MWMichał Wach Home

Warsaw · Attorney at Law

GDPR, DPIA and data protection

GDPR, DPIAs, agreements and risk assessment.

Scope

  • data protection impact assessments (DPIAs)
  • data processing agreements and roles
  • documentation and risk
  • GDPR in AI use

I provide legal services involving the assessment of processing activities, risk and the documentation required.

I prepare and review agreements, data-processing rules and solutions used with digital tools and AI. I translate GDPR requirements into decisions concerning processes, suppliers and organisational safeguards.

Working together

How I work

  1. description of the process, data and participating entities
  2. assessment of legal bases, risks and necessary documentation
  3. implementation in agreements, procedures and operational measures

Questions and answers

Frequently asked questions

When is a DPIA required?

A data protection impact assessment is required when proposed processing may result in a high risk to individuals’ rights and freedoms. The specific process must first be assessed carefully.

When is a data processing agreement needed?

When one entity processes personal data on behalf of another as a processor. Correctly identifying the parties’ roles is the starting point for selecting the appropriate documentation.

The information on this website is general in nature; the scope of legal services depends on the circumstances of the individual matter.

Contact about a matter