VIVALDI18 Protegge

Privacy / DPO

Compliance doesn't start with documents. It starts with how data really flows through the organisation.

Software, suppliers, people and processes change continuously. Documentation must represent that reality, not replace it. VIVALDI18 STUDIO helps understand how data is processed, which responsibilities exist and which interventions are really needed.

ANTONIO AI is VIVALDI18 STUDIO's AI orientation assistant: it helps frame the question, it does not provide legal opinions and does not replace professional assessment.

In summary

When it's useful

Documentation, tools, suppliers or processes no longer represent how data is really processed within the organisation.

What you get

  • A map of the real processing activities
  • Clear roles and responsibilities
  • Documentation and procedures aligned with reality

First step

A Responsible Technology CHECK, focused on the data you process today.

Request the first step

Stated limits. A check does not constitute a legal opinion and does not replace professional assessment in the specific case.

The organisation changes. Privacy has to change with it.

  • We have documentation prepared years ago and don't know if it's still up to date.
  • We introduced new software or cloud services.
  • We work with new suppliers.
  • We use, or would like to use, artificial intelligence systems.
  • We are no longer sure who has access to which data.
  • Notices and real processes no longer match.
  • Retention and responsibilities are not clear to everyone.
  • We have a DPO, but they are only involved once decisions have already been made.

The first task is to understand how the processing really works today.

We follow the path of the data

A processing activity is not just an entry in a register: it is a path that runs through people, processes, tools and suppliers. Reconstructing it makes responsibilities and control points visible.

  1. Point 1 · What we process

    Data

    What information is really collected, generated or received.

    Continues to: Purpose

  2. Point 2 · Why we process it

    Purpose

    What it is for and which legal basis it relies on.

    Continues to: People

  3. Point 3 · Who uses it

    People

    Who uses it, with which authorisations and which instructions.

    Continues to: Processes

  4. Point 4 · Where it flows

    Processes

    In which day-to-day activities the data enters, is transformed or duplicated.

    Continues to: Tools

  5. Point 5 · With what

    Tools

    Applications, archives, forms, shared folders, cloud services.

    Continues to: Suppliers

  6. Point 6 · Where it goes

    Suppliers

    Who processes data on behalf of the organisation and under which agreements.

    Continues to: Retention

  7. Point 7 · For how long

    Retention

    For how long it remains available and what happens afterwards.

    Continues to: Responsibility

  8. Point 8 · Who answers

    Responsibility

    Who decides, who checks, who answers for each step.

    Closes the path.

Before producing documents, we make the system understandable.

The VIVALDI18 model

Phase 1
We understand
Organisation, activities, services, people, tools, suppliers and real workflows.
Phase 2
We map
Processing activities, purposes, data, data subjects, recipients, systems, retention, transfers and responsibilities.
Phase 3
We assess
Lawfulness, legal bases, minimisation, transparency, security and risk, within the limits of the specific case.
Phase 4
We prioritise
We distinguish what is urgent from what can be addressed progressively.
Phase 5
We adapt
Procedures, notices, registers, roles, contracts, flows and measures that are really necessary.
Phase 6
We oversee
Updates, training, audits, support for new projects and, when appropriate, a DPO function.

Processing activities first. Then documents.

  • A correct notice does not automatically make the processing correct.
  • An existing register can be outdated by the changes that have taken place.
  • A contract may not represent the roles that are really carried out.
  • A procedure may not correspond to the way people actually work.

A document must describe and govern reality. Not replace it.

The necessary documentation remains indispensable: registers, notices, procedures and contracts are the tools that make choices verifiable. The point is the order of work, not their value.

The questions that need an answer

Not a list of legal provisions, but the questions an organisation must be able to answer about its own data.

  • Why do we use this data?

    Purpose and legal basis

  • Do we really need all of it?

    Minimisation

  • Who can access it?

    Roles and authorisations

  • Who do we share it with?

    Suppliers, processors and recipients

  • How long do we need it?

    Retention

  • What happens if a person exercises a right?

    Procedures and responsibilities

  • What happens if something goes wrong?

    Incidents and data breaches

Privacy takes less effort when it enters the project before the final decisions.

A new service, a piece of software, a portal, a process, a supplier, an app, a new information flow or the use of AI systems: in all these cases, choices about data, roles and tools are made at the beginning. Acting later almost always means correcting something that has already been decided.

We don't add privacy at the end. We consider it while the project takes shape.

When the topic originates from a project under construction, the work connects with the Project design expertise.

AI, DPIA and new risks: no automatic answers

  • Introducing AI systems does not automatically mean breaching the GDPR.
  • It doesn't mean being automatically compliant either.
  • It does not automatically trigger the obligation to carry out a DPIA.
  • The need for further assessments depends on the actual processing and the risk to people.
  • A DPIA is not a standard form to fill in every time.
  • Every conclusion requires verification in the specific case.

The indications on this page are for informational purposes and do not constitute a legal assessment referred to a specific organisation.

Privacy, data and artificial intelligence

When an organisation uses artificial intelligence systems, data protection must be read together with the governance of the tools: data entered into the systems, purposes, legal bases, minimisation, suppliers, transfers, retention, human oversight and transparency towards people.

If the topic also concerns internal rules, roles, supplier assessment and AI training for people, the work continues in the dedicated expertise.

Go to AI governance and AI compliance

Privacy consulting and DPO are not the same thing

Privacy consulting

A support activity for the organisation. It can help to:

  • analyse
  • design
  • adapt
  • organise
  • implement
  • train
  • correct

DPO

A function with its own position and tasks. It can:

  • inform and advise
  • monitor
  • support DPIAs
  • cooperate with the Authority
  • act as a point of contact

The DPO does not make processing decisions on the controller's behalf.

The presence of a DPO does not transfer overall responsibility for compliance to them.

Not all organisations must appoint a DPO: any obligation, or the opportunity of a voluntary appointment, must be verified in the specific case.

When the situation cannot wait

Some situations require prompt human assessment: a possible data breach, a request or communication from the Authority, an imminent deadline, a complaint, a high-risk processing activity, a significant incident.

In these cases ANTONIO AI can help orient, but should not become the main channel for assessment: it is preferable to contact VIVALDI18 STUDIO directly.

What we can do

Activities are chosen based on the situation: they are not all always included.

Understand

  • Assessment
  • Mapping of processing activities
  • Gap analysis

Organise

  • Roles and responsibilities
  • Register of processing activities
  • Suppliers and agreements
  • Retention

Protect

  • Procedures
  • Managing data subject rights
  • Data breach
  • Privacy by design
  • Assessments when necessary

Put into practice

  • Notices
  • Contracts
  • Checklists
  • Training
  • Roadmap

Oversee

  • Audits
  • Updates
  • Support for new projects
  • Possible DPO appointment

Documents and tools that need to stay useful

Possible outcomes of the work, to be defined together: not a standard package.

  • Map of processing activities
  • Gap analysis
  • Priority plan
  • Updated register
  • Notices
  • Roles matrix
  • Operating procedures
  • Retention framework
  • Managing data subject rights
  • Data breach procedure
  • DPIA when necessary
  • Supplier documentation
  • Privacy by design checklist
  • Training plan
  • Roadmap
  • Audit report

Illustrative scenarios

Examples built to make the type of work clear. They are not real cases or clients of VIVALDI18.

SME

Documentation prepared years ago, new cloud tools and many suppliers to be framed.

Local authority

A new digital service to build, keeping privacy by design and accessibility together.

Non-profit

Sensitive information about beneficiaries and the need to strengthen roles and procedures.

Startup

A new AI-based service to assess before launch.

Frequently asked questions

Do your documents still describe how you really handle data?

If people, tools, suppliers or services have changed, it may be useful to check whether your privacy setup still represents reality. We can start from what you do today and understand which interventions really deserve priority.

Every engagement is built and followed together with the client, with shared goals, activities and progress.