Privacy has become a business responsibility
EU Regulation 2016/679 (GDPR), directly applicable since 25 May 2018, has changed the way every company must handle the personal data of employees, suppliers, customers and partners. Xion IT Group manages all the documentation and compliance requirements for you, combining legal-organisational expertise with IT expertise: because today, data protection is implemented mainly through systems.
The two main principles of the Regulation
- Controller accountability: the company must be able to demonstrate that it processes data in a compliant way, with appropriate technical and organisational measures.
- Stronger data subject rights: access, rectification, erasure, portability - people have more control over their data, and the company must be able to respond.
The 6 principles of data protection
Every processing activity must comply with six principles, each with specific organisational and security obligations:
- Lawfulness, fairness and transparency
- Purpose limitation
- Data minimisation
- Accuracy
- Storage limitation
- Integrity and confidentiality
Our method: compliance in 5 stages
- Awareness - bringing GDPR knowledge into the company, starting with the people who handle data every day.
- Data mapping - taking a snapshot of the current situation: what data exists, where it is, who can access it, and what the risks are.
- Action plan - defining corrective actions with the people responsible for implementation.
- Implementation - putting the plan into practice within defined timescales, from policies to technical measures.
- Management and improvement - ongoing checks and periodic system review, because compliance must be maintained over time.
Why work with Xion
A legal adviser tells you what to do; we also handle the how: encryption, backups, access control, network security and endpoint security. With a single point of contact, GDPR compliance becomes a natural part of your company’s IT management.
What you actually receive
Compliance is demonstrated through facts — and through documents. At the end of the compliance process, the company will have:
- A complete and maintainable record of processing activities;
- Correct privacy notices and consents for customers, employees, suppliers and the website;
- Appointments and authorisation letters for those who process data, both internal and external;
- Supplier assessments (processors under Article 28) and contractual clauses;
- Operational procedures — handling data subject rights, data breaches, retention;
- DPIAs where processing requires them;
- Verified technical measures — access controls, encryption, backups, logs: not just stated, but implemented;
- Documented staff training.
And above all: a maintainable system, because compliance that lives only in a binder dies at the first inspection.
Who is required to do what
The most common misunderstanding is that the Regulation only concerns large companies. It does not: it applies to anyone who processes personal data, and every business processes personal data because every business has employees. What changes depending on size and the type of data is not the obligation, but the proportionality of the measures.
There are three roles, and they must be kept distinct, because on the day something goes wrong they determine who was supposed to do what.
The data controller is the company: it decides why and how data is used, and remains accountable to the authority. This responsibility cannot be delegated — execution can be entrusted, accountability cannot.
The data processor is whoever processes data on behalf of the controller: the business software provider, the company hosting the servers, the IT support provider. The relationship must be governed by a written contract that sets out what they can and cannot do. Many companies only realise they do not have this document when someone asks for it.
The system administrator is the person with privileged technical access. They must be formally appointed in writing, and their activities must be logged: this is a specific Italian requirement, predating the Regulation and still in force.
The seventy-two hours
If a breach occurs that poses a risk to individuals, it must be notified to the authority within seventy-two hours of becoming aware of it. This is the deadline that worries people most, and almost always for the wrong reason.
The problem is not the deadline itself: it is that without preparation, the first seventy-two hours are spent trying to understand what happened, and the notification is submitted with incomplete information — or not submitted at all. The three things that make that deadline manageable must be prepared in advance and cost very little:
- knowing what data is where, which is exactly what you need in order to say whether the breach involves personal data and which data;
- having active logs, because without traces you cannot reconstruct what happened;
- knowing who decides, meaning who assesses the risk and signs off the notification, without having to work it out while the company is at a standstill.
It should also be said that not all breaches must be notified: if the risk to individuals is unlikely — for example, a lost laptop with an encrypted disk — the assessment may reach a different conclusion. But the assessment must be carried out and documented, and disk encryption is what changes the outcome.
Compliance and technology are the same thing
Much of what the Regulation requires is not solved with a document: it is solved with configurations. Appropriate security measures, to use its wording, are concrete things — who can access what, two-factor authentication, backups that can actually be restored, network segmentation, encrypted devices.
That is why treating compliance as something for a consultant to handle and security as a matter for technicians almost always produces two pieces of work that do not speak to each other: a beautifully written record of processing activities sitting on top of an infrastructure nobody has really examined. With us, the two belong together, because whoever writes the record can ask whoever manages the systems how things actually stand — and that is also the logic behind GAPOFF, the compliance platform we developed.
The mistakes we most often find in SMEs
- Photocopied documents downloaded from the internet, describing a company that does not exist;
- Privacy notices with no real processing behind them — or real processing with no notice;
- Suppliers never assessed — the cloud business software provider, the payroll firm, the IT consultant: they all process your data, but who has formally appointed them?
- Backups declared and never tested — until a restore is needed;
- No data breach procedure — and the 72-hour notification window passes quickly;
- No training ever delivered — even though it is the first thing the authority checks after an incident caused by human error.
GDPR + technology: the Xion advantage
Most breaches result from weak technical configurations, not poor documentation. That is why our service combines the documentary and technical sides: the same team that writes the backup procedure is also the team that implements and tests it. And to keep everything tracked over time — records, deadlines, compliance tasks — there is GAPOFF, the compliance operations platform developed by Xion.
When something happens
A dedicated page on what to do in the event of a data breach: when the seventy-two hours start running, when notification is required and when it is not, and the register to keep even for incidents that do not need to be notified.