COMPLIANCE SERVICES

Software Is Half of It

A platform will tell you that a processing record has no legal basis. It will not sit with your finance team and work out what that basis should be. For the work that needs judgement rather than a screen, our legal and technical people do it with you, or for you.

Services, With or Without the Platform

Each of these can be bought on its own. They work better on top of PrivaxisOS, because the evidence lands somewhere permanent instead of in a report that ages, but none of them require it.

When it matters most

Data Breach Response

The clock starts before anyone has agreed what happened. We help you establish the facts, decide whether the incident is notifiable, draft what goes to the Commissioner and to affected people, and keep the record that shows how the decision was reached.

  • Triage and notifiability assessment
  • Notification drafting and post-incident review
  • Retainer available so the number is in your phone beforehand
Team capability

Training

Sessions built around Law 124/2024 and, where you need it, the GDPR alongside. Delivered for the people who actually touch personal data, in Albanian or English, with the attendance record kept as evidence that the training happened.

  • General awareness, or role-specific for HR, IT, marketing and support
  • Board and management briefings
  • On site or remote, with materials you keep
Where to begin

Compliance Audit and Gap Assessment

A structured review of where the organisation actually stands against Law 124/2024 and the GDPR it mirrors, delivered as findings you can act on rather than a document that sits in a drawer. Usually the first engagement, because it tells everyone what they are dealing with.

  • Findings ranked by severity, with a remediation plan
  • Loadable into the platform so progress is tracked, not re-audited
Done with you

ROPA Build-Out and DPIA Support

Interviewing the business, writing the processing records and running the impact assessments, rather than handing you an empty system and wishing you luck. The part most teams underestimate, and the reason implementations stall.

  • Business unit interviews and a populated register
  • Impact assessments facilitated end to end
Third parties

Vendor and DPA Review

Reading the agreements you already signed, clause by clause, and telling you which ones are short. Then building the vendor register so the answer stays current instead of being rediscovered at the next audit.

  • Clause-by-clause review against the Art. 26(3) list
  • Register build-out and sub-processor mapping
Getting ready

Certification Readiness

Preparation for the certification regime introduced by Instructions 08 and 09 of 2025. The groundwork is the same work the law asks for anyway, so this is mostly about doing it in an order that holds up to external scrutiny.

  • Readiness review against the published criteria
  • Documentation and evidence prepared for assessment
Something else

Ask Us

Most privacy work does not arrive in a neat package. If what you need is not on this page, describe the situation and we will tell you honestly whether it is something we do, something we can help scope, or something you want a different kind of adviser for.

The Work Lands Somewhere Permanent

The difference between a consultancy engagement and this one is what you are left holding at the end of it.

Not a PDF That Ages

Findings, records and assessments go into the platform, where they stay current and get re-checked. A report describes the day it was written; a register describes today.

Legal and Technical Together

Someone who can read a contract and someone who can read a cookie table, on the same engagement. Most privacy problems sit exactly on that line.

Tell Us What You Are Facing

An audit, an incident, a deadline, or a board that has started asking questions. Describe it and we will tell you what the work looks like and what it does not.

Talk to Us See Your Sector