ITENFR
Parlez-nous
Partenaires/Tomaino & De Zan
Tomaino & De Zan
Reference law firm

Paperwork
that's actually
in order.

Tomaino & De Zan is the law firm we rely on for our business clients' paperwork: GDPR and NIS2, DPO appointments, IT contract drafting, data breach handling. Specific expertise in the Italian tech world.

STUDIO LEGALE · COMPLIANCEDOSSIER · GDPR + NIS2Registro trattamentiNomina DPO esternoInformative privacyData breach planContratti & DPAMisure NIS2CONFORMEVERIFICATOOAKNET → TDZ · TRIAGE LEGALE
What we do together

Compliance without panic, contracts without surprises.

When an OakNet client needs an external DPO appointment, a GDPR audit on internal processes, or an opinion on a cloud contract, we connect them with the firm. For more technical cases (a data breach, an inspection by the Garante) we hold a three-way meeting. Lean process, no extra-long invoices.

Some of the services

The services we get asked for most.

01 · EXTERNAL DPO

DPO appointment + monitoring

Companies up to 250 employees

Official appointment, processing register review, training, annual audit.

02 · GDPR AUDIT

Privacy assessment

Audit + remediation plan

Processing mapping, gap analysis, compliance plan.

03 · IT CONTRACTS

Contracts & legal review

SLA, NDA, processor agreement

Review of cloud, SaaS, data processing agreements with foreign suppliers.

04 · NIS2

NIS2 compliance

EU Directive 2022/2555

NIS2 scope analysis, security measures, risk management and incident notification duties. Data protection aligned with the Garante's requirements.

What's included

Technical triage, legal support.

First contact and triage from our side
Negotiated rates for OakNet clients
Three-way meetings when the case is technical-legal
Shared documentation via secure channel
Data breach management in case of incident
Response time under 48 hours on business days
Use cases

Sure you're compliant?

01

Active company, never made compliant

You've operated for years with no processing register or up-to-date privacy notices. If the Garante inspects, fines start in the thousands of euro, even if nothing happened. We get you compliant before it does.

02

Garante complaint or inspection

It takes one ex-employee or client filing a complaint. With no register, appointments or notices you answer empty-handed, with an open inquiry and a likely fine. We prepare the paperwork before it's needed.

03

Active data breach

An attack or an email in the wrong hands: you have 72 hours to notify the Garante, or your position worsens. OakNet technical triage + TDZ legal support within 24h to handle it in time.

04

Data collected without realising

Website forms, newsletters, CCTV, the management system with client data: each is a processing activity to declare. If it isn't, you're exposed. We map it all and bring you into compliance.

Parlez-nous

Need to get
compliant?

Briefly describe the situation (GDPR or NIS2 audit, data breach, DPO appointment, contract review). We triage and connect you with the firm.

Écrivez-nous