Security & IntelligenceData privacy
Data privacy under GDPR and US state laws, put into practice
For companies in the US, Italy and the rest of the EU that handle personal data of customers, employees or users. We map your data, write clear privacy notices and policies, set up records, retention and request procedures, and train your staff. Your lawyer keeps the legal side, we handle the practical one.
- GDPR and US laws
- Italy and the EU, California and other states
- Clear documents
- notices and policies in plain language
- With your lawyer
- we handle the practical, technical side
Which data, why and for how longRecords of processing · first draft
- Website contact formreplies to requests · kept 24 months OK
- Payroll and HR filesemployment contract · HR only OK
- Security camerasdeleted after 72 hours · sign at entrance Notice
- Newsletter listconsent records missing Fix
- CVs not hired
- 12 months
- Camera footage
- 72 hours
- Invoices
- 10 years
- Form messages
- 24 months
Example · not a real system
01When to call us
Personal data everywhere, rules nobody wrote down
Customer lists, CVs, payroll, camera footage, website forms. Personal data ends up in many places, and the rules about it are rarely written down.
A privacy policy copied from somewhere
It does not describe what you really do with data, and nobody has updated it in years.
Data with no owner and no end date
Old customer records, CVs and backups kept forever, “just in case”.
A data request and no procedure
A customer asks what data you hold about them. Who answers, and by when?
Customers on both sides of the Atlantic
GDPR in Italy and the EU, state laws like the CCPA in California. Different rules, one company.
02What we do
Clear records, clear notices, trained people
We start from how your company really works, not from a template. Then we turn it into documents your staff can follow and your customers can understand.
- Data mapping and records of processing
- Privacy notices for website, customers and staff
- Internal privacy and retention policies
- Procedures for access and deletion requests
- Checks on suppliers who handle your data
- A data breach procedure, ready in advance
- Technical measures: access, encryption, backups
- Staff training and ongoing support
Your privacy work, step by stepChecklist agreed with management
- Records of processing
- Website privacy notice
- Staff privacy notice
- Training for HR and sales
- Retention scheduleHR files kept too long
- Breach procedure tested
- INFOAccess request by email
- OKIdentity confirmed
- OKData gathered: CRM, mail
- OKReply sent and logged
03Italy, EU and US
GDPR and US state laws, side by side
With customers or staff on both sides of the Atlantic, you need one way of working that respects both. We help you find the common ground and handle the differences.
Italy and the EU
GDPR
One regulation across the EU. In Italy, the Data Protection Authority (Garante) adds guidance and checks.
- A legal basis for each use of personal data
- Records of processing and privacy notices
- Breaches reported to the authority within 72 hours when required
- Requests from individuals answered within one month
United States
State privacy laws
There is no single federal privacy law. California’s CCPA, as amended by the CPRA, and similar laws in other states set the rules.
- A notice at the point of collection
- Rights to know, delete and correct personal information
- An opt-out from the sale or sharing of personal information
- Requests answered within 45 days in California
We are not a law firm. We do the practical, technical and organizational work. Legal opinions and final decisions stay with you and your lawyer, and we are glad to work alongside them.
04What is included
Privacy work, item by item
Most companies need a bit of everything, in proportion to the data they handle. We start where the gaps are biggest.
Data mapping
What personal data you hold, where it lives, why and who can see it.
- Interviews with each department
- Records of processing
- Data flows to suppliers and abroad
Policies and notices
Documents in plain language that match what you really do.
- Website privacy and cookie notices
- Notices for customers and staff
- Internal privacy and retention policies
Requests from individuals
A simple procedure when someone asks to see or delete their data.
- Who answers and by when
- Identity checks
- Reply templates and a request log
Technical measures
The protections that make the paperwork true.
- Access rights and two-factor authentication
- Encryption and tested backups
- Retention and secure deletion
Breach readiness
A plan to follow if personal data is lost or exposed.
- Who decides and who informs whom
- Notification deadlines under each law
- A breach register
Training and support
People who know what to do, and someone to ask.
- Short sessions for each role
- Practical answers to daily questions
- Periodic reviews as things change
05How we work
From scattered data to a privacy program that holds
We work with the people who handle the data every day, so documents describe real practice.
-
Map
We talk to each department and list the personal data you handle, where it lives and why.
Interviews, not forms -
Find the gaps
Missing notices, unclear access, data kept too long. We list them in order of risk.
Ranked by risk -
Write and set up
Policies, notices, procedures and technical measures, reviewed with your lawyer where needed.
Your lawyer decides -
Train and maintain
Training for staff and a periodic check, so documents stay true over time.
In English or Italian
06Questions
Privacy questions, plain answers
If your question is not here, write to us. A real person reads every message and replies by email.
General information, not legal advice. What applies to your company depends on your situation. Your lawyer has the final word.
Are you lawyers? Do you give legal advice?
No. We are a technical and organizational partner. We map data, write practical documents, set up procedures and protections and train staff. Legal opinions stay with you and your lawyer, and we are happy to work with them.
Does GDPR apply to a US company?
It can. GDPR may apply to a company outside the EU that offers goods or services to people in the EU or monitors their behavior. We help you see where your data comes from, so your lawyer can confirm what applies.
Which US laws do you work with?
We work with the California Consumer Privacy Act (CCPA), as amended by the CPRA, and with similar laws in other states. The rules differ from state to state, so we start from where your customers and staff are.
Do we need a Data Protection Officer?
Under GDPR some organizations must appoint one, for example public bodies or companies whose core work involves large-scale monitoring or sensitive data. We help you gather the facts. The decision is yours, with your lawyer.
Can you also handle the technical side?
Yes, and that is where we are strongest. Access rights, encryption, backups, secure hosting and secure deletion are all part of the same team’s work.
Want privacy documents that match what you really do?
Tell us where your customers and staff are and what data you handle. We reply by email with a practical first step, in English or Italian.