Compliance and regulation

GDPR and LSSI

Data protection and compliance with information society services regulation.

What it involves

What we do

We bring processing activities, contracts, policies and technical measures into line with the GDPR and the LOPDGDD, and review LSSI compliance (cookies, commercial communications, legal notices) for websites and applications.

What's included

  • Record of processing activities
  • Data protection impact assessments (DPIA) and risk analysis
  • Policies, clauses and data processor agreements
  • Management of data breaches and data subject rights
  • Cookie and consent compliance (LSSI)
  • Compliance audit and training

Who it's for

  • Any organisation that processes personal data
  • Websites and applications with users and digital marketing
  • Sectors handling special categories of data (health, finance)

Deliverables

  • Record of processing activities
  • DPIA
  • Legal texts and contracts
  • Audit report

Reference frameworks and standards

GDPRLOPDGDDLSSI-CEISO 27701

Reference frameworks used to design, implement, review and evidence. They are not presented as our own certifications unless contractually applicable.

How we approach it

  1. DiscoverWe get to know your business, environment, risks and priorities.
  2. AnalyseWe assess maturity, exposure, compliance and real capabilities.
  3. DesignWe define strategy, roadmap, architecture and action plan.
  4. ImplementWe deliver controls, processes, technology and evidence.
  5. OperateWe monitor, respond and support continuous improvement.
  6. OptimiseWe measure results, reduce risk and evolve capabilities.

Let's talk

Does GDPR and LSSI fit your situation?

Tell us about your challenges and let's design together the best strategy to protect and strengthen your business.