GDPR compliance
GDPR compliance is a legal obligation for all companies and professionals that collect, use, store or process personal data. Complying with Regulation (EU) 2016/679 (GDPR) contributes to protecting the rights of data subjects, reducing the risk of sanctions and conducting business in accordance with the legislation on the protection of personal data.
GDPR compliance involves implementing legal documentation adapted to the activity carried out and adopting the measures necessary for the lawful processing of personal data. The documentation may include privacy policies, cookie policies, website terms and conditions, GDPR information notices, data processing agreements (DPAs), as well as other internal policies and procedures necessary to comply with the obligations provided for by the Regulation.
Each document must be drafted according to the field of activity, the types of data processed, the way it is collected and used, and the existing relationships with clients, employees, collaborators and contractual partners. Using standard templates or documents that are not adapted to the activity may lead to a failure to meet legal obligations and to exposing the company to legal risks and sanctions.
Properly drafted and updated GDPR documentation makes it easier to demonstrate compliance during inspections carried out by the competent authorities, helps to comply with legal obligations and provides the company with a clear framework for processing personal data.
GDPR compliance services
- Privacy policy – The privacy policy is one of the essential documents provided for by Regulation (EU) 2016/679 (GDPR) and is intended to inform data subjects about how personal data is collected, used, stored and protected. The document is drafted according to the activity carried out, the types of data processed and the purposes of the processing, being adapted to each company and each website.
- Cookie policy – The cookie policy informs website users about the use of cookies and similar technologies, the types of cookies used, their purpose and the way in which consent options may be exercised, in accordance with the applicable legislation.
- Website terms and conditions – The website terms and conditions set out the rules for using the site, the rights and obligations of users and of the administrator, as well as the conditions applicable to the services provided and the information offered. The document is drafted according to the specific nature of the activity and of the website.
- GDPR information notices – GDPR information notices are drafted to inform data subjects about the processing of personal data, in accordance with the obligations provided for by the GDPR. Their content is adapted to the purpose of the processing, the categories of data subjects and the types of data processed.
- Data processing agreements (DPAs) – Data processing agreements (DPAs) govern the relationships between controllers and processors regarding the processing of personal data. The documents set out the responsibilities of the parties, the security measures and the conditions of processing, in accordance with the requirements of Regulation (EU) 2016/679 (GDPR).
- Other GDPR documents – Depending on the activity carried out, other GDPR documents may be drafted, such as the record of processing activities, internal data protection procedures, procedures for handling security incidents, documents concerning the exercise of data subjects' rights, internal GDPR policies and other documents necessary to demonstrate compliance with the legislation on the protection of personal data.
Frequently asked questions
What is the GDPR and to whom does it apply?
Regulation (EU) 2016/679 (GDPR) applies to all authorised natural persons, companies, associations, foundations and other organisations that collect, use, store or process personal data. The GDPR obligations differ according to the activity carried out and the types of data processed.
When is GDPR compliance mandatory?
Compliance with Regulation (EU) 2016/679 (GDPR) is mandatory whenever a company, authorised natural person, association, foundation or other organisation collects, uses, stores, transmits or processes personal data. The obligations concerning documentation and compliance measures differ according to the activity carried out, the types of data processed and the purposes of the processing.
What GDPR documents must a company hold?
Depending on the activity carried out and the way personal data is processed, a company may need documents such as a privacy policy, a cookie policy, website terms and conditions, GDPR information notices, data processing agreements (DPAs), records of processing activities, internal GDPR policies and procedures, as well as other documents required by the applicable legislation.
Are a privacy policy and a cookie policy mandatory for a website?
Where a website processes personal data and uses cookies or similar technologies, it is necessary to have a privacy policy and a cookie policy drafted in accordance with the provisions of Regulation (EU) 2016/679 (GDPR) and the applicable legislation on electronic communications. These documents must be adapted to the activity carried out, the types of data processed and the way the website collects and uses users' information.
What sanctions can be imposed for failing to comply with the GDPR?
Failure to comply with the obligations provided for by Regulation (EU) 2016/679 (GDPR) may result in corrective measures and administrative fines imposed by the competent authority, depending on the nature and gravity of the infringement. Complying with the obligations on the protection of personal data and preparing compliant GDPR documentation help to reduce legal risks and to demonstrate compliance with the applicable legislation.
When should GDPR documentation be updated?
GDPR documentation must be updated whenever there are changes concerning the company's activity, the way personal data is processed, the implementation of new services or applications, legislative changes or changes to the categories of data processed. Updating the documents periodically helps to maintain GDPR compliance and to reduce legal risks.
Request a legal consultation
Benefit from a clear legal analysis and solutions tailored to your situation.