Privacy by Design, that does not slow down the launch of a new project

We help companies organise roles, data flows, legal bases, documents and risks before launching a new product, service, process or sales channel. This enables the team to move faster and allows the management board to decide whether to launch the project with greater confidence.

WYZWANIA

the most common problems we solve

The project is ready, but personal data is addressed only at the end The product is developed first, while personal data is left until the end. Suddenly, forms, consents, notices or access permissions in tools need to be changed.

We get involved earlier and put the processing model in order: what you collect, where it goes, who has access and on what legal basis. You receive a clear indication of what is required for launch" and what can wait.

Business benefit: fewer last-minute fixes and a smoother launch.

Risk of inaction: a delayed implementation or rushed changes after launch.

The team is unclear about who is responsible for what At some point, a familiar problem arises: who is the controller, who is the processor and who is responsible for providing information to the user? Without clarity on this, it is difficult to proceed with contracts, policies and communications.

We define roles and responsibilities in practical terms: who is responsible for what, which contractual provisions are needed and how this should be communicated to users.

Business benefit: faster alignment and less passing the issue back and forth between departments.

Risk of inaction: unclear accountability, particularly when an incident occurs or a client raises a question.

The new project uses forms, automation, integrations or profiling A new project quickly accumulates “add-ons”: forms, CRM integrations, marketing automation tools, lead scoring and sometimes AI features. At some point, the team is no longer sure whether all of this can be launched without taking a risky shortcut.

We map the data flows and identify areas of heightened risk. Rather than causing alarm, we present the options: what to simplify, what to address organisationally and what to leave unchanged.

Business benefit: a predictable launch without "surprises" along the way.

Risk of inaction: launching a process that will need to be redesigned after its first few weeks of operation.

Documents and communications are not keeping pace with the project The product is ready, but the documents and communications are not keeping pace: privacy notices are out of date, consents do not “match” the form, the terms and conditions do not cover the new feature, and suppliers are waiting for contractual provisions.

We review what you have and tell you plainly what must be corrected before launch, what can be simplified and where discrepancies between the product and the documentation most often arise.

Business benefit: a prompt, specific list of changes — without weeks of iterations.

Risk of inaction: changes made "in several places at once" and unnecessary friction between teams.

The management board must approve the project launch without a clear picture of the risks The management board must decide whether to launch, but lacks a single, clear document setting out what data are involved, why they are needed, the applicable legal basis, where the risks lie and what is required for the “green light”.

We prepare decision-making material in plain language: the key risks, priorities and launch conditions. No lengthy legal memorandum, just a clear list of actions.

Business benefit: a faster decision and risk control without paralysis.

Risk of inaction: launching "on instinct" or unnecessarily putting the project on hold.

OUR SOLUTION

GDPR translated into project decisions — before you spend your budget on fixes

You do not receive a “legal opinion” that then needs to be explained to the team. You receive a launch-readiness plan: what to change in the product and process, what to finalise in documents and contracts, and whether you need a DPIA. Everything is prioritised so that it can simply be implemented.

Project model analysis

  • reviewing the new product, service, process, tool or implementation,
  • identifying the points at which personal data arise,
  • understanding the business objective and planned launch.

 

  • A brief description of the project's operating model from a personal-data perspective.

Defining roles, legal bases and obligations

  • defining the parties’ roles in the project,
  • identifying the legal bases for processing,
  • clarifying information, organisational and contractual obligations.

 

  • A clear allocation of roles and responsibilities + a list of the required legal bases and information obligations.

Data flow map (Privacy by Design)

  • organising data sources and the points at which data are used,
  • identifying access to data by teams and suppliers,
  • recommendations on data minimisation and adequacy.

 

  • A data flow map with recommendations.

Assessment of gaps in documents and communications

  • reviewing notices, consents and provisions for terms and conditions and contracts,
  • identifying gaps in user communications,
  • identifying the changes needed before launch.

 

  • A list of documents and communications to prepare or revise.

Risk assessment and decision on a DPIA / additional safeguards

  • analysing areas of heightened risk,
  • assessing profiling, automation, new integrations and unusual use cases,
  • determining whether a DPIA or other safeguards are needed.

 

  • Decision-making material: risks, priorities and a recommendation on whether a DPIA is needed.

Pre-launch implementation recommendations

  • prioritising actions,
  • aligning GDPR requirements with marketing, sales, operations, IT and documentation,
  • supporting the sequencing of pre-launch actions.

 

  • A single prioritised list of pre-launch actions (for the team and the management board).

WHO THIS SERVICE IS FOR

who will benefit most from this service

This service works best when the project has a specific launch date, involves several teams (marketing/IT/sales/operations) and you need a clear “yes, subject to conditions”, rather than endless discussions about consents and documents.

Project Manager

is responsible for implementation and needs a specific action list to keep the project moving through the final stages.

Product Manager / Head of Product

must translate personal-data issues into recommendations that marketing, IT, operations and partners can understand.

Management Board Member / COO / CEO

wants to approve the project launch with a clear picture of the risks, responsibilities and conditions for a safe launch.

STAGES OF WORK

how we work together

The process is simple: first, we gather the facts about the project; then we make key decisions about data and risks; and finally, we prepare a list of pre-launch actions.

Ustalenie celu i zakresu projektu

Ustalamy, co dokładnie uruchamiacie, kiedy planujecie start, gdzie zbieracie dane, z jakich narzędzi i dostawców korzystacie oraz kto podejmuje decyzje po Waszej stronie.

Analiza modelu przetwarzania i ryzyk

Sprawdzamy role, podstawy prawne, przepływy danych oraz punkty styku z marketingiem, sprzedażą, operacjami i technologią.

Projekt rozwiązań i rekomendacji

Przygotowujemy praktyczne rekomendacje: co wdrożyć, co zmienić, jakie dokumenty przygotować i czy potrzebna jest DPIA.

Gotowość do startu

Dostarczamy listę działań i pomagamy domknąć rzeczy krytyczne. Jeśli trzeba - sprawdzamy ostatnie wersje komunikatów/dokumentów przed uruchomieniem.

Sprawdź gotowość projektu do startu

Contact us

Do you have a project to launch? Let us conduct a quick pre-launch GDPR review

In 30-60 minutes, we will review the project with you and explain plainly what is blocking the launch, what needs to be done now and what can wait.

Briefly tell us what the project involves, when you plan to launch and where personal data arise. We will send you a proposed scope and the first 3-5 steps worth taking.

Natalia Jabcoń