Practice areas
Data privacy
Documentation, reviews and contracts for personal data processing in commercial and digital projects.
Perspective
Advice adapted to how the company makes decisions.
Data privacy should be treated as part of how the company operates, negotiates and accepts risk. It is not enough for documents to be formally correct; they must be usable by directors, founders, management, investors or international teams at real decision points.
Practical privacy support for websites, digital services and business operations. In practice, this means clarifying signing authority, approvals, party relationships and the risks that should be solved before they become commercial blockers.
We frequently work on privacy and cookie policies, dPAs and supplier clauses, processing activity mapping, privacy risk in digital projects, support for data subject requests. Each matter is calibrated to the commercial stakes: sometimes the client needs a precise review, while in other cases the project requires a complete structure that can stand up to negotiation, audit, financing or international implementation.
For foreign clients, we explain Romanian law in a format that can be integrated into a wider project. For Romanian companies, we translate legal risk into business options, timing, documents and concrete next steps.
The objective is a clear legal position: what can be done, what should be avoided, which documents are needed and where negotiation matters. This reduces uncertainty and helps the company make decisions without turning law into an operational brake.
How we work
From context to documents that can be used.
We begin with the commercial objective, the party structure and the real constraints of the matter.
Material risks are separated from legal noise, with options and consequences explained clearly.
We prepare documents that can be used in negotiation, signing, implementation or internal reporting.
We coordinate next steps with management, tax advisers, external counsel or local collaborators.
When clients usually call us
- the website collects data
- analytics, CRM or newsletter tools are used
- suppliers process personal data
- a digital product is launching or expanding
Typical work product
- privacy and cookie policies
- DPAs and supplier clauses
- processing maps
- notices and data subject response support
Selected matter types
Situations where we are often involved
- Privacy and cookie policies
- DPAs and supplier clauses
- Processing activity mapping
- Privacy risk in digital projects
- Support for data subject requests
Services
How we help
Privacy and cookie policies
DPAs and supplier clauses
Processing activity mapping
Privacy risk in digital projects
Support for data subject requests
FAQ
Do we need a privacy policy without a database?
Yes, if the website collects data through forms, analytics or newsletter signups.
Can you adapt documents for a SaaS company?
Yes. Documents should reflect the product, party roles and real data flows.