Technology Law · Privacy & Security

Data Privacy &
Cybersecurity.

GDPR compliance programmes, DPIAs, DPO advisory, data processing agreements and cross-border data transfer mechanisms, including SCCs. NIS2 compliance, management and notification of data breaches, and representation before the Hellenic Data Protection Authority.

8Jurisdictions Covered
3Languages
Fortune 50 GC experience
A partner of our firm has served for eleven years as General Counsel to a Fortune 50 technology group, with responsibility across four business lines and eight countries.
Publications and international speaking
The firm's lawyers contribute to leading international legal publications and are regularly invited to speak at international symposia.
Trusted by foreign embassies
A partner of our firm is dual-qualified in England & Wales and Greece, so English-law questions are advised on directly in-house. Court appearances remain before the Greek courts and international arbitral tribunals; English proceedings are conducted through instructed English correspondent counsel.
Concerned about your business's GDPR compliance?
Tell us what is concerning you and we will discuss your legal position and the options available.
Request Consultation
Overview Scope of Service Process Experience

Data Privacy & Cybersecurity

Compliance is a process,
not a document in a file.

The GDPR is not exhausted by a privacy policy on a website. A business has to know what personal data it processes, for what purpose and on what legal basis, and it must also be able to show that it applies appropriate protective measures. A data protection lawyer assesses the legal basis for the processing, the documentation obligations and the measures required, according to the nature and the risk of the processing.

A privacy policy is only one part of compliance. Depending on what the business does, it may need records of processing activities, Data Protection Impact Assessments (DPIAs), procedures for handling data subject rights requests and a Data Protection Officer (DPO). Real compliance lies in the procedures that are applied in practice and in the documentation that can be produced in the event of an audit or a complaint.

A privacy policy on a website is not the same as a GDPR compliance programme. Real compliance is judged by the procedures, by the measures actually applied and by the documentation available when it is needed. Cybersecurity adds a further layer of requirements. NIS2 has widened the range of businesses and organisations that may be subject to specific cybersecurity obligations, depending on their sector, size and activity. For businesses within its scope, appropriate risk-management measures and incident response and reporting procedures are required.

Cross-border transfers of personal data also call for particular care. Where data is transferred outside the EEA — to a cloud provider, a group company or a partner outside the EU, for example — an appropriate transfer mechanism has to be in place and the relevant GDPR conditions have to be met. Standard Contractual Clauses (SCCs) are one of the principal mechanisms for such transfers, but their use has to be assessed against the specific circumstances of the transfer. If a personal data breach occurs, the business has to assess the incident immediately and, where the conditions are met, notify the breach to the Hellenic Data Protection Authority within the prescribed time limit. Having the right procedures in place before an incident can make a material difference to how it is handled. We advise businesses on data protection and cybersecurity, from the design of policies and procedures through to cross-border transfers, processing agreements and incident response. Our experience from the in-house side at a multinational technology group shapes a practical approach: what the law requires, what has to be done in practice and how it can be documented.

Not a filing exercise
GDPR compliance is a programme, not a document
Records of processing activities, lawful basis documentation and Data Protection Impact Assessments (DPIAs) are part of the documentation a business has to be able to produce if it is audited. A published privacy policy, on its own, is not enough.
Expanded scope
NIS2 widens the scope of cybersecurity obligations
The NIS2 framework now covers more sectors and businesses than the previous regime, including certain digital services, manufacturing businesses and other entities that meet the prescribed criteria. The obligations depend on the sector, the size and the category of the entity.
Post-Schrems II
Cross-border transfers need an appropriate legal mechanism
Moving personal data outside the EEA requires an appropriate legal basis and, where Standard Contractual Clauses (SCCs) are used, an assessment of the circumstances of the particular transfer and of the risks involved. A general clause in a vendor's terms is not enough on its own.

Scope of Service

From data mapping
to documenting the compliance programme.

GDPR Compliance Programmes
Designing and implementing GDPR compliance programmes covering records of processing activities, lawful basis documentation, data retention policies and internal procedures and responsibilities.
GDPRGovernanceRecords of Processing
01
Data Protection Impact Assessments (DPIAs)
Carrying out and documenting DPIAs for processing that may involve a high risk to the rights and freedoms of individuals, such as new systems, profiling and large-scale monitoring, before the processing begins.
DPIARisk AssessmentAudit
02
DPO Advisory Services
Advisory support to the Data Protection Officer (DPO), with specialist legal support on personal data protection and GDPR compliance.
DPOAdvisory
03
Data Processing Agreements & Cross-Border Transfers (SCCs)
Drafting and negotiating Data Processing Agreements and designing mechanisms for the cross-border transfer of personal data, including Standard Contractual Clauses (SCCs) and the assessments required for transfers after Schrems II.
DPASCCsCross-Border
04
NIS2 Cybersecurity Compliance
Assessing whether your organisation falls within NIS2's "essential" or "important" entity categories, and supporting the implementation of the cybersecurity risk-management and incident reporting requirements.
NIS2CybersecurityIncident Reporting
05
Data Breach Response & HDPA Representation
Immediate assessment and handling of personal data breaches, including assessment of the notification duty and the applicable deadline, together with representation of the organisation before the Hellenic Data Protection Authority in audits, investigations and administrative proceedings.
Breach ResponseHDPARepresentation
06

How We Work

A process that starts from
the business's actual data.

STEP 01
Data Mapping & Gap Assessment
We look at what personal data you process, for what purpose, where it is transferred and how it is used. We identify the points at which current practice needs adjusting to meet the requirements of the GDPR and, where applicable, NIS2.
STEP 02
Compliance Programme Design
We put in place the appropriate compliance framework, from lawful basis documentation and DPIAs through to data transfer procedures and the role of the DPO, based on the business's actual needs and risks.
STEP 03
Implementation & Documentation
We draft the necessary records and documents — records of processing activities, Data Processing Agreements, SCCs and internal policies — and support their implementation in the relevant business processes.
STEP 04
Ongoing Monitoring & Breach Readiness
Immediate assessment and handling of personal data breaches, including assessment of the notification duty and the applicable deadline. Representation of the organisation before the Hellenic Data Protection Authority in audits, investigations and administrative proceedings.

Why Pantazis & Associates

We know data protection
from the business's side.

In-House · Fortune 50
Fortune 50 GC experience
A partner of our firm, Dionysios Pantazis, has served for eleven years as General Counsel to a Fortune 50 technology group, with responsibility across four business lines and eight countries.
Publications · Speaking
Publications and international speaking
The firm's lawyers contribute to leading international legal publications and are regularly invited to speak at international symposia.
Recognised · Independent
Trusted by foreign embassies
Foreign embassies in Greece, among them the United Kingdom, the United States, Australia, France and Poland, refer their nationals to the firm for legal support.
Practical experience
Representation before the Data Protection Authority
We represented a multinational company before the Hellenic Data Protection Authority in proceedings concerning alleged GDPR infringements.

Do you really know where the risk lies?

A confidential conversation about the data you process, your systems and procedures, and the points at which there may be a compliance gap.