Compliance & Governance

GDPR Compliance

Full compliance with EU Regulation 2016/679 and the Italian Privacy Code: from the initial snapshot of processing activities to a management system that holds up over time, with usable documents and people trained to apply them.

What we do

Our areas of work

Privacy assessment and gap analysis

We map processing activities, data flows, systems and suppliers; we measure the gap against the Regulation and the decisions of the Italian Data Protection Authority (Garante), and set clear priorities for action.

Record of processing and documentation

We draft the record of processing activities (Article 30), privacy notices, appointments of processors and authorised persons, policies and procedures: documents that reflect how the business actually works, not generic templates.

Impact assessments (DPIA) and risk analysis

We carry out DPIAs on high-risk processing (Article 35), assess the technical and organisational measures and document the choices made, as the accountability principle requires.

Data breaches and data subject rights

Procedures and registers to detect, assess and notify breaches within 72 hours, and to answer data subject requests within the prescribed time limits.

Suppliers, transfers and contracts

We vet processors, prepare data processing agreements (Article 28) and manage non-EU transfers with appropriate clauses and assessments.

Training and ongoing oversight

We train staff through role-specific programmes and keep the system up to date with periodic audits and support in the event of inspections.

The regulatory context

The General Data Protection Regulation (GDPR) changed the way companies have to think about privacy: no longer a list of formal requirements, but a principle of accountability that asks every controller to demonstrate, with evidence, that it has assessed the risks and adopted appropriate measures. Alongside it sit the Italian Privacy Code (Legislative Decree 196/2003), the decisions of the Italian Data Protection Authority (the Garante) on specific topics (CCTV, marketing, employee monitoring, cookies) and the European guidelines issued by the European Data Protection Board (EDPB).

Fines can reach 4% of annual worldwide turnover or €20 million, but the most frequent damage lies elsewhere: losing the trust of clients and partners, and the cost of a data breach that is handled badly.

Our approach

We do not start from templates: we start from the company. Every project begins with a real mapping of processing activities – which data come in, where they are stored, who sees them, for how long and with which suppliers. Only then do we write the documents, which therefore describe what actually happens and stand up to scrutiny.

We work alongside the functions involved, in particular IT, human resources, marketing and sales, because data protection cuts across the whole organisation. Where useful, we integrate GDPR compliance with information security (technical measures, vulnerability testing), with the 231 Model under Italian Legislative Decree 231/2001 and with certified management systems such as ISO/IEC 27001, avoiding duplication of procedures and controls.

What sets our service apart

  • Usable documents: short procedures, plain language, explicit responsibilities.
  • Mapping before documents: the record of processing, privacy notices and DPIAs are built on a reconstruction of actual processing activities (data flows, legal bases, suppliers, retention periods), not on pre-filled templates.
  • Continuity: GDPR compliance does not end when the documents are handed over; we provide for periodic audits, updates as legislation and the organisation change, and support on data subject requests, data breaches and inspections.
  • Experience in regulated sectors: we know the specific features of the energy, telecommunications, healthcare and services sectors, where data volumes and commercial pressure make privacy a critical issue.

Our method

How we work

  1. Kick-off and information gathering

    We meet management and the heads of each area, collect the existing documentation and agree the scope, the timescales and the points of contact.

  2. Assessment and mapping of processing activities

    Structured interviews and analysis of systems to reconstruct processing activities, legal bases, data flows, retention periods and security measures.

  3. Gap analysis and compliance plan

    A report setting out the non-conformities ranked by risk, and an agreed action plan with owners and deadlines.

  4. Supported implementation

    We draft the documents, support changes to processes and systems, manage relations with suppliers and train staff.

  5. Maintenance and review

    Periodic audits, updates as legislation and the organisation change, and support on data subject requests, data breaches and inspections.

Benefits

What the business gains

  • A tangible reduction in the risk of fines and reputational damage, with documentary evidence that stands up to an inspection
  • Privacy documentation that reflects real processes and that people genuinely use
  • Stronger relationships with clients and partners, who increasingly require contractual privacy guarantees
  • Better-organised processes: knowing what data are processed, where and why, also improves operational efficiency
  • A stable point of contact for everyday questions on marketing, employees, CCTV and suppliers

Deliverables

What we deliver

  • Assessment report with gap analysis and a prioritised compliance plan
  • Record of processing activities (as controller and/or processor)
  • Privacy notices for data subjects (clients, employees, candidates, suppliers, website)
  • Appointments and instructions for processors and authorised persons
  • Documented impact assessments (DPIA) and risk analyses
  • Procedures for data breaches, data subject rights, retention and erasure
  • Internal policies (use of company equipment, CCTV, marketing)
  • Training plan and materials with attendance certificates

Frequently asked questions

Answers to the questions we hear most often

Our company is small: does the GDPR still apply?

Yes. The Regulation applies to every organisation that processes personal data, whatever its size. What changes is the complexity and proportionality of the measures, not the obligation to comply. Our approach calibrates the requirements to the actual size of the business.

How long does a GDPR compliance project take?

It depends on size, the number of processing activities and the starting level of maturity. For an SME with standard processes, the assessment and the core documentation usually take a few weeks; complex or multi-company organisations call for a more involved programme. We set firm timescales in the initial proposal.

We already have privacy documents from 2018: are they still valid?

Often only in part. Legislation, the decisions of the Garante, digital tools and the organisation itself all change: the record of processing, privacy notices and security measures need periodic review. A focused assessment shows what to update without starting from scratch.

Do we need to appoint a DPO?

Appointment is mandatory for public authorities, for organisations carrying out regular and systematic monitoring on a large scale and for those processing special category or criminal offence data on a large scale. In other cases it is optional, but often advisable. We assess the specific case together and, where useful, provide an outsourced DPO service.

What happens if the Garante or the Guardia di Finanza (the Italian financial police) carries out an inspection?

We work alongside the company in preparing the documentation, during the on-site visit and in the stage that follows. A privacy system built around accountability makes it possible to demonstrate the choices made and significantly reduces the risk of fines.

Let’s talk

Together, let’s build your tomorrow.

Tell us your business priorities: in a first meeting with no obligation we look at your context and propose a concrete way forward, with clear timescales and measurable results.