Ad Stack Data Flow Mapping and Article 28 DPA Set

Longmere GrowthProNew0 orders on this service
Ad Compliance and Legal · DPA and data-flow documentation

Data flow map, Article 30 record and SCC annexes built from captured ad traffic and container exports, not from a vendor questionnaire.

About this service

We build the paperwork backwards from the network log. A first pass on a live consumer product usually turns up nine to fourteen recipients of personal data that appear in no register, no privacy notice and no contract: a pixel-only partner, an analytics SDK bundled inside another vendor's SDK, a tag somebody added in the container in 2023 and nobody removed. The record you sign at the end of this engagement describes what the stack does on the day it is signed, and it ships with the capture files that prove it. What we produce: An Article 30 record covering controller and processor activities, in a spreadsheet your DPO can maintain, one row per processing operation rather than one row per tool. A data flow map showing which requests carry identifiers, which carry only aggregate counts, and where the first cross-border hop happens. Annexes I, II and III of the 2021/914 standard contractual clauses filled in per vendor, with the module chosen and the reason for choosing it written down next to it. Transfer impact assessments for the transfers that need one, following EDPB Recommendations 01/2020, and a note on which vendors are actually listed under the EU-US Data Privacy Framework and which are relying on it without being certified for the data category you send them. A subprocessor register with retention periods taken from each vendor's own contractual terms rather than from its marketing page. How the evidence is gathered: We proxy the product with mitmproxy on web and on a provisioned test device, decode the TC string on every bid request that carries one, export the tag manager container as JSON and diff the published version against what actually fires, and read the app's dependency tree rather than the SDK list somebody typed into a wiki. Where a server-side integration hides the downstream recipients, we ask for the conversion API and clean room configuration and read that instead. Anything we cannot observe is written down as unobserved, not assumed. What this does not include: We do not give legal advice and we are not a law firm. Conclusions on lawful basis, on whether a given transfer is defensible, and anything addressed to a regulator belong to your counsel. We hand them evidence in a form they can use, and we have run that split alongside firms in Madrid, Berlin and London. We do not negotiate contracts with your vendors; we mark up the clause and tell you which two of the fourteen are worth spending a negotiation on. We do not implement the fixes, though we will sit with the engineer who does. Not for you if: You want a template set delivered next week. You want a document that concludes the stack is compliant before anybody has looked at the traffic. Or your ad stack is one Meta pixel and Google Analytics, in which case this is far more work than your exposure justifies and a two-hour call would serve you better; we will say that on the first call and not invoice for it. Who does the work: One person, on the traffic, with your engineering lead reachable for questions. We do not staff this with juniors filling in a matrix, because the entire value sits in noticing the request that should not be there and knowing why it is there.

Scope

Target market
Worldwide, United Kingdom, Germany, Spain
Working language
English, Spanish
Industry
B2B SaaS, Developer tools, Crypto and Web3, iGaming
Engagement model
One-off project
Turnaround
1 month or more
Seller type
In-house-grade specialist

What the seller needs from you

  1. 1Which properties are in scope, and can you give us a debug build or staging environment we can proxy?
  2. 2Export of your tag manager container and the ad and analytics SDKs in the current release.
  3. 3Which countries do your users, your servers and your logs sit in?
  4. 4Your current records of processing and vendor contracts, if they exist.

Asked at checkout. Delivery time starts once you answer, not when you pay.

Reviews

No reviews on this service yet.

Reviews appear only after an order completes, and both sides review each other. Nothing here is seeded or bought.

Other sellers offering dpa and data-flow documentation

See all →

Starting at €7,500