Data Protection

Personal data protection and privacy are key to building trust in organizations today, especially in a regulatory environment where the GDPR intersects with the rapid development of technology, digital services, and complex IT provider ecosystems. Non-personal data also plays an increasingly important role in the economy, enabling better management of the infrastructure that generates it and creating new business models. We support our clients in building data solutions that are legally compliant and feasible - from strategy and documentation to incident response and proceedings before regulatory authorities.

We provide advice on both day-to-day processes (marketing, HR, IT, sales) and projects requiring in-depth analysis (new technologies, AI, large-scale processing, non-personal data in critical infrastructure, international transfers). We analyze each issue in the context of a specific business model, the roles of the parties involved, and the architecture of data-processing systems.

Our team is one of the largest in Poland and has experience working under time pressure - including on data breach incidents, handling requests from data subjects, and liaising with supervisory authorities. We regularly assist entities in the financial sector - banks, payment institutions, insurance companies, and investment firms - in establishing data processing structures compliant with the GDPR and sector-specific regulations. We provide concrete advice that combines legal and business perspectives.

Our Approach

We combine our expertise in data law with our expertise in IT and intellectual property, which helps us design solutions tailored to the realities of the digital world. Depending on the needs, we also collaborate with teams specializing in M&A, labor law, energy, banking and finance, and white-collar crime - to ensure consistent advice on projects requiring an interdisciplinary approach.

How can we help?

Documentation, policies, and records

We prepare and update GDPR documentation (including policies, records, breach procedures, and rules for using IT devices and systems), tailoring it to the realities of the client’s business and the practices of regulatory authorities.

Monitoring (CCTV and electronic monitoring)

We advise on the design and implementation of video surveillance and electronic monitoring (email, websites) in employee and business contexts (e.g., in workplaces, stores, and public spaces).

Biometrics

We support the implementation of biometric solutions (including facial, voice, and fingerprint recognition) and assess the compliance of existing systems with the GDPR and sector-specific regulations.

Balancing tests (legitimate interest, LIA)

We prepare balancing tests for processing based on legitimate interest, including recommendations for risk mitigation measures.

Data Protection Impact Assessment (DPIA)

We conduct DPIAs for business processes and technology projects; we advise on when an assessment is required and how to design the scope of the analysis.

Information Clauses and Consents

We draft and review information clauses and consent forms (including those related to image rights and employee consent), ensuring compliance with the GDPR, laws governing personal rights, and copyright law, as well as consistency with the policies in place at the organization in question.

Data transfers to third countries

We advise on data transfers outside the EEA (including the selection of legal bases for transfers, risk assessments, and documentation). We prepare Transfer Impact Assessments (TIAs) when required and represent clients in proceedings before supervisory authorities. We adapt privacy notices and documentation to the agreed-upon data transfer rules.

Data protection incidents and breaches

We help assess incidents, determine notification obligations, and select remedial measures. We prepare reports to the supervisory authority and notifications to data subjects, and provide support for further communication.

Digital services, cloud computing, applications, and cookies

We advise on the design of electronically provided services, including cookies, privacy policies, disclosure obligations, and models for cooperation with technology providers; we also review and advise on projects related to data processing in the cloud.

Cloud and IT Outsourcing

We support cloud implementations, including the analysis of roles (controller/processor), access rights, audits, data transfers, and contract negotiations with vendors.

AI

We advise on issues related to the processing of personal data in artificial intelligence solutions, including data processing during training, fine-tuning, and validation of AI models; the exercise of data subjects’ rights; identifying the legal basis for data processing; and updating documentation and information for data subjects.

Personal Data in HR and Employee Relations

We advise employers on the processing of employee and candidate data—including in the areas of monitoring, sobriety testing, remote work, IT tools, authorization verification, and the exercise of data subjects’ rights.

Data Subject Access Requests (DSARs)

We draft responses to requests and complaints and recommend measures to mitigate the risk of disputes or intervention by the supervisory authority.

Inspections, proceedings, and disputes

We represent clients in audits and proceedings before the supervisory authority, as well as in disputes concerning violations of data processing rules (including claims for damages). We help clients prepare for audits, analyze findings, and provide support for post-audit actions.

Agreements and Negotiations

We draft and negotiate data processing agreements, data sharing agreements, and provisions regarding personal data. We draft and negotiate agreements for the sharing of non-personal data and for the use of non-personal data generated by products and services.

Data Protection Due Diligence

We support transactions and reorganizations by analyzing risks related to the legality of data collection and use, legal bases for processing, data transfers, and information security. We identify practical ways to mitigate risks and recommend corrective actions.

Internal investigations and whistleblowing

We advise on personal data matters in internal investigations and on the design and operation of channels for reporting irregularities.

New business models

We provide legal opinions and prepare documentation for new business models involving the use of personal and non-personal data.

Why us?
(12)
Button text

In our work, we emphasize efficiency, transparency, and proper communication.

We understand that we are entrusted with managing strategic projects and are always available. We strive not only to answer questions but, above all, to address the real business needs of our clients.

SK&S lawyers are recommended in national and international rankings (Legal 500, Chambers & Partners, IFLR 1000).