Privacy & DPO

Assist data controllers and processors with the governance of personal data and serve as Data Protection Officer on an ongoing and operational basis.

The scope is no longer limited to the GDPR. The same processing activity may now fall under the GDPR, AI Act, and Data Act at the same time: privacy, security, and artificial intelligence must be governed as a single system, not as separate silos.

We also bring a security perspective to the privacy function: we combine the role of DPO with that of Lead Auditor ISO/IEC 27001. This makes it possible to translate legal obligations into verifiable technical safeguards.

What we do

  • DPO appointment — external DPO and support to the internal DPO, with ongoing oversight.
  • Mapping and documentation — records of processing activities, privacy notices, appointments, legitimate interest assessments.
  • Data Protection Impact Assessments (DPIAs) — for high-risk processing activities, including those based on AI.
  • Extra-EU transfers — Standard Contractual Clauses (SCCs) and Transfer Impact Assessments.
  • Data breaches — incident management, notification to the Italian Data Protection Authority, and communication to data subjects.
  • Audits and training — compliance assessments, including an ISO 27001 approach, and training programmes.
  • GDPR — Regulation (EU) 2016/679. The cornerstone: principles, legal bases, data subject rights, accountability, security obligations, and data breach notification requirements.
  • Italian Privacy Code — Legislative Decree 196/2003. As amended by Legislative Decree 101/2018, it integrates the GDPR into the Italian legal framework; the decisions and guidelines of the Italian Data Protection Authority and the EDPB are also relevant.
  • International data transfers. Adequacy decisions and Standard Contractual Clauses, with country-by-country risk assessment (Transfer Impact Assessment).
  • Intersection with the AI Act — Regulation (EU) 2024/1689 and Law 132/2025. Many processing activities feed AI systems: legal basis, transparency, and DPIAs must be coordinated. See the Artificial Intelligence practice.
  • Data Act — Regulation (EU) 2023/2854. Redefines access to and sharing of data, including personal data generated by connected devices.

How we work

Privacy is as much about governance as it is about security. We approach it through the dual lens of legal expertise and auditing, because a compliance measure that cannot withstand technical scrutiny protects nothing.

Would you like to be contacted?


Contact information