GDPR is a voluminous and through piece of legislation that came into force on 25th May 2018 and which re-writes the manner in which personal information is collected, shared and processed.  GDPR sets out the new personal data framework by means of an EU Regulation which, unlike EU Directives that are implemented by Member State national laws, are directly effective in EU Member States.  Therefore, business falling with the scope of GDPR should ensure that they have undertaken the necessary steps to be compliant with this important piece of legislation.

Our team has extensive experience in dealing with personal data protection matters.  We regularly give advice and guidance on issues regarding protection of personal data to our customers as well as on practical issues regarding proper practices in promoting their services and handling personal data in order to avoid any complaints from the data subjects.

We are currently handling various mandates for the design and implementation of solutions for compliance with the new Regulation across a wide range of industries.

Our services include drafting of policies and procedures, data mapping exercises and support in the creation of data registers (which are an essential tool in demonstrating compliance with GDPR), establishment and redesign of policies and procedures in respect of processing of personal data, drafting of appropriate consent forms and amending contractual agreements so as to bring themin line with GDPR, support in conducting  a Data Protection Impact Assessment (DPIA), drafting and reviewing Data Processing Agreements (DPA) and training on newly implemented policies and procedures.
We have conducted numerous training exercises on the provisions and practical implementation of GDPR.

Furthermore, we have supported clients in handling data complaints made against them and supported clients in reporting and handling data breach incidents.