Data Protection and Cybersecurity

Data Protection and Cybersecurity

RockBridge Legal provides legal support on data protection and cybersecurity matters – from drafting internal regulations and arranging contracts to representation before the Data State Inspectorate and other supervisory authorities.

We offer

RockBridge Legal Associates help ensure the compliance of personal data processing with GDPR and national regulations. Our services include:

– assessment of the legal basis and purposes of personal data processing;
– organization of data processing registers, data categories, and retention periods;
– preparation or review of privacy notices, privacy policies, and cookie policies;
– preparation of data processor agreements and joint controller agreements;
– preparation of the legal part and documents for Data Protection Impact Assessments (DPIA).

RockBridge Legal attorneys advise on the application of cybersecurity regulations and actions in the event of security incidents. Our services include:

– assessment of the applicability of NIS2 and other cybersecurity requirements to the company;
– development of incident management and reporting procedures from a legal perspective;
– preparation of notifications to the Data State Inspectorate and other supervisory authorities in case of data/security incidents;
– preparation of the legal part of communication with data subjects and partners after an incident;
– regulation of liability and risk allocation in contracts with IT and cybersecurity service providers.

The firm’s specialists ensure that data protection and cybersecurity aspects are reflected in contracts with IT and cloud service providers. Our services include:

– preparation of Data Processing Agreements (DPA) and security requirement clauses;
– legal review of contracts with cloud service, software (SaaS), and outsourcing providers;
– preparation and adaptation of Standard Contractual Clauses (SCC) and other international data transfer solutions;
– integration of data and cybersecurity requirements into service, cooperation, and supply contracts;
– development of liability, insurance, and recourse mechanisms for cases where security breaches are caused by a third party.

RockBridge Legal Associates evaluate the company’s internal documentation in the field of data protection and cybersecurity and prepare necessary improvements. Our services include:

– legal audit of existing policies, regulations, and contracts regarding data and security aspects;
– preparation or review of internal IT and information security regulations, access, and device usage policies;
– development of data retention, deletion, and archiving procedures;
– preparation of guidelines for employee conduct on data and cybersecurity matters (from a legal standpoint);
– development of action plans to address compliance deficiencies.

Our attorneys represent clients in supervisory authority inspections and disputes related to data protection and cybersecurity. Our services include:

– representation before the Data State Inspectorate and other institutions (explanations, objections, appeals);
– preparation of correspondence and procedural documents in administrative cases and litigation;
– dispute resolution between the client and service providers regarding breaches of security and data protection obligations;
– assessment of damages and penalty clauses and preparation of claims;
– recommendations for improving compliance and contracts to mitigate future sanction risks.

trust begins with a conversation

Contact us >

Our specialists:

Image hover effect image

Par uzvarētāju nedzimst!
Par tādu kļūst!
-P. Summit

Nulla vitae elit libero, a pharetra augue. Curabitur blandit tempus porttitor cum sociis.

Alisa Leškoviča
Partner
Image hover effect image

Iespējas nerodas, jūs tās radāt
-Mashall Goldsmith

Nulla vitae elit libero, a pharetra augue. Curabitur blandit tempus porttitor cum sociis.

Anna Bogdanova
Associate Specialist
View all >