
Reviews ensure your compliance documentation is up to date with the latest legal requirements and changes within your organisation.
Process Optimization
I’ll optimize your internal workflows for GDPR, ensuring processes are streamlined and integrated seamlessly into your operations without disruption.
Quarterly Progress Reports
You’ll receive detailed updates on our progress, highlighting what’s been completed what’s next, and the roadblocks that need to be resolved to continuously set the project up for success.
Clear Action Steps
Every step is broken down into manageable tasks. I’ll provide checklists, templates, and clear instructions so you know exactly what to do and when.
With me, there are no endless delays, I make sure your project keeps moving forward consistently.
I take proactive steps to prevent slowdowns: I break down complex topics into manageable steps, provide clear instructions, and use ready-to-go templates so that every task is understandable, doable, and quick to implement.
Delays often happen because tasks are too big, too complicated, or not clearly defined. That’s exactly where I come in:
I make data protection accessible, practical, and easy to apply even for teams without a legal background.
And if things ever do stall, I’ll help you get back on track quickly.
My system is flexible and adaptable and I stay by your side to make sure you reach your business goals without losing sight of GDPR compliance.
In the final stage of The Roadmap I will focus on training your team how to maintain the implemented system.
If you’d like continued support after the setup, my Unlimited Consulting service ensures that your implemented Data Protection Management System is continuously monitored, updated, and improved over time.
For you, this means your data protection stays up to date with minimal effort on your part and without the long-term headaches that GDPR management usually brings. Your system keeps working — and you can stay focused on your core business.
To ensure GDPR doesn’t take up more of your time than necessary, I:
Ongoing GDPR maintenance is possible in less than 1 hour per week with my support thanks to clear structures, proactive guidance, and direct handling of urgent matters through my Unlimited Consulting.
You’ll need to assign a Data Protection Coordinator (DPC), provide information and documents when needed, and participate in regular calls to track progress. Don’t worry, I’ll guide you through each step to keep things simple.
With Unlimited Consulting, you get support whenever you need it, without worrying about unpredictable costs.
The service comes with a fixed fee, so you can ask questions, resolve urgent issues, and stay on top of compliance without stressing about hourly rates or surprise fees.
Proactive support:
I take the lead in managing your GDPR compliance, so you don’t have to chase me for updates or guidance. I’ll identify potential issues before they become problems and address them on your behalf, ensuring smooth, continuous compliance.
Minimal time commitment:
Maintaining compliance takes less than 1 hour per week of your time. I streamline processes so your team only handles what’s necessary, and I do the rest, keeping things efficient and effortless.
Stay ahead of changes:
With ever-evolving regulations, you can trust that I’ll keep your compliance updated without you having to track every change. I’ll keep you informed and make any necessary adjustments to stay on top of new requirements.
This service ensures you stay compliant long-term, with proactive, hands-on support and predictable costs, no surprises, no need to chase me, just peace of mind.
Providing privacy and security consulting for european and international startups, SMEs, and corporations on GDPR implementation since 2017.
Law
Data Protection
Information Security
Certified Data Protection Officer (IHK)
iapp Certified Information Privacy Professionals/Europe (CIPP/E)
iapp Certified Information Privacy Manager (CIPM)
Certified ISO IEC 27001 Auditor (TÜV)
CompTIA Securiy+ Certified
Certified Chief Information Security Officer (CISO)
Recht
Diplomjuristin (LMU)
Datenschutz
IHK zertifizierte
Datenschuftbeauftragte
iapp Certified Information Privacy Professionals/Europe (CIPP/E)
iapp Certified Information Privacy Manager (CIPM)
Informationssicherheit
TÜV-zertifizierte ISO IEC 27001 Auditorin
CompTIA Security+
zertifiziert
Certified Chief Information Security Officer (CISO)
Because I work closely with each client, spots are limited.
If you’re ready to finally get GDPR handled with less stress and more clarity, I would d love to hear from you.
Apply now to explore if we’re a good fit.
Contact me via the contact form or per e-mail.