
Personal data, GDPR and cybersecurity
We bring data processing into line with the GDPR and the Law of Ukraine «On the Protection of Personal Data»: audit of the processes, legal grounds, the roles of controller and processor, the DPO. We draft privacy policies and contracts with processors, structure cross border transfers, support data leaks and cyber incidents, and audit IT systems.
Personal data protection compliance
Audit of data processing and bringing it into line with the GDPR and the Law of Ukraine «On the Protection of Personal Data»: legal grounds for processing, records, the roles of controller and processor, the DPO.
Regulation in the field of personal data protection has become one of the key factors of trust in a business. Failure to meet the requirements of the law may lead not only to significant financial sanctions but also to the loss of reputation and of partner relations.
The PROCTOR team carries out a comprehensive audit of personal data processing, analysing information flows, international transfers of data, internal policies, contracts with counterparties and technical means of protecting information.
We help companies build a personal data management system that meets Ukrainian law, the requirements of the GDPR and international information security standards.
Privacy and data processing policies
Drafting of a privacy policy, a cookie policy and data processing notices for websites, applications and internal company processes - clear to users and able to withstand a check by the regulator.
Data processing agreements (DPA)
Conclusion of data processing agreements with contractors and cloud providers: allocation of liability, standard contractual clauses (SCC) for cross border transfers, audit of processors.
Response to data breaches
Legal support of incidents: assessment of the scale and the risks, notification of regulators and data subjects within the set deadlines, minimisation of fines and reputational consequences.
Cross border transfers of data
Structuring lawful transfers of personal data abroad: adequacy decisions, SCC, binding corporate rules for international groups.
Legal support of cyber incidents
Legal support during cyber attacks, ransomware and compromise of systems: interaction with CERT-UA and law enforcement, preservation of evidence, claims against those responsible, insurance payouts.
Compliance audit of IT systems
Checking IT products and internal systems for compliance with the requirements of data and cybersecurity legislation, in particular for critical infrastructure and the financial sector.
How a data project runs
From a map of the data flows to documents in use and readiness to answer an incident within the set deadlines.
01
Map of data flows
We work out what data the company collects, where they are stored and to whom they are passed. The client receives a record of processing and a list of non compliances with priorities.
02
Grounds and roles
We set the legal ground for each process and fix the roles of controller and processor inside the group and in relations with contractors. Where needed we appoint a DPO.
03
Documents and contracts
We draft the privacy policy, the cookie policy, notices to users, internal regulations, DPAs with contractors and SCCs for transfers abroad.
04
Putting procedures in place
We set the processes to match the documents: the order of answering requests from data subjects, the separation of access to information, briefing for the staff who work with data.
05
Readiness for an incident
We write the scenario of the first 72 hours: who does what, whom we notify, how the evidence is preserved. After that we support real data leaks and cyber attacks.
Ways we work on data protection
The scope depends on whether one document is needed, a full compliance project, or standing support of the function.
A single document
One privacy policy, a DPA, or a set of SCCs for a particular transfer of data. A finished document for your processes, not a template copied from another website.
Full compliance project
Bringing data processing into line with the GDPR and Ukrainian law: the audit, the grounds, a set of documents, procedures put in place and briefing for the staff responsible.
Standing support
An external data protection function: review of new products and contractors, updates to policies, handling of requests from the regulator, response to leaks and cyber incidents.