Data Protection (GDPR)

Data Protection (GDPR)

Data Protection (GDPR)

I advise businesses on GDPR compliance in a way that works in practice — not binders of paperwork nobody reads, but documentation and processes matched to how your organisation actually handles data. From privacy policies and data-processing agreements to audits and impact assessments, I make sure your data operations meet regulatory standards.

Compliance That Serves the Business, Not the Other Way Around

Data protection was the subject of my master's thesis and has been part of my daily practice ever since — including designing and delivering GDPR training for clients. I translate regulatory requirements into concrete steps your team can follow.

Why Work With Me?

Specialist Background

Master's thesis on European personal-data standards; GDPR advisory since the start of my practice.

Practical Perspective

Day-to-day governance and compliance experience inside an international financial institution.

Legal consultation

How I Can Help

Whether you are building compliance from scratch, updating it after growth, or responding to an incident, I provide documentation and advice your organisation can actually operate with.

Typical Matters I Handle

  • Privacy policies, information clauses, and records of processing
  • Data-processing agreements and impact assessments (DPIA)
  • Compliance audits, breach response, and staff training

My company is small. Does GDPR really apply to me?

Almost certainly yes — GDPR applies from the moment you process any personal data of EU residents: customers, employees, even newsletter subscribers. The good news is that the scale of your obligations is proportionate; a small business usually needs a lean, well-chosen set of documents, not an enterprise compliance programme.

Do I need a Data Protection Officer?

Only certain organisations are legally required to appoint one — it depends on what data you process, at what scale, and whether it is your core activity. This is exactly the kind of question I answer definitively at a consultation after understanding your operations.

We have had a data breach. What now?

Act immediately — GDPR gives you as little as 72 hours to notify the supervisory authority where notification is required. Contain the incident, document what happened, and get legal advice on the same day if possible: whether and whom you must notify is a legal assessment, and getting it wrong compounds the problem.

We also operate in Switzerland. Is GDPR enough?

Not by itself — Switzerland has its own Federal Act on Data Protection (FADP), which is similar to GDPR but not identical. If you operate in both markets, your documentation should address both regimes; I advise with that cross-border context in mind.

Mikołaj Kawka Attorney Logo
back top