Risk assessment and formal evaluation on existing Privacy and Compliance Programs and Regulatory requirements:
Review and evaluation of the existing Privacy and Compliance Programs, policies and Regulatory issues of your company, your websites, your mobile applications, communications systems, cloud storage solutions, etc., in order to assess the risks or gaps resulting from your activities, your geographical scope, the types of personal data you collect and process and any applicable regulations that might affect your business, such as Privacy, Compliance and any other regulations on your sector (i.e.: banking, pharma, telecoms regulations, etc.).
The risk assessment and evaluation can be set up to be conducted periodically, to document the level of maturity and compliance with the applicable regulations and test the programs and their implementation, establishing the necessary processes to embed Privacy, Compliance and Regulatory into the normal business activities of all departments of your company and your communications to the public through your websites or mobile apps.
Planning the implementation of a Privacy and/or Compliance Program and Regulatory requirements or development of the existing Programs:
Should there not be an existing formal Privacy Program, designing and implementing a Privacy Program adapted to your size and needs, establishing the necessary steps, phases, deadlines for the implementation and documenting each step of the way.
Additionally, assessment of your needs regarding the Compliance Program and any other Regulatory matters, to create a fully compliant environment for your business, your websites, your mobile applications, communications systems, cloud storage solutions, etc.
And, as the necessary complement to the design and implementation of such program/programs, preparation of trainings for your staff in all Privacy, Compliance and Regulatory matters, with ad hoc content depending on their roles and responsibilities within the business (i.e.: Whistleblowing, fair and correct use of devices, how to behave during a dawn raid by any regulatory authority, data incident and data breach reporting and reacting, how to mitigate insider threats, basic privacy and compliance knowledge for your sector of activity, role and location, etc.).
In case there´s already a Privacy Program, after having assessed it, highlighting the priority areas to implement/enhance/develop and configuration of the roadmap to continue with the Program.
Assessment on your additional needs regarding your existing Compliance Program and Regulatory matters and preparation of the necessary trainings for your staff, with ad hoc content depending on their roles and responsibilities within the business.
Update of the Privacy Program and other Compliance/Regulatory requirements:
Periodical review and assessment of the impact on your business activities of any new regulations in the fields of Privacy, Compliance or any other regulations applicable to your sector, evaluating timelines for implementation and training, establishing priorities and determining possible risks.
Privacy-by-Design and Compliance for any projects, products, technologies, systems or enterprises you might want to carry out/launch:
Privacy, Compliance and Regulatory assessment for any projects, products, technologies, systems or enterprises that you are planning on creating, implementing or commercializing, so that they are compliant with any applicable regulations from the beginning. Participation in meetings with the responsible developing team, negotiating any agreements with third parties, assessing on obtaining any regulatory permits/licenses, trainings for staff and users, etc.