Behind every item of data there is a person. Behind every act of processing, a responsibility.
The Firm assists companies, groups and public bodies in the governance and protection of personal data across the entire lifecycle of the processing, and assists individuals in the protection of their own rights. The practice is organised along five main lines.
Governance and organisational design
Definition of the organisational arrangements, roles and procedures by which data are collected, managed, shared and retained; design of the safeguards required by the GDPR and the Italian Data Protection Code; record of processing activities, appointments and instructions to authorised persons, internal policies and their updating.
Compliance and regulatory duties
Impact assessments and analysis of the lawful basis for processing; contracts with suppliers and platforms; transfers to third countries; marketing and tracking technologies; the processing of employee data and video surveillance.
DPO, advice and training
Data Protection Officer appointments with national and multinational companies; ongoing or project-based advice supporting the controller and the in-house DPO; training of staff and management, in compliance with statutory obligations.
Critical events, inspections and litigation
Handling of data breaches, from the risk assessment through to notification and communication to data subjects; inspections and enforcement proceedings; defence before the Italian Data Protection Authority and before the courts; damages litigation.
Protection of the individual
Exercise of data subject rights — access, erasure, objection, portability — against companies, public bodies and platforms; de-indexing and the right to be forgotten; complaints to the Italian Data Protection Authority and applications to the courts; compensation for damage caused by unlawful processing.