Data privacy
GDPR documents should describe real data flows, not a generic model.
Privacy documents are useful only if they reflect what the company actually does: what data it collects, why, through which suppliers, where the data goes and who is responsible.
Common documents
Privacy policies, cookie policies, data processing agreements (DPAs), supplier clauses, notices and records of processing activities. Each document should reflect what the company actually does, not a generic template copied from the internet.
The parties roles
Before drafting documents, we establish who is the controller and who is the processor. Getting the roles wrong affects everything else: instructions, obligations, liability and supplier agreements. In a SaaS relationship, for example, the customer is usually the controller and the provider the processor.
Digital projects
Websites, newsletters, analytics, SaaS, CRM, marketing tools, software applications and processor contracts. For digital products, privacy documentation should be connected to the product and the contracts from the design stage.
Transfers and sub-processors
Many companies use hosting, analytics or support vendors located outside the Union. International transfers and the chain of sub-processors must be regulated and documented, with the safeguards that apply to each flow.
Practical approach
We start with the data-flow map and build documents around the company real operations, so they hold up to questions from enterprise customers and authorities.
FAQ
Is a DPA required with every supplier?
Not with every supplier, but with suppliers processing personal data as processors or in roles that require clear contractual regulation.
Does Google Analytics require consent?
Analytics should usually be assessed together with the cookie banner, technical settings and user notice.
Do I need a privacy policy without a database?
Yes, if the website collects data through forms, analytics or newsletter signups. Even without a classic database, there are processing activities that must be disclosed correctly.
Who is controller and who is processor?
The controller decides the purposes and means of processing; the processor acts on the controller behalf. The roles depend on the concrete situation and should be analysed, not assumed.