Personal Data Protection

We prepare the documents the GDPR requires — from your privacy policy to internal procedures. Clear, practical and tailored to how your business works.
What is personal data protection?

Personal data is any information that can identify a specific person: a name, an email address, a phone number, an IP address, a photograph, location data, purchase history or even a cookie identifier.

Almost every company processes personal data every day — when hiring an employee, signing a client contract, sending a newsletter, installing security cameras, or simply running a website.

Personal data protection is the set of legal and organisational measures that ensure this data is collected on a valid legal basis, used only for the stated purpose, kept no longer than necessary, and protected against unlawful access.

What data protection covers

Establishing a legal basis for processing and managing consents

Informing people clearly about how their data and cookies are used

Internal company rules on who may process personal data and how

Data protection when working with IT, accounting, marketing and AI service providers

Handling people’s requests to access, correct, erase or transfer their data

Acting on a data breach, loss or other security incident

Transferring data outside the EU securely and lawfully

Data protection risks usually arise from everyday actions and decisions.

The GDPR applies to every company regardless of size — a small business is held to the same principles as a corporation. In practice, however, problems start in ordinary places: a privacy policy copied from someone else, a cookie banner that collects consent only formally, an IT supplier contract with no data processing terms, an employee uploading a client list into an AI tool.

These are exactly the things that turn into customer complaints, inspections by the data protection authority, reputational damage, and disputes in which the company has nothing to support its actions.
Well-kept documents are not bureaucracy — they are proof that the company acted responsibly.

What we prepare

We tailor documents to your business — we do not fill in a template.

External documents

For clients and website visitors
  • Privacy policy
  • Cookie policy and assessment of your cookie consent solution
  • Website / e-shop terms of use
  • Consumer sales and service terms
  • Direct marketing and newsletter consent procedures
  • Rules for games, promotions and prize draws

Internal documents

For the company and its employees
  • Personal data processing rules
  • Records of processing activities (ROPA)
  • Employee data processing and information documents
  • Video surveillance procedure and information signs
  • Procedure for handling data subject rights
  • Data breach management procedure
  • Rules on the use of artificial intelligence in the company
  • Confidentiality and data access procedure

Contracts and assessments

For relationships with suppliers and partners
  • Data processing agreements and annexes with suppliers
  • Joint controller agreements
  • Assessment of transfers outside the EU and standard contractual clauses
  • Data protection impact assessment (DPIA)
  • Review of existing contracts and related documents

Service fee from EUR 200 + VAT

How we work

01

Initial call

We find out what data you process and why, and which tools and suppliers you use.
02

Analysis

We review your existing documents, website and contracts, and identify gaps and risks.
03

Documents

We prepare documents tailored to your business.
04

Implementation

We explain how to apply the documents in practice, train your team and answer questions.

What to expect

30+ years of experience

We have worked in business and intellectual property law since 1992.

Plain language

We write documents so that non-lawyers can understand them.

No templates

We adapt solutions to your real processes.

The bigger picture

We look at data protection together with intellectual property, advertising and AI regulation.

Languages

We advise in English, Lithuanian and Russian.

Service provided by

Your specialist in this field

Specialises in intellectual property, contract and data protection law. Delivers training and seminars for businesses and the public sector, and lectures in law at university.
⭐⭐⭐⭐⭐ LEGAL 500 · LITHUANIA · 2025

Martynas Šukevičius

Patent Attorney · Associate Lawyer

Frequently asked questions

Answers to the questions we are asked most often about personal data protection.

Does the GDPR apply to a small company as well?

Yes. Obligations depend not on the size of the company but on what data you process and to what extent. For a small company the set of documents is simply simpler.

No. A privacy policy has to reflect your own data flows, purposes and suppliers. Someone else’s policy usually describes activities you do not carry out — and stays silent about the ones you do.

Not every company does. We assess whether your activities fall under Article 37 of the GDPR and give you a clear answer.

Yes. Using AI raises additional questions about data transfers, confidentiality and information duties — we prepare separate rules on the use of AI.

A standard package takes about 1–2 weeks from receiving the information.

CONTACT US

Have questions?

CALL US

WRITE TO US

WORKING HOURS

Mon–Fri 8:00-17:00

Fill out the form

We will contact you within 1 business day

Contact form