Personal Data Protection


Personal data is any information that can identify a specific person: a name, an email address, a phone number, an IP address, a photograph, location data, purchase history or even a cookie identifier.
Almost every company processes personal data every day — when hiring an employee, signing a client contract, sending a newsletter, installing security cameras, or simply running a website.
Personal data protection is the set of legal and organisational measures that ensure this data is collected on a valid legal basis, used only for the stated purpose, kept no longer than necessary, and protected against unlawful access.
What data protection covers
Establishing a legal basis for processing and managing consents
Informing people clearly about how their data and cookies are used
Internal company rules on who may process personal data and how
Data protection when working with IT, accounting, marketing and AI service providers
Handling people’s requests to access, correct, erase or transfer their data
Acting on a data breach, loss or other security incident
Transferring data outside the EU securely and lawfully
Data protection risks usually arise from everyday actions and decisions.
These are exactly the things that turn into customer complaints, inspections by the data protection authority, reputational damage, and disputes in which the company has nothing to support its actions.
Well-kept documents are not bureaucracy — they are proof that the company acted responsibly.
What we prepare
We tailor documents to your business — we do not fill in a template.
External documents
- Privacy policy
- Cookie policy and assessment of your cookie consent solution
- Website / e-shop terms of use
- Consumer sales and service terms
- Direct marketing and newsletter consent procedures
- Rules for games, promotions and prize draws
Internal documents
- Personal data processing rules
- Records of processing activities (ROPA)
- Employee data processing and information documents
- Video surveillance procedure and information signs
- Procedure for handling data subject rights
- Data breach management procedure
- Rules on the use of artificial intelligence in the company
- Confidentiality and data access procedure
Contracts and assessments
- Data processing agreements and annexes with suppliers
- Joint controller agreements
- Assessment of transfers outside the EU and standard contractual clauses
- Data protection impact assessment (DPIA)
- Review of existing contracts and related documents
Service fee from EUR 200 + VAT
How we work
Initial call
Analysis
Documents
Implementation
What to expect
30+ years of experience
Plain language
No templates
The bigger picture
Languages
Service provided by
Your specialist in this field

„Explains complex intellectual property matters clearly and practically.”
Martynas Šukevičius
Patent Attorney · Associate Lawyer
Frequently asked questions
Answers to the questions we are asked most often about personal data protection.
Yes. Obligations depend not on the size of the company but on what data you process and to what extent. For a small company the set of documents is simply simpler.
No. A privacy policy has to reflect your own data flows, purposes and suppliers. Someone else’s policy usually describes activities you do not carry out — and stays silent about the ones you do.
Not every company does. We assess whether your activities fall under Article 37 of the GDPR and give you a clear answer.
Yes. Using AI raises additional questions about data transfers, confidentiality and information duties — we prepare separate rules on the use of AI.
A standard package takes about 1–2 weeks from receiving the information.