Gdpr compliance both in general and with regard to single processes/projects/activities
Together with a team of professional, specialized in different areas of practice, such as legal, technological and IT, we assist our Clients in redacting a complete and efficient GDPR compliance plan. Our services are usually customized on the basis of the needs of the single Client, of the organizational structure and of the complexity of such structure; furthermore, our compliance plan can easily be adapted to the company in its complex, or to a single project or process.
Our added value is considering consultancy as a set of legal and informatics specialized services, in the field of data protection, guaranteeing solutions which are both compliant with the applicable laws and easily feasible.
Our Services include:
- Mapping of all data processed and of the categories of data subjects involved;
- Analysis of all processes and personal data flows;
- Identification of subjects (both internal and external) which are involved in the data processing activities;
- Analysis of the data processing policies already adopted by the Client;
- Analysis of all existing technical and organizational security measures;
- Identification of synergies with Organization Models (corporate, banking, insurance compliance laws and for the prevention of informatic crimes, in compliance with art. D.Lgs. 231/2001 etc.);
- Evaluation of preexisting provision of the Supervisory Authorities, addressed to the Client or, more in general, in relation to similar areas of practice or projects.
All this information is usually collected by our professional, who will carry out specific interviews with single departments, as well as a thorough documental due diligence.
Our service also includes the definition and drafting of all necessary law requirements, specifically customized to the Client’s area of business (e.g. specific privacy notice for different specific sectors, modular consent forms, data processing agreements, prior Consultation to the Authority etc.).
The release of the documents is – case by case – usually accompanied by a summary report, which includes the assessment’s result and specific instructions on how to use the documents delivered.
Our goal is to support our Clients in defining corporate principles on the protection of personal data, in order to ensure that all processing activities are compliant with the GDPR and with the national relevant laws, but also in line with the business’ goals.
Compliance assessment
We measure the organisation’s level of compliance with personal data protection legislation, giving back a clear picture of its strengths and of the areas for improvement. The service is tailored to the Client’s operational needs and organisational complexity and may cover the whole organisation, individual processes or specific projects. The added value is that we do not stop at the diagnosis: we set out the improvement actions and put together a concrete strategy for implementing them, with priorities defined based on risk.
The service is delivered through:
- A review of the processing activities carried out and of the data protection documentation already adopted;
- Verification of compliance against the requirements of the GDPR and of the applicable national legislation;
- Analysis of the technical and organisational security measures in place;
- Assessment of the roles and responsibilities of the parties (internal and external) involved in the processing;
- Identification of improvement actions, ranked by risk priority;
- Preparation of a strategy and an operational plan for implementing the actions identified.
The service ends with an assessment report setting out the level of compliance found, the improvement actions suggested and the roadmap for implementing them.
The aim of the service is to give the organisation full awareness of its own level of compliance and an operational tool for planning action, in line with business priorities.
Audit
We verify compliance with the personal data protection legislation applicable to specific obligations and business processes, with an integrated legal and technical/IT approach. Content and method vary according to the Client’s operational needs and the service may cover individual processing activities, processes or business functions. We offer an independent, documented check that delivers concrete evidence on the state of compliance and on the corrective action required.
The service is delivered through:
- Definition of the audit scope and of the compliance obligations to be verified;
- Examination of the data protection documentation adopted (records, notices, appointments, procedures);
- Interviews with the business functions involved in the processes verified;
- On-site verification of the technical and organisational security measures;
- Identification of gaps against the legislation and internal policies;
Indication of corrective action, ranked by risk priority.
The service ends with an audit report setting out the evidence gathered, the gaps identified and the plan of suggested corrective action.
Marketing and digital advertising
We work alongside the Client in setting up marketing and profiling campaigns in compliance with the GDPR and with the guidance of the EDPB and of the Italian Data Protection Authority (Garante per la protezione dei dati personali), taking account of the Client’s commercial objectives and organisational complexity. We handle the obligations relating to the use of cookies and other digital tracking systems, the preparation of privacy notices and the collection of consent, making it easier to process data correctly along the whole marketing funnel. Our approach seeks to combine compliance and business: respect for the rules and the development of effective marketing.
Remote monitoring of workers
We work alongside the Client in managing the employment law and data protection aspects connected with the remote monitoring of employees, including video surveillance systems and work tools. We take account of the guidance of the Italian Authorities (Ispettorato del Lavoro and Garante per la protezione dei dati personali) for the individual sectors and tools concerned. Our assistance may cover individual installations or the entire scope of company monitoring and includes preparing the agreement with the trade union representatives or the application to the Italian “Direzione territoriale del Lavoro”, the privacy notices, the procedures and the authorisations to process data, the balancing test on legitimate interests and the impact assessment.
Our support extends to the assessment of any trade union observations or requests and to legal assistance both in the authorisation process and in any inspection and enforcement proceedings on the matter.
International data transfers Standard Contractual Clauses and Transfer Impact Assessments
We provide legal and technical assistance in managing transfers of personal data to third countries, ensuring that the flows comply with Chapter V of the GDPR. We take account of the Client’s organisational complexity and of the nature of the transfers, and we can provide support both for individual relationships with non-EU suppliers and for the entire processing chain. We map outbound data flows, identify the legal basis for the transfer and handle the adoption of the Standard Contractual Clauses (including completing them), carrying out the Transfer Impact Assessment with our own model, which takes account of the EDPB Guidelines, in order to assess the level of protection offered by the country of destination and define any supplementary technical and contractual measures
Codes of conduct (Art. 40 GDPR)
We work alongside trade associations and representative bodies in developing codes of conduct on the protection of personal data under Article 40 of the GDPR and in taking them through approval. In the GDPR ecosystem, a code of conduct is an instrument shared between the members of the association that promoted it, who undertake to comply with it, which translates the principles of the GDPR into the concrete practices of those members and simplifies the compliance obligations of individual operators. A code of conduct can be a distinguishing element of accountability and of trust towards data subjects and the market. We handle the analysis of the processing activities typical of the sector, the drafting of the content and of the implementing measures, the definition of the monitoring bodies provided for by the legislation and the management of the approval process before the supervisory authority.
Data breach management and assessment
We work alongside the Client in assessing and managing personal data breaches, stepping in promptly in the critical phase following the incident. We operate both preventively, by preparing data breach management procedures, and reactively, once an incident has occurred. We support the analysis of the event and the reconstruction of how it unfolded, the assessment of the risk to the rights and freedoms of data subjects, the management of the notification to the supervisory authority within seventy-two hours where required and of the communication to the data subjects, as well as the keeping of the breach register. Assistance in this area allows the Client to react quickly, in a documented and compliant way, containing reputational and enforcement impacts and strengthening its incident response capability over time.
Privacy aspects of M&A transactions
We aid in managing the privacy and personal data protection aspects connected with mergers and acquisitions. We follow every stage of the deal, from due diligence through to closing and post-transaction integration. We carry out privacy due diligence on the target company to bring critical issues and hidden liabilities to light, assess the impacts on processing activities and data flows, handle the setting of roles and legal bases for the sharing of information and support the harmonisation of compliance systems at the integration stage. The added value of privacy due diligence is to allow the parties to quantify and manage data protection risk within the transaction, protecting the value of the deal and ensuring continuity of compliance after finalization.
Data protection litigation
We assist and represent the Client, with the support of a network of correspondents that allows us to operate before courts other than Milan, in managing disputes on the protection of personal data, both in and out of court. The service may cover litigation with data subjects, proceedings before the supervisory authority and challenges to its decisions. We handle the defence strategy, the preparation of submissions, complaints and appeals, the management of compensation claims and the defence against administrative fines and measures restricting processing, coordinating with the internal functions and with any technical consultants. Ours is a specialist defence, reinforced by in-depth knowledge of the case law in this field.
Ongoing data protection consultancy with maintainance support
With this service, we offer to our clients constant support, helping them on an ongoing basis in dealing with problems relating to the processing of personal data. Our goal is to offer to our clients the well-established experience of our professionals in order to find quick and effective solutions to the increasingly frequent privacy implications of the daily management of business activities.
Our services may include, by way of example, the following activities:
- Assistance in managing requests from the data subjects;
- Updating or drafting privacy notices and consent forms;
- Updating or drafting procedures, policies and/or operating instructions;
- Assistance in defining privacy roles and responsibilities with external providers and drafting all necessary documents required by the law;
- Assistance in evaluating informatic instruments and/or new technologies for processing of personal data;
- Assistance in launching digital marketing campaigns, or sponsoring projects, in full compliance with data protection requirements;
- Assistance in launching recruitment projects, or selection of personnel, in full compliance with data protection requirements;
- Legal advice in launching new projects which may involve processing of personal data;
- Periodical audits to verify the client’s compliance, either in general or with regard to single business areas;
- Assistance at the client’s offices during inspections carried out by the supervisory authority or by the Custom Police.
With regard to the modalities of our intervention, we offer the typical “help desk” methodology: which means flexibility and freedom for the Client to define an annual budget which shall be allocated to the services, so as to take full advantage of the economies of scale.
Drafting and review of clinical trial and pharmacovigilance agreements
We provide assistance in drafting and reviewing clinical trial and pharmacovigilance agreements. We take account of the Client’s role and responsibilities (sponsor, investigator, CRO or healthcare facility) and of the nature of the study. Depending on the Client’s needs, we work on individual agreements or on the entire set of contracts for the project. We handle the definition of the parties’ roles and responsibilities, the identification of the timelines and obligations of each party involved, the rules governing the processing of personal and health data and the transparency obligations, as well as the coordination with sector-specific legislation and with the authorisations required. Our approach is to deliver clear, balanced and compliant agreements that protect the Client from a legal and data protection standpoint and ensure that the trial and the pharmacovigilance activities are carried out properly.
Specialistic opinion on data protection issue in the context of specific business areas (e.G. Scientific research, health sector, telemedicine, retail, third sector etc.)
Data protection laws applies differently in relation to various sectors (e.g. scientific research, health sector, pharmaceutical sector, telemedicine, retail, third sector, artificial intelligence, video surveillance etc.) and has relevant impacts in consideration of the intended use for the data (e.g. marketing, communication, employment management, digital services etc.)
Our approach in providing opinions goes beyond the traditional methodology and it is characterized by a strong practical approach. Our opinions are always correlated by a summary and various attachments with all documents necessary to ensure the Client’s compliance. Furthermore, it is our priority to educate the Client’s personnel on the contents of the opinion and, where, necessary, interacting with the third service providers, which shall carry out all the necessary intervention pursuant to the opinion.
Training and learning sessions, workshops, e-learning
Among our services, we offer training and learning sessions on specific subjects, including privacy and protection of personal data, corporate compliance and Organizational Model pursuant to D. Lgs. 231/2001.
Our learning sessions include both general and theoretical notions on the main principles of the applicable laws, and more technical and practical notions, tailored on the area of business of the Client, as well as on any relevant sectorial applicable law. Furthermore, and within our consultancy services, we offer specific training sessions on the correct use and implementation of all documents and deliverables prepared for the Client (e.g. appointments of delegates, policies, information notices etc.).
All our learning services are modulated and adapted to the specific needs of the Client, and can be delivered both in class and at distance; timing, duration and recipients of such sessions are always defined in advance and agreed upon with the Client, with the possibility to arrange single sessions for personnel with specific duties and competences within the company.
We furthermore offer drafting of learning materials (e.g. awareness raising materials, simulations of possible scenarios with fictional characters, legal text easily accessible via hypertext) which can also be uploaded into e-learning platforms including animations, sounds, multiple answers questions and randomized answers.
We also offer a range of “ready-to-go” solutions, thanks to a consolidated collaboration with our technological partner Mediamed Interactive, which allows us to offer to our Clients a product based on the more evolved and widespread training platforms, so that our Clients can enjoy both standard sessions or more tailored sessions.
Assistance in administrative proceedings before the authority
We assist and represent our Clients in administrative proceeding before the Italian Data Protection Authority and before other Europeans’ Supervisory Authorities, in cases of, by way of example:
- Requests to provide documents and information by the Authority after a complaint brought by a data subjects;
- Investigations carried out by the Authority after an administrative complaint;
- Pleadings against administrative sanctions;
- Notification of violations of personal data to the Authority, pursuant to art. 33 GDPR;
- Request for prior consultation to the Authority, pursuant to art. 36 GDPR.
Guidelines on specific issues
We prepare operational guidelines to support the management of compliance obligations and to govern processes with a particular impact on the protection of personal data. We carry out the work in synergy with the Client, covering, depending on the case, individual processing activities, business functions or cross-cutting processes that call for specific and consistent instructions. We translate the regulatory requirements into clear, concrete instructions, tailored to how the organisation operates and coordinated with the policies and procedures already adopted. The aim is to give the internal functions an immediate point of reference that reduces the margin for error, ensures consistent application and facilitates daily compliance with personal data protection legislation, strengthening the overall accountability of the organisation.
Data protection impact assessment
Pursuant to art. 35 of the GDPR, we offer our Client support in all risk analysis evaluations required by GDPR for those processing activities which, due to their purpose, nature and context, and in relation to the business area where the Client operates, may potentially pose a risk for the rights and freedoms of the data subjects involved.
In this context, we offer our Data Protection Impact Assessment services (i.e. DPIA), which include:
- Preliminary opinion on the necessity to carry out a DPIA, after a technical and legal analysis of the processing operations, in light of the legislative requirements (both national and European) and considering the nature of the Client’s activities and any applicable sectorial legislation;
- After establishing the necessity or the opportunity to carry out a DPIA, analysis of the corporate processes and of all the personal data flows in the relevant area, from a technical and legal standpoint;
- Assessment of the necessity and the proportionality of the processing, in relation to the purposes to achieve, together with an evaluation of the risks for the rights and freedoms of the individuals;
- Identification of all the required document to be drafted, pursuant to the applicable data protection laws and to the specific sectorial law (e.g. privacy notice, procedures, consent forms, specific modalities for collection of consents etc.);
- Definition of operating procedure for designing data flaws in a privacy compliant manner;
- Definition of organizational processes, adequate security procedures and appropriate mechanisms to ensure protection of personal data and full compliance with the GDPR and with the specific sectorial laws;
- Where necessary, support in involving and/or collecting the opinions of the data subjects (or their representatives);
- Where necessary, assistance in prior consultation to the Supervisory Authority, pursuant to art. 36 of the GDPR, and where the residual risk, after analysis and adoption of security measures, remains high.
Thanks to a wide experience in the field, together with constant updates and attentions to news and novelties in the legal and technological framework, we offer our Clients a complete and precise service, with a dynamic and innovative approach which goes beyond the mere analysis of the privacy risks connected to a single operation (usually offered by most tools available on the market). Our analysis in fact, also considers and analyzes the potential implications on the individual rights of the data subjects, including, by way of example, the right to self-determination, the right to image, to reputation, the right to health and to integrity.
Out DPIA services are offered by a cross disciplinary team of experts in different areas, including legal and information security, through which we can assist our Clients in adopting adequate security measures, ensuring full compliance with data protection laws.
Outsourcer/external providers assessment
We assist our Clients in defining and regulating the contractual relationship with strategic providers, entrusted with processing activities of personal data, especially in those business areas which are subjected to specific sectorial laws on externalizations (e.g. pharmaceutical sector).
With regard to this area, our services include:
- Preliminary evaluation of the general overall level of compliance of the provider, where there are specific legislative requirements which the provider has guaranteed upon;
- Assistance in drafting and reviewing service agreements, in all aspects which may have implication on the protection of personal data;
- Assistance in defining privacy roles and responsibilities with the service providers by drafting, where necessary, ad hoc appointments as Data Processor, pursuant to art. 28 GDPR, customized on the Client’s needs and on the characteristics of the specific service offered by the provider;
- Legal and technical verification of the adoption, by the provider, of adequate technical and organizational measures to ensure security and integrity of personal data processed on behalf of the Client.
Our services are specifically customized to the Client’s necessities, end include both a preliminary verification during the selection of an outsourcer and a subsequent control of the compliance level of the chosen provider for a specific service or activity.
Analysis and drafting of documents are carried out by cross disciplinary teams, including legal, technological, IT experts and professionals.
Data protection officers services (for medium-big sized companies)
Our Data Protection Officer services, are carefully customized to the size, the peculiarity and the characteristics of the Client’s organization, and include the thorough verification of the general compliance levels of the Client with the requirements of the law; proactive actions in promoting the fulfilment of legislative obligations, and an internal guarantee for the respect of such obligations.
Our Data Protection Officer services include:
- Support in drafting and updating corporate Policies and support in their enactment;
- Consultancy and advice on single relevant privacy issue;
- Support on how to properly set privacy initiatives, activities, and applications;
- Control over processing activities carried out by the Client or by external providers acting on Client’s behalf;
- Management of personal data breaches;
- Management of requests from the competent authorities;
- Management of data subject’s requests;
- Maintenance of privacy compliance systems;
- Reports to management;
- Constant update and training;
- On-site assistance in the occasions of investigation by the Italian Authority.
Our Data Protection Officer’s services are offered by a team of legal and data security experts, who will constantly interact and support the Client’s internal departments in the daily compliance with all the requirements of the law. Our goal is to transform the mere compliance with a legal obligation into an added value for our Clients.
Assistance in enforcing the right to be forgotten
In case there are still news of criminal records or other defamatory information on the internet, affecting the reputation of our clients, our team of experts will assist them in enforcing the Right to be Forgotten.
In such cases, it will be necessary to bring to the attention of our team of legal experts on the right to be forgotten and IT experts, the relevant link harming the client’s reputation; our team will then device an effective plan, in order to assess whether the criteria to apply the right to be forgotten, and therefore to remove the malicious link, pursuant to art. 17 GDPR, are met.
Nowadays, Google is the most used and advanced search engine, and the information show on the first page, connected to your name, are what matters the most.
It often happens to be subjected to external attacks, due to negative past experiences or criminal records, which remain on the internet for a very long time and are very easy to retrieve even after years.
One should know that a legal action against Google (or other search engines) could very easily be counterproductive, and this is not how we work: a legal action in fact would imply a considerable amount of legal expenses, and would be very time consuming.
Our working method is tried and true and aims at solving the problem in the shortest possible time, in order to help our client to effectively enforce their right to be forgotten.
Legal Desk
With this service we provide the Client with ongoing support on personal data protection, working alongside it in the day-to-day management of the privacy implications of its business. We rely on an integrated legal and technical/IT team and on a dedicated contact lawyer, who coordinates the work and develops an in-depth knowledge of the company context over time, ensuring rapid, tailored and effective solutions.
The service is shaped around the Client’s needs and includes, by way of example:
- assistance in handling data subject requests;
- updating and producing privacy notices, consent forms,
- procedures, policies and operating instructions;
- defining privacy roles with suppliers and the related documentation;
- assessing, from a data protection standpoint, IT tools and new technologies, digital marketing campaigns, recruitment projects and new processing operations;
- periodic compliance audits on the entire system or on individual business areas;
- assistance at the Client’s premises during inspections by the supervisory authority, together with the ongoing maintenance and updating of the privacy model adopted.
In operational terms we adopt the typical help desk methodology: the Client sets a dedicated annual budget upfront, making the most of economies of scale and of the flexibility of the support. The added value is turning the cost of regulatory compliance into an investment in the peace of mind of operating correctly, maintaining high standards of personal data protection over time.