TECHNOLOGY, DATA & AI
Privacy and Data Protection
Privacy work is credible only when it starts with the data the organization actually uses, the people who can access it and the systems and vendors that move it.
THE WORK BEHIND THE DOCUMENT
Start with the decision and the facts.
I help organizations map processing, identify the legal and contractual questions that matter, and turn them into operational documents. A privacy notice drafted without a data map is usually a description of what the business hopes is happening—not evidence of what is happening.
The applicable framework depends on the organization, the people whose data is involved, contractual commitments and the jurisdictions reached by the activity. I do not present general GDPR familiarity as permission to give foreign-law advice without limits. Where local advice elsewhere is needed, I identify the question and coordinate rather than overstate the scope.
TYPICAL MATTERS
- 01 Data mapping, processing inventories and responsibility allocation
- 02 Privacy notices, internal policies and consent language
- 03 Controller-processor terms, vendor review and data-processing agreements
- 04 Cross-border transfer questions and coordination with foreign counsel
- 05 Incident-response preparation, retention and deletion decisions
- 06 Privacy-by-design review for products, websites, employment and marketing
DELIVERABLES
Work product designed to be used.
The work may result in a data map, gap and priority memo, privacy notice, processing agreement, vendor questions, retention schedule, incident checklist or a governance plan with named owners and review dates.
SCOPE & BOUNDARIES
A defined role is part of good advice.
The engagement records the client, jurisdictional scope, deliverables, assumptions, timing and fee basis. Government and judicial fees, VAT, registrations, court representation, foreign-law opinions and third-party specialist work are excluded unless expressly included in writing.
Where another adviser is needed, I identify the question and coordinate the hand-off. General information on this page is not legal advice on a specific matter.
SERVICE FAQ
Questions specific to this work.
Do we need a privacy policy before a data map?
A temporary notice may be necessary, but meaningful drafting should be based on verified processing, vendors and purposes.
Can you make us GDPR compliant?
Compliance is not a one-document outcome. The applicable obligations and my jurisdictional role must be defined before using that label.
Does this include cybersecurity testing?
No. Legal governance and contractual review can be coordinated with technical security assessment, which requires the appropriate specialist.
NEXT STEP
Describe the decision, the parties and the real deadline.
I will review fit, conflicts and the information needed before proposing a scope. Do not send sensitive documents until an engagement and exchange method are confirmed.