Skip to content
Illustrative image for the firm's data protection & gdpr practice

Data Protection & GDPR

GDPR compliance, international data transfers, breach response, DPO support and dealings with supervisory authorities.

Eight years after the GDPR took effect, enforcement has become specific: transfers, cookie consent, retention and the security of processors. We advise controllers and processors on compliance that can be evidenced, and we act for clients in front of the Belgian Data Protection Authority, the Autoriteit Persoonsgegevens and the Garante.

What this area covers

  • Records of processing, retention schedules and privacy notices
  • Data processing agreements, joint controller arrangements and vendor review
  • International transfers: adequacy, standard contractual clauses and transfer impact assessments
  • Data protection impact assessments for high-risk and AI-assisted processing
  • Breach assessment, 72-hour notification and data subject communication
  • Data subject access, erasure and objection requests, including difficult ones

Situations clients bring us

You have had a data breach

The seventy-two hour clock starts at awareness, not at the end of your investigation. We help you assess notifiability, prepare the regulator notification and any communication to affected people, and document the decisions taken.

You are using a US or non-EU service provider

We advise on the lawful transfer route, prepare or review the clauses and the transfer impact assessment, and identify where a provider's terms do not match what the GDPR requires of a processor.

A supervisory authority has opened an investigation

We handle correspondence, prepare the evidence file and represent you in proceedings and, where appropriate, negotiate on measures rather than litigating a fine that will hold.

How we work

  • Compliance work sized to your actual risk, not a template programme for a bank.
  • External DPO and retained advice arrangements for organisations without in-house capacity.
  • Plain-language documentation your staff can follow without a lawyer present.

The European dimension

Where cross-border practice makes the difference

The GDPR is a single regulation applied by twenty-seven supervisory authorities with different priorities and procedures. Where the lead authority sits, and how the one-stop-shop mechanism applies to your group, materially affects both risk and process. With Brussels, Amsterdam, Luxembourg, Milan and Málaga offices we deal with several of those regulators regularly.

Questions about data protection & gdpr

Talk to a lawyer about data protection & gdpr

An initial consultation of up to forty-five minutes is charged at a fixed fee of €150 excluding VAT, and waived where we go on to act for you on the same matter.