Experts in CCPA (CPRA), GDPR, PIPEDA We have longstanding experience in creating policies for different markets
02 We review the current policy We assess its compliance with current legal requirements, completeness, and relevance to the product
03 We create a new policy If the current privacy policy doesn’t meet legal standards, we draft a new version
04 We review cookies We examine your cookie banner design and cookie policy text — and update them if needed
06 We add a DPA An optional step for companies looking to streamline B2B sales and operate in specific markets
Right to access personal data Find out whether data is being processed and receive a specially formatted archive or document with that data
Right to rectification of inaccurate data Data processing systems must include functionality for correcting user records
Right to erasure (“right to be forgotten”) This right does not always apply, so it’s important to understand which data your company must delete upon request
Right to restrict data processing Systems should be configured to, for example, isolate such data in a separate table or make records read-only in response to this request
Right to data portability Affects data format choices, processing systems, protocols, data architecture, and third-party vendors involved
Right to object to data processing The user has an absolute right to opt out of marketing, so clear links and mechanisms must be provided to exercise this right
Right not to be subject to automated decision-making, including profiling Important for AI systems — there must be a way for human intervention and the ability to override decisions
Right to know What categories and specific pieces of personal data are collected, disclosed to third parties, or sold — and for what purposes
Right to opt-out of the sale or sharing Applies to businesses that profit (or benefit in other ways) from selling or disclosing data to third parties upon request
Right of non-retaliation Guarantees that submitting a request cannot be used by the company to discriminate against the individual
Right to limit use of sensitive personal information For example, limiting the duration of use, restricting storage within company systems, or disclosure to certain third parties
Right to correct personal information Similar to the GDPR — requires both architectural and procedural updates, such as enabling databases to modify user data or records
Right to opt-out of automated decision-making technology Relevant for AI and other automated systems — especially when data is collected directly from the data subject
Right to refuse targeting / cross-context behavioral advertising (CCBA) Specific requirements for companies acting as data brokers or using advertising in their business models
Data Processing Agreement We create annexes to public offers and EULAs to simplify data processing for your B2B clients
Forms for GDPR/CCPA requests We assist in designing and implementing request forms for data subject rights
How much does it cost? €100/hour Depends on the complexity of data flows and processing mechanisms Send a request