Services – data protection

Go to content

Data protection

Conducting almost any type of business involves processing of personal data, which requires compliance with a range of regulatory standards. These regulations establish the permissible scope of data processing, and violating them can generate significant negative legal and reputational consequences.

We advise clients in relation to data protection breaches and represent them in administrative proceedings before the Personal Data Protection Office and the administrative courts.

We provide comprehensive support on the EU’s General Data Protection Regulation and other data protection provisions. We conduct audits of GDPR compliance as well as audits on the use of cookies and other tracking technologies. We help clients prepare responses to requests from data subjects submitted under the GDPR (e.g. concerning exercise of the right to access or copy their data).

We draft contracts for processing and accessing personal data. We also draft internal documents ensuring that clients’ operations comply with data protection laws (e.g. data protection policies, privacy policies, cookies policies, and other documents and informational clauses to ensure transparency in processing of personal data).

We advise on transfers of personal data to countries outside the European Economic Area, including drafting of data transfer agreements.

We assist in conducting data protection impact assessments.

We support clients with regard to inspections by the data protection authority.

We conduct training for our clients on protection of personal data.

We assist clients in drafting documentation for job candidates and employees (including informational clauses, consents to processing of data, authorisations to process data, monitoring policies, and data protection policies for remote work).

We advise on arrangements for intra-group flows of HR data.

We advise on personal data issues in internal investigations.

We assist in handling employees’ requests under the GDPR (e.g. for access to their data).

We conduct audits of M&A targets for compliance with data protection requirements.

We advise on M&A-related issues such as the permissibility of sharing certain data for purposes of the transaction or the possibility of using certain data post-closing.

We assist in structuring transactions so that the timetable appropriately reflects data issues.

We assist in drafting transactional documentation concerning personal data, governing such issues as:

  • Liability for potential breaches
  • The manner of transferring or accessing personal data
  • Processing of data during the period after closing but before operational consolidation of acquired assets into the buyer’s structure, systems and practices.

We advise on the targeting of marketing content, such as newsletters, telemarketing and mailings, to individual recipients.

We support clients in drafting documentation for use in contests, loyalty programmes, and other such initiatives.

We negotiate and draft contracts for clinical trials and the flow of data between the sponsor, the investigator and the hospital, as well as the related informational clauses.

We advise on issues of access to medical documentation.