Technology. Data. AI.
Technology no longer sits at the edge of your business — it sits at the center. From GDPR and the AI Act to NIS2, DORA and the Data Act, the legal landscape is becoming increasingly complex. Whether you are deploying AI, managing cyber risks, sharing data across ecosystems or navigating digital regulation, Nuans helps organisations translate complex rules into practical governance, compliance and risk management frameworks that actually work — keeping your business compliant, resilient and ready for what’s next.
Data protection & privacy
Privacy compliance is not a one-off exercise. It is an ongoing governance challenge. We help organisations build and maintain mature privacy programmes that align with their business objectives.
We assist with:
- GDPR compliance assessments
- GDPR implementation and remediation projects
- Privacy governance frameworks
- Data protection impact assessments (DPIAs)
- Data transfer impact assessments (DTIAs)
- Privacy policies, notices and procedures
- Data Processing Agreements (DPAs)
- Data breach and (security) incident procedures
- Regulatory investigations and interactions with supervisory authorities
- Training and awareness programmes
- Complex or sensitive data processing activities and intersection with other legislation
DPO Advisory
Already have a DPO or DPO team? We help them succeed.
What we do:
- Internal DPOs
- Internal CISOs
- Privacy officers
- Compliance teams
- Legal departments
- Information security teams
Typical support includes:
- Second legal opinions
- Complex GDPR questions
- DPIA reviews
- Regulatory interpretation
- Strategic advice
- Training and coaching
- Temporary capacity support
Your DPO doesn’t need to know everything. That’s what we’re here for.
DPO-as-a-service
Many organisations are legally required to appoint a Data Protection Officer. Others choose to do so because strong privacy governance creates trust and reduces risk.
Our lawyers and privacy specialists are certified (DPI) and act as external DPOs for organisations across a wide range of sectors.
As your external DPO, we:
- Monitor GDPR compliance
- Advise on privacy risks and obligations
- Support management and operational teams
- Review DPIAs and privacy projects
- Assist with incident and breach management
- Liaise with supervisory authorities
- Serve as a trusted point of contact for data subjects
- Report independently to senior management
Why clients choose Nuans:
- Deep legal expertise
- Sector-specific experience
- Independence and objectivity
- Direct access to a multidisciplinary team
- Pragmatic, business-oriented advice
A DPO should be more than a checkbox. We help turn privacy governance into a strategic advantage.
Cybersecurity & digital resilience
Cybersecurity has become a boardroom issue.
We help organisations navigate the growing ecosystem of European cyber and resilience legislation.
Our expertise includes:
- NIS2
- DORA
- Cyber Resilience Act (CRA)
- Cyber Fundamentals Framework (CCB)
- ISO27001 certification projects
- Incident governance and response
- Security governance frameworks
- Supplier and third-party risk management
We assist with:
- Gap assessments
- Compliance roadmaps
- Governance frameworks
- Policy development
- Contractual compliance
- Regulatory readiness
AI Governance & Compliance
The AI Act is changing the rules for organisations that develop, deploy or procure AI systems
We help businesses implement practical AI governance frameworks that balance innovation and compliance.
We assist with:
- AI Act applicability assessments
- AI risk classifications
- AI governance frameworks
- AI policies
- High-risk AI obligations
- Fundamental rights impact assessments (FRIAs)
- Contract reviews
- AI procurement support
- Internal AI governance programmes
Because AI compliance is not just about AI. It often requires alignment with GDPR, cybersecurity, intellectual property, employment law and sector-specific regulation.
Digital regulation
The European Union is building an entirely new digital regulatory framework. We help organisations understand how these rules interact and what they mean in practice.
Our expertise includes:
- Data Act
- Digital Services Act (DSA)
- Digital Markets Act (DMA)
- eIDAS
- Electronic communications
- Digital contracts
- Platform and digital services regulation
- Cloud and SaaS regulation
- Intellectual property legislation
Legal FAQ-ups
Do we need a privacy policy?
Mostly, yes. If you process personal data in the context of your services, you must provide a privacy policy under the GDPR.
This policy should explain what personal data you collect, why you process it, how long you retain it and what rights data subjects have.
Should we use NDAs?
NDAs (Non-Disclosure Agreements) are useful when discussing confidential information with partners, contractors or potential acquirers. Investors are generally reluctant to sign NDAs at an early stage, but you should ensure one is in place before sharing sensitive information.
When does GDPR apply to my startup?
GDPR applies when you process personal data of EU individuals in the context of your services to EU users. So, most presumably, yes, GDPR is applicable to your startup as from the start. In the early days, make sure to be able to demonstrate that you encounter basic compliance through ccountability documentation.
Do we need Data Processing Agreements (DPAs)?
Yes.
Under GDPR, you must conclude Data Processing Agreements with service providers that process personal data on behalf of your company, such as cloud hosting providers, SaaS platforms, CRM systems and analytics providers.
Most reputable providers offer standard DPAs, but smaller service providers often don’t.
Obviously, we do develop or use AI. Does the EU AI Act apply to my startup?
Possibly.
The EU AI Act applies not only to companies that develop AI systems, but also to those that use or
integrate AI into their products or services.
Whether it applies depends on factors such as how the AI system is used and the level of risk involved. We recommend you to assess early whether your activities fall within the scope of the AI Act and what compliance obligations may apply. Happy to help!
When should a startup work with Nuans?
‘As soon as possible’ won’t do the deal, right?
But honestly: as soon as possible — within reason.
We understand that legal budgets are limited in the early days and that you’re already stretched thin. Our goal is to help you get the essentials right in a pragmatic way.
If we understand your company, your story and your challenges, we can guide you and flag issues before they become problems.
Legal support shouldn’t slow you down — it should help you move faster and safer.
