Privacy assessment and gap analysis
We map processing activities, data flows, systems and suppliers; we measure the gap against the Regulation and the decisions of the Italian Data Protection Authority (Garante), and set clear priorities for action.
Compliance & Governance
Full compliance with EU Regulation 2016/679 and the Italian Privacy Code: from the initial snapshot of processing activities to a management system that holds up over time, with usable documents and people trained to apply them.
What we do
We map processing activities, data flows, systems and suppliers; we measure the gap against the Regulation and the decisions of the Italian Data Protection Authority (Garante), and set clear priorities for action.
We draft the record of processing activities (Article 30), privacy notices, appointments of processors and authorised persons, policies and procedures: documents that reflect how the business actually works, not generic templates.
We carry out DPIAs on high-risk processing (Article 35), assess the technical and organisational measures and document the choices made, as the accountability principle requires.
Procedures and registers to detect, assess and notify breaches within 72 hours, and to answer data subject requests within the prescribed time limits.
We vet processors, prepare data processing agreements (Article 28) and manage non-EU transfers with appropriate clauses and assessments.
We train staff through role-specific programmes and keep the system up to date with periodic audits and support in the event of inspections.
The General Data Protection Regulation (GDPR) changed the way companies have to think about privacy: no longer a list of formal requirements, but a principle of accountability that asks every controller to demonstrate, with evidence, that it has assessed the risks and adopted appropriate measures. Alongside it sit the Italian Privacy Code (Legislative Decree 196/2003), the decisions of the Italian Data Protection Authority (the Garante) on specific topics (CCTV, marketing, employee monitoring, cookies) and the European guidelines issued by the European Data Protection Board (EDPB).
Fines can reach 4% of annual worldwide turnover or €20 million, but the most frequent damage lies elsewhere: losing the trust of clients and partners, and the cost of a data breach that is handled badly.
We do not start from templates: we start from the company. Every project begins with a real mapping of processing activities – which data come in, where they are stored, who sees them, for how long and with which suppliers. Only then do we write the documents, which therefore describe what actually happens and stand up to scrutiny.
We work alongside the functions involved, in particular IT, human resources, marketing and sales, because data protection cuts across the whole organisation. Where useful, we integrate GDPR compliance with information security (technical measures, vulnerability testing), with the 231 Model under Italian Legislative Decree 231/2001 and with certified management systems such as ISO/IEC 27001, avoiding duplication of procedures and controls.
Our method
We meet management and the heads of each area, collect the existing documentation and agree the scope, the timescales and the points of contact.
Structured interviews and analysis of systems to reconstruct processing activities, legal bases, data flows, retention periods and security measures.
A report setting out the non-conformities ranked by risk, and an agreed action plan with owners and deadlines.
We draft the documents, support changes to processes and systems, manage relations with suppliers and train staff.
Periodic audits, updates as legislation and the organisation change, and support on data subject requests, data breaches and inspections.
Benefits
Deliverables
Frequently asked questions
Yes. The Regulation applies to every organisation that processes personal data, whatever its size. What changes is the complexity and proportionality of the measures, not the obligation to comply. Our approach calibrates the requirements to the actual size of the business.
It depends on size, the number of processing activities and the starting level of maturity. For an SME with standard processes, the assessment and the core documentation usually take a few weeks; complex or multi-company organisations call for a more involved programme. We set firm timescales in the initial proposal.
Often only in part. Legislation, the decisions of the Garante, digital tools and the organisation itself all change: the record of processing, privacy notices and security measures need periodic review. A focused assessment shows what to update without starting from scratch.
Appointment is mandatory for public authorities, for organisations carrying out regular and systematic monitoring on a large scale and for those processing special category or criminal offence data on a large scale. In other cases it is optional, but often advisable. We assess the specific case together and, where useful, provide an outsourced DPO service.
We work alongside the company in preparing the documentation, during the on-site visit and in the stage that follows. A privacy system built around accountability makes it possible to demonstrate the choices made and significantly reduces the risk of fines.
Related services
An outsourced data protection officer: independence, specialist expertise and continuous oversight of compliance with data protection obligations.
Find out moreAlignment with EU Directive 2022/2555 and Italian Legislative Decree 138/2024: scope, gap analysis, security measures, governance and incident notification.
Find out moreTechnical security testing of networks, applications and infrastructure: we find vulnerabilities before an attacker does.
Find out moreLet’s talk
Tell us your business priorities: in a first meeting with no obligation we look at your context and propose a concrete way forward, with clear timescales and measurable results.