We are an 8-person digital marketing and custom software agency based in Strasbourg. We submitted a proposal to a large France-based retail chain to develop in-store customer loyalty and analytics software. We agreed on commercial terms and budget, but before signing the contract, the client's procurement and legal department asked us for a comprehensive «RGPD Compliance Package» along with a technical and organizational measures document.
We are a small team; we don't have an in-house full-time lawyer or data protection officer (DPO). Until now, we just got by with putting a standard privacy policy on our website. Do we need to present an ISO certification or a state-approved certificate to the client, or are internal documents prepared by us sufficient for an enterprise-level company?
What concrete documents do we actually need on hand to convince a large client at the negotiating table, how do we include a data processing agreement (DPA) and data inventory in this package, and in what order should an agency of our scale tackle this preparation from scratch?