Information security compliance, security governance and policies, gap assessments, DORA, NIS2, vendor risk and incident governance.
Practice area 05
Privacy & Data Protection
Privacy compliance built around how your business actually uses personal data — defensible to supervisory authorities, and workable for product, marketing and engineering teams.
Discuss your matterTypical deliverables
- Data map and records of processing
- Privacy notices and policy set
- DPIAs for high-risk processing
- Data processing and transfer agreements
- Audit report and remediation plan
- Breach response procedure
Overview
Why it matters
Regulated digital businesses process personal data at scale: identity documents, payment data, behavioural data and, often, data about vulnerable customers. The same data sits at the centre of AML, fraud and marketing processes, which makes privacy compliance a structural question rather than a matter of publishing a policy.
We build privacy programmes from a map of what data you hold, why you hold it and where it goes. Where the GDPR applies, we implement its requirements in full; elsewhere, we work to the data protection law that governs your processing and coordinate local advice where it is needed.
Scope
What we do
- 1.
Privacy Compliance
A privacy compliance programme covering governance, lawful bases, notices, individuals' rights, retention and vendor management, sized to the business.
- 2.
GDPR Compliance
Implementation of the GDPR for EU operations and for businesses outside the EU that offer services to, or monitor, individuals in the EU.
- 3.
Privacy Policies & Notices
Privacy notices, cookie notices and internal policies written for the processing you actually carry out.
- 4.
Data Processing Agreements
Controller–processor and joint controller agreements, and the data protection terms in commercial contracts.
- 5.
Data Protection Impact Assessments (DPIA)
Impact assessments for high-risk processing, such as large-scale monitoring, profiling or the use of new technologies.
- 6.
Data Mapping
Mapping personal data across systems, vendors and group entities as the foundation for records, notices and transfers.
- 7.
Records of Processing Activities (ROPA)
Records of processing activities kept in a form supervisors can review and your team can keep current.
- 8.
International Data Transfers
Transfer mechanisms and transfer impact assessments for personal data leaving the EEA or other restricted jurisdictions, including within the group.
- 9.
Privacy Compliance Audits
Independent review of the programme against the applicable law, with findings prioritised by risk.
- 10.
Data Breach / Incident Support
Breach assessment, notifications to supervisory authorities and individuals, and remediation — working to statutory notification deadlines.
Jurisdictions
Supported across jurisdictions
Privacy & Data Protection is one of our cross-jurisdiction capabilities: we support it for businesses across the jurisdictions in our directory. What the law requires, and how the work is delivered, differs between jurisdictions; where local qualification is required, we coordinate locally qualified counsel.

- Europe18
- Asia & Middle East4
- Americas & Caribbean11
- Africa & Indian Ocean6
Industries
Where we apply it
- iGaming & GamingB2C operators, B2B suppliers, platforms, aggregators and affiliates.

- Fintech & PaymentsPayment and e-money institutions, PSPs and acquirers, payment facilitators and embedded finance.

- Crypto & Digital AssetsCASPs and VASPs, exchanges, custodians, wallets, token projects and crypto payments.

- Forex & InvestmentsForex and CFD brokers, investment firms, trading and investment platforms.

- Digital Platforms & MarketplacesOnline marketplaces, platform operators and intermediary business models.

- Technology BusinessesSoftware, SaaS, data-driven and ICT businesses operating across borders.

- High-Risk & Regulated Digital BusinessesBusiness models that banks, payment providers and regulators treat with enhanced scrutiny.

Questions
Frequently asked
Does the GDPR apply to us if we are not established in the EU?
It can. The GDPR applies to businesses outside the EU that offer goods or services to individuals in the EU or monitor their behaviour there, and such businesses may also need to appoint a representative in the EU. We assess whether and how it applies before designing the programme.
Do we need a data protection officer?
A DPO is mandatory in defined cases — for example, where core activities involve regular and systematic monitoring of individuals on a large scale. Many regulated digital businesses fall within those cases, so we assess the question against your actual processing.
How do AML obligations fit with data protection?
AML rules require you to collect and keep data that privacy law requires you to minimise and protect. The two are reconciled through clear lawful bases, retention schedules and access controls, which we design together with your AML framework.
Related
Related practice areas
AML/CFT programmes, MLRO-as-a-Service, independent AML/CFT audits, risk assessments, monitoring, sanctions and inspection support.
Platform, white-label, B2B supply, SaaS, affiliate and outsourcing agreements drafted for regulated environments.
Regulatory, business model, perimeter, payment, gaming, crypto-asset and cross-border opinions for banks, partners and investors.
Discuss your matter with a senior advisor.
Share a few details about your business and plans. We will come back to arrange a confidential initial conversation.
