Vai al contenuto

GDPR consultancy for companies and professional firms

Compliance with the European data protection regulation, without unnecessary bureaucracy.

In breve

The Regulation applies to anyone who processes personal data, which means every business, because every business has employees. What changes with size is not the obligation itself but the proportion of the measures required. Xion brings together the documentary and technical sides, because much of what the Regulation requires is not solved by a document but by configurations: access controls, two-factor authentication, verified backups, encrypted devices.

Complete documentation

We manage all GDPR documentation relating to employees, suppliers, customers and partners - accurate, up to date and ready for inspection.

5-stage method

From awareness to ongoing management - a clear compliance path, with defined responsibilities and timescales.

Compliance that lasts

GDPR is not a one-off exercise - periodic checks and system reviews keep the company compliant over time.

Privacy has become a business responsibility

EU Regulation 2016/679 (GDPR), directly applicable since 25 May 2018, has changed the way every company must handle the personal data of employees, suppliers, customers and partners. Xion IT Group manages all the documentation and compliance requirements for you, combining legal-organisational expertise with IT expertise: because today, data protection is implemented mainly through systems.

The two main principles of the Regulation

  1. Controller accountability: the company must be able to demonstrate that it processes data in a compliant way, with appropriate technical and organisational measures.
  2. Stronger data subject rights: access, rectification, erasure, portability - people have more control over their data, and the company must be able to respond.

The 6 principles of data protection

Every processing activity must comply with six principles, each with specific organisational and security obligations:

Our method: compliance in 5 stages

  1. Awareness - bringing GDPR knowledge into the company, starting with the people who handle data every day.
  2. Data mapping - taking a snapshot of the current situation: what data exists, where it is, who can access it, and what the risks are.
  3. Action plan - defining corrective actions with the people responsible for implementation.
  4. Implementation - putting the plan into practice within defined timescales, from policies to technical measures.
  5. Management and improvement - ongoing checks and periodic system review, because compliance must be maintained over time.

Why work with Xion

A legal adviser tells you what to do; we also handle the how: encryption, backups, access control, network security and endpoint security. With a single point of contact, GDPR compliance becomes a natural part of your company’s IT management.

What you actually receive

Compliance is demonstrated through facts — and through documents. At the end of the compliance process, the company will have:

And above all: a maintainable system, because compliance that lives only in a binder dies at the first inspection.

Who is required to do what

The most common misunderstanding is that the Regulation only concerns large companies. It does not: it applies to anyone who processes personal data, and every business processes personal data because every business has employees. What changes depending on size and the type of data is not the obligation, but the proportionality of the measures.

There are three roles, and they must be kept distinct, because on the day something goes wrong they determine who was supposed to do what.

The data controller is the company: it decides why and how data is used, and remains accountable to the authority. This responsibility cannot be delegated — execution can be entrusted, accountability cannot.

The data processor is whoever processes data on behalf of the controller: the business software provider, the company hosting the servers, the IT support provider. The relationship must be governed by a written contract that sets out what they can and cannot do. Many companies only realise they do not have this document when someone asks for it.

The system administrator is the person with privileged technical access. They must be formally appointed in writing, and their activities must be logged: this is a specific Italian requirement, predating the Regulation and still in force.

The seventy-two hours

If a breach occurs that poses a risk to individuals, it must be notified to the authority within seventy-two hours of becoming aware of it. This is the deadline that worries people most, and almost always for the wrong reason.

The problem is not the deadline itself: it is that without preparation, the first seventy-two hours are spent trying to understand what happened, and the notification is submitted with incomplete information — or not submitted at all. The three things that make that deadline manageable must be prepared in advance and cost very little:

It should also be said that not all breaches must be notified: if the risk to individuals is unlikely — for example, a lost laptop with an encrypted disk — the assessment may reach a different conclusion. But the assessment must be carried out and documented, and disk encryption is what changes the outcome.

Compliance and technology are the same thing

Much of what the Regulation requires is not solved with a document: it is solved with configurations. Appropriate security measures, to use its wording, are concrete things — who can access what, two-factor authentication, backups that can actually be restored, network segmentation, encrypted devices.

That is why treating compliance as something for a consultant to handle and security as a matter for technicians almost always produces two pieces of work that do not speak to each other: a beautifully written record of processing activities sitting on top of an infrastructure nobody has really examined. With us, the two belong together, because whoever writes the record can ask whoever manages the systems how things actually stand — and that is also the logic behind GAPOFF, the compliance platform we developed.

The mistakes we most often find in SMEs

  1. Photocopied documents downloaded from the internet, describing a company that does not exist;
  2. Privacy notices with no real processing behind them — or real processing with no notice;
  3. Suppliers never assessed — the cloud business software provider, the payroll firm, the IT consultant: they all process your data, but who has formally appointed them?
  4. Backups declared and never tested — until a restore is needed;
  5. No data breach procedure — and the 72-hour notification window passes quickly;
  6. No training ever delivered — even though it is the first thing the authority checks after an incident caused by human error.

GDPR + technology: the Xion advantage

Most breaches result from weak technical configurations, not poor documentation. That is why our service combines the documentary and technical sides: the same team that writes the backup procedure is also the team that implements and tests it. And to keep everything tracked over time — records, deadlines, compliance tasks — there is GAPOFF, the compliance operations platform developed by Xion.

When something happens

A dedicated page on what to do in the event of a data breach: when the seventy-two hours start running, when notification is required and when it is not, and the register to keep even for incidents that do not need to be notified.

Frequently asked questions

What is GDPR?

GDPR (General Data Protection Regulation) is EU Regulation 2016/679, applicable from 25 May 2018, governing the protection of personal data across the European Union. It is based on two main principles - greater accountability for the data controller and stronger rights for the data subject.

Does my company have to comply with GDPR?

Almost certainly yes. GDPR applies to all companies with headquarters or branches in the EU that process personal data, and also to non-EU companies offering goods or services to people in the Union. It also applies to SMEs - employee, customer and supplier data are personal data in every sense.

What does a non-compliant company risk?

Fines can reach up to €20 million or 4% of annual global turnover. But the more common risk is operational - a poorly handled data breach, disputes from employees or customers, exclusion from tenders and supply chains that require compliance.

What does your compliance service include?

We follow a 5-stage path - staff awareness, data and risk mapping, action plan, implementation with defined timescales, and ongoing management and improvement. At the end, the company has complete documentation and sustainable procedures.

Looking for a partner to manage your IT?

Tell us what you need: a Xion consultant will get back to you quickly, and the initial assessment visit is free of charge.