Let's chart the right path to follow together
The European Regulation EU 679/2016 (GDPR) on the protection of personal data, together with national regulations and provisions, imposes on organizations a constant process of organizational and procedural adaptation.
We analyze and verify the processes in use, to evaluate the actions to be taken to correct and implement them, implementing an integration plan with the technical and organizational security measures necessary to obtain regulatory compliance.
Regulatory compliance
We provide consultancy for all those services necessary to achieve compliance with the GDPR and related regulations.
Analysis and editing for:
- Privacy Policy
- Information regarding personal data management
- Register of Data Controller/Data Processor
- Drafting of DPIA
- Privacy Risk Assessment Enisa/ISO 27001
- Privacy Analysis by Design/Default
- Management and appointment of Authorized Persons for Processing
- Data Breach Procedure and Register
- Procedure for management of the rights of interested parties.
- Procedure for AdS - System Administrators management
Our services are carried out by consultants with over ten years of expertise in the field of privacy and processing of personal data, certified by TUV.
Training
The GDPR provides that anyone "[...] who has access to personal data shall not process such data unless instructed to do so by the data controller [...]".
Among other things, it is worth remembering that the principle of accountability imposes on the Data Controller a new approach to the training obligation, more formal and structured as it is unavoidable to have to approve in writing the annual training plan for those in charge of processing.
We take care of the drafting and implementation of an adequate training plan, to be submitted to the approval of the Data Controller or the designated Manager, and of the courses for the subjects involved in the data processing process, with the issuing of the relevant certification regarding participation in the course.
DPO - RPD
It is a professional figure with legal, IT and management skills, whose task is to observe, evaluate, advise and verify that personal data processing activities (and therefore their protection) within an organization are implemented. correctly, in compliance with the principles indicated in the art. 5 of EU Regulation 2016/679.
When the person who holds this role operates autonomously and is given decision-making power in carrying out his duties, he is called a Data Protection Officer (DPO), or Data Protection Officer (RPD).
We offer this service with competence and professionalism to various organizations of various nature and size.
Interested in the service?
Let us know exactly your needs so we can provide you with the ideal solution. Tell us what you need and we will do our best to help you.