Area 02 · Civil law

GDPR, privacy and cookie policy advice

Compliance for companies, professionals and e-commerce: website privacy policy, cookie policy in line with the Italian Data Protection Authority’s guidelines, records, DPIAs. Tailored documents, explained in plain language.

Who it’s for

Who turns to the practice

SMEs and companies

Businesses that process data on customers, employees and suppliers and want sustainable compliance: the essential documents, clear responsibilities, no useless paperwork.

Professionals and firms

Those who handle data on behalf of their own clients — consultants, firms, agencies — and must show they do it properly, starting from the contracts with suppliers.

Websites and e-commerce

Anyone selling or collecting contacts online: website privacy policy, cookie policy, banners and consents that withstand a check, not just the visitor’s eye.

Recurring cases

The problems we solve

  • The website privacy policy is copied from a template and doesn’t describe the actual processing.
  • The cookie banner was set up carelessly and the consent collected may be worthless.
  • A customer or supplier asks you to sign a DPA and it isn’t clear what you’re signing.
  • An email to the wrong recipient, a lost laptop: is it a data breach? Must it be notified to the Authority?
  • A request to access or delete data arrives and there’s no procedure to answer it.

Here too the output is a document: a policy written to measure, a record that describes the actual processing, a procedure to follow when needed.

The services

From the website to the record

GDPR compliance

A review of how the organisation processes data — tools, suppliers, flows — and sustainable compliance: clear priorities, essential documents, no needless bureaucracy.

Notices and policies

Website privacy policy, compliant cookie policy, Article 13–14 GDPR notices for forms, newsletters and customers: written to measure, never photocopied.

Records of processing and appointments

Article 30 record, internal appointments and authorisations, data processing agreements with suppliers (DPAs, Article 28): the documentary structure that withstands an inspection.

DPIAs and data breaches

Impact assessments (Article 35) for high-risk processing; in the event of an incident, assessment of what happened, notification to the Authority (Article 33) and, where required, communication to the individuals affected (Article 34).

Website and e-commerce compliance

Showcase sites, e-commerce and sales funnels: banners only where needed, valid consents, tracking pared back to the essentials, terms and conditions consistent with the actual flows.


Legal references

Regulation (EU) 2016/679 (GDPR); Legislative Decree 196/2003 (Italian Privacy Code); the Data Protection Authority’s guidelines on cookies and other tracking tools (10 June 2021) and further related measures.

Consistency, first of all: this website uses no profiling cookies and no third-party tracking — which is why you see no banner. It’s the same criterion we apply to clients’ projects.

How it works

Three steps, in writing

  1. Request

    You tell us how you work: website, tools, newsletter, suppliers. A couple of lines and the website address are enough.

  2. Analysis

    We map the actual processing — data, flows, suppliers — and identify the gaps against the GDPR; we agree the scope, timing and fee in writing.

  3. Delivery

    You receive ready-to-use documents — policies, notices, record, appointments — and the instructions to keep them current, not shut in a drawer.

Compliance can be complete or limited to single documents; support can be ongoing too — useful when tools and suppliers change often. Everything remotely as well.

Contact

Is your website really compliant?

Send us the website address or a couple of lines about the project: we’ll reply with an honest first assessment.

First reply within one business day. The first contact is free and carries no obligation.