Privacy consulting
A support activity for the organisation. It can help to:
- analyse
- design
- adapt
- organise
- implement
- train
- correct
VIVALDI18 Protegge
Privacy / DPO
Software, suppliers, people and processes change continuously. Documentation must represent that reality, not replace it. VIVALDI18 STUDIO helps understand how data is processed, which responsibilities exist and which interventions are really needed.
ANTONIO AI is VIVALDI18 STUDIO's AI orientation assistant: it helps frame the question, it does not provide legal opinions and does not replace professional assessment.
Documentation, tools, suppliers or processes no longer represent how data is really processed within the organisation.
A Responsible Technology CHECK, focused on the data you process today.
Stated limits. A check does not constitute a legal opinion and does not replace professional assessment in the specific case.
The first task is to understand how the processing really works today.
A processing activity is not just an entry in a register: it is a path that runs through people, processes, tools and suppliers. Reconstructing it makes responsibilities and control points visible.
Point 1 · What we process
What information is really collected, generated or received.
Continues to: Purpose
Point 2 · Why we process it
What it is for and which legal basis it relies on.
Continues to: People
Point 3 · Who uses it
Who uses it, with which authorisations and which instructions.
Continues to: Processes
Point 4 · Where it flows
In which day-to-day activities the data enters, is transformed or duplicated.
Continues to: Tools
Point 5 · With what
Applications, archives, forms, shared folders, cloud services.
Continues to: Suppliers
Point 6 · Where it goes
Who processes data on behalf of the organisation and under which agreements.
Continues to: Retention
Point 7 · For how long
For how long it remains available and what happens afterwards.
Continues to: Responsibility
Point 8 · Who answers
Who decides, who checks, who answers for each step.
Closes the path.
Before producing documents, we make the system understandable.
A document must describe and govern reality. Not replace it.
The necessary documentation remains indispensable: registers, notices, procedures and contracts are the tools that make choices verifiable. The point is the order of work, not their value.
Not a list of legal provisions, but the questions an organisation must be able to answer about its own data.
Why do we use this data?
Purpose and legal basis
Do we really need all of it?
Minimisation
Who can access it?
Roles and authorisations
Who do we share it with?
Suppliers, processors and recipients
How long do we need it?
Retention
What happens if a person exercises a right?
Procedures and responsibilities
What happens if something goes wrong?
Incidents and data breaches
A new service, a piece of software, a portal, a process, a supplier, an app, a new information flow or the use of AI systems: in all these cases, choices about data, roles and tools are made at the beginning. Acting later almost always means correcting something that has already been decided.
We don't add privacy at the end. We consider it while the project takes shape.
When the topic originates from a project under construction, the work connects with the Project design expertise.
The indications on this page are for informational purposes and do not constitute a legal assessment referred to a specific organisation.
When an organisation uses artificial intelligence systems, data protection must be read together with the governance of the tools: data entered into the systems, purposes, legal bases, minimisation, suppliers, transfers, retention, human oversight and transparency towards people.
If the topic also concerns internal rules, roles, supplier assessment and AI training for people, the work continues in the dedicated expertise.
A support activity for the organisation. It can help to:
A function with its own position and tasks. It can:
The DPO does not make processing decisions on the controller's behalf.
The presence of a DPO does not transfer overall responsibility for compliance to them.
Not all organisations must appoint a DPO: any obligation, or the opportunity of a voluntary appointment, must be verified in the specific case.
Some situations require prompt human assessment: a possible data breach, a request or communication from the Authority, an imminent deadline, a complaint, a high-risk processing activity, a significant incident.
In these cases ANTONIO AI can help orient, but should not become the main channel for assessment: it is preferable to contact VIVALDI18 STUDIO directly.
Activities are chosen based on the situation: they are not all always included.
Possible outcomes of the work, to be defined together: not a standard package.
Examples built to make the type of work clear. They are not real cases or clients of VIVALDI18.
Documentation prepared years ago, new cloud tools and many suppliers to be framed.
A new digital service to build, keeping privacy by design and accessibility together.
Sensitive information about beneficiaries and the need to strengthen roles and procedures.
A new AI-based service to assess before launch.
If people, tools, suppliers or services have changed, it may be useful to check whether your privacy setup still represents reality. We can start from what you do today and understand which interventions really deserve priority.
Every engagement is built and followed together with the client, with shared goals, activities and progress.