Privacy policy and data protection compliance

We will work out which data protection regimes actually reach your users, write the privacy policy that matches what your product does, and set up the procedures behind it.

 

Breach report

Сообщить об утечке

72 hours

72 часа

Consumer request

Ответ на запрос

45 days

45 дней

Top fine band

Верхний штраф

€20m or 4% of turnover

20 млн € или 4% оборота

Agreeing alone

Соглашается сам

13, 14 or 16

13, 14 или 16 лет

When you need a privacy policy

You are opening a new market

Which law reaches you is decided by where your users sit; your own address decides nothing. One new country adds a whole set of duties.

A store rejected your listing

App stores ask for a working policy address before they publish. A broken link or a page that contradicts the app is enough to be sent back.

Children are using your product

The age at which a person may agree for themselves is different in every regime, and getting it wrong is the most expensive kind of mistake.

A customer sent a data questionnaire

Enterprise buyers ask where the data goes, who processes it and on what basis. Once signed, the answers bind you like a contract term.

Personal data leaked last week

A clock started the moment somebody in the company became aware of it, and it is counted in hours.

What you get

  • The laws that reach you
  • The policy and the notices
  • A working request procedure
  • A plan for a breach
  • Contracts with your processors

What is required for a privacy policy

The question is never «which law do we follow». It is «which laws reach us at once», because these regimes are written to follow the person, and your users are in more than one place.

The European regulation says so in as many words: it applies to a controller or processor not established in the Union where the processing relates to offering goods or services to people who are in the Union.

The Emirati decree-law of 2021 reaches processing carried out inside or outside the country. Neither of them asks where your office is.

What the policy has to say

  • What you collect, in categories a reader recognises, and what you do with each category.
  • The ground you rely on for each purpose, and what changes if a person withdraws their agreement.
  • Who else receives the data: the services you run on, and the countries those services sit in.
  • How long each category is kept, and what happens to it at the end of that period.
  • The rights a person has and the address that actually answers when one of them is used.

Privacy policy for app stores

A store checks two things: the address works, and the page matches what the app does. A policy naming a tracker the build dropped, or missing one it added, fails that comparison.

What a generator leaves out

A privacy policy generator writes a document from a questionnaire. What it cannot do is check the answers against your build, name the regimes that actually reach your users, or set up the procedure that answers a request inside the deadline.

The document is the visible part. The duties behind it are the expensive part, and they do not appear because a page was published.

Six regimes, one product

European Union

A breach goes to the supervisory authority without undue delay and, where feasible, within 72 hours. The top band of fines reaches 20 million euro or 4% of worldwide annual turnover, whichever is higher.

Cyprus

The same regulation applies, and the national law fills the gaps it leaves to member states. Where the regulation sets 16 as the age at which a child may agree alone to an online service, the Cypriot law sets 14.

United States

There is no single federal statute for everyone; duties come by sector and by state. The federal children's rule applies to services directed to children under 13 and requires verifiable parental consent before collection.

California

A business answers a verified consumer request within 45 days, extendable once by another 45. Administrative fines run to 2,500 dollars per violation and 7,500 dollars where it was intentional or involved a consumer under 16.

Brazil

The national authority may impose a fine of up to 2% of the revenue the business earned in the country in its last financial year, excluding taxes, capped at 50 million reais per infraction.

United Arab Emirates

The 2021 decree-law took effect on 2 January 2022 and covers processing inside or outside the country. Processing without the person's agreement is prohibited except in cases the law names.

Sources: the 72-hour report, the 4% band and the age of 16 are in the European regulation, the age of 14 in Cypriot law 125(I)/2018; 45 days and the two fines in the Californian code; under 13 in the children’s rule; 2% and 50 million in the Brazilian law.

Stages of work

Working out which laws reach you — 3–5 working days.

We will start from where your users are and where your data physically sits, and name the regimes that follow from both. That list decides everything else on this page.

Listing what you collect and why.

Every field the product asks for, every event it records, every service it sends something to. Each line gets a purpose and a ground, or a note that it has neither.

Writing the policy and the notices.

One document people can read, plus the short notices that appear at the moment of collection. We will write them against what the build actually does, and mark what has to change if the build changes.

Setting up the request procedure.

Access, correction, deletion and objection arrive by email and have to be answered inside a deadline that differs by regime. We will write who receives them, how identity is checked and what the answer looks like.

The breach plan and its clock.

The obligation starts when somebody in the company becomes aware, well before the investigation ends. We will write the steps, the decision on whether to notify, and the record kept either way.

Contracts with the services you use.

Analytics, hosting, support tools and payment providers all process data for you. We will paper that relationship and check what each already promises in its own terms.

Our work on licences and compliance sits in the Licensing & Compliance area.

Our case studies

EdTech Platform Legal Launch in UAE

Client

EdTech platform operator

arrow_outward

Personal Data Compliance Review in Qatar

Client

International IT company

arrow_outward

Global IP Registration and Data Privacy for Recycling Tech

Client

Global recycling technology company in 34 markets

arrow_outward

Legal Support for National Tourism Marketing Campaign

Client

UAE-based digital marketing agency

arrow_outward

Leaders of the Area

Alexandra Kurdiumova

Alexandra

Kurdiumova

arrow_outward

FAQ

Do we actually need a privacy policy?
add
remove
Does European law apply if we are not in Europe?
add
remove
Can a privacy policy generator do the job?
add
remove
From what age can a child agree alone?
add
remove

Discuss
the Task

Speak to our team

Speak to our team. Tell us about your task –

we’ll help you with it in any jurisdiction.

Tell us about your task –
we’ll help you with it in any jurisdiction.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

We use cookies to improve your experience.