GDPR and Personal Data Protection
The firm provides legal support in aligning business operations with personal data protection rules, including analysis of data flows, definition of legal bases and purposes of processing, drafting of privacy policies, internal acts, processor agreements, notices to data subjects and other documents needed for transparent and responsible processing. Particular attention is paid to practical implementability of compliance. Documents must not remain mere formality but must correspond to actual processing, tools, organisation of work, retention periods and responsibilities within the company or organisation.
- analysis of personal data processing and records of processing activities
- privacy policies and notices to data subjects
- contracts with processors, other controllers and joint controllers
- internal policies, procedures and templates
- processing of employee, candidate and business contact data
- cookies, web forms and digital tools
- impact assessments and risk management where required
- handling data subject requests and communication with supervisory authorities
Compliance is implemented according to the actual situation, not generic templates. The first step is to understand which data are processed, for what purpose, who has access, how long they are retained and what legal basis exists for processing.