European data regulation consulting

One Europe on paper. Three regimes in practice.

The EU runs on the GDPR and the digital rulebook built around it. Switzerland runs on the revFADP. Norway applies the GDPR through its own law and its own regulator. Privello builds one compliance program that answers all three, so a US or international company can enter Europe with a file that holds up.

Market Entry
GDPR and revFADP compliance, ePrivacy and cookies, and the EU Data Act, built before the first European record is processed.
Financial Sector
GDPR data privacy and DORA operational resilience for fintech and payments, run as one program.
Representation advisory
GDPR Art. 27, DSA, AI Act, and NIS2 duties scoped and appointed in one pass.

The differentiator

"Europe" is not one jurisdiction

Ask most compliance vendors about Europe and you will get a GDPR answer. That answer is incomplete twice over. Switzerland is outside the EU and the EEA entirely: since 1 September 2023 its regime is the revised Federal Act on Data Protection, with its own regulator, its own transfer rules, and its own Swiss–U.S. Data Privacy Framework. Norway is inside the EEA, so the GDPR applies, but through the Norwegian Personal Data Act, under Datatilsynet, alongside local instruments like the ekomlov cookie rules and the Transparency Act.

Privello covers the EU, Switzerland, and Norway as one triangle — a combination the established European compliance shops do not offer as a single practice.

Start with the Swiss gap
  • European Union. GDPR (Reg. 2016/679) plus the rulebook around it: ePrivacy, the Data Act, the DSA, the AI Act, NIS2, and DORA.
  • Switzerland. The revFADP overlay, mapped onto your GDPR program rather than duplicated, with the Swiss–U.S. transfer file documented separately.
  • Norway. EEA GDPR through the Personal Data Act, plus ekomlov cookies, Åpenhetsloven due diligence, and the Article 27 duty nobody else mentions.
  • One file. A single record that answers a regulator, an enterprise buyer, or a procurement questionnaire in any of the three.

The engagement

Assess, build, embed. Then prove it.

Every engagement follows the same arc. First understand how personal data actually moves through the business, not how the org chart says it should. Then close the gaps in order of risk. Then leave behind documentation and workflows the company's own team can run.

The file matters commercially, not just legally. Enterprise buyers now ask for a transfer mechanism, a data-processing agreement, and a breach process before they sign. Clean documentation closes deals as often as it closes audits.

Start a conversation
One coordinated program
Documentation Operations
  1. Assess Data map and gap report against the GDPR, the revFADP, and any sector rules in play Interviews with the people who actually touch the data
  2. Build ROPA, notices, DPAs, and DPIAs drafted; representatives appointed where entry requires them Transfer mechanism selected and documented, with the impact assessment behind it
  3. Embed Breach-response plan and DSAR playbook written down and rehearsed Team trained; vendor and sub-processor reviews running on a schedule
  4. Business as usual The program runs day to day, and the file proves it.

Why Privello

Between the legal memo and the checkbox tool

Privacy compliance is usually sold two ways: law-firm memos that never become operational, or software dashboards nobody configures. Privello was built for the gap between them.

An attorney's rigor, a consultant's delivery

Privello is led by a U.S.-licensed attorney (State of Texas) and Certified Information Privacy Professional/Europe (CIPP/E) who reads the regulations in the original, not in a vendor summary. The engagement is consulting, not legal representation, but the analysis is built to survive a regulator's questions.

Deliverables a team can run

Notices in plain language, a ROPA that matches the real operation, DPAs your vendors will actually sign, and workflows with named owners. Not a hundred-page binder that goes in a drawer.

Senior attention, one desk

The person who scopes the engagement is the person who does the work. One advisor across privacy and operational resilience, instead of separate vendors reconciling their differences on your invoice.

Start small

The fixed-price Cookie Compliance Audit

European enforcement usually begins at the cookie banner, and the evidence is public: tags that fire before consent, refusal buried a click deeper than acceptance, analytics quietly exporting to the U.S. The audit finds all of it in about two weeks and hands you a prioritized fix list. It is the lowest-risk way to see how Privello works.

See the cookie audit

Begin

Tell us where your data goes

Which markets you are entering, what personal data the business touches, and where it flows. One conversation is usually enough to outline where you stand and what to fix first. Every engagement is scoped in writing at a fixed fee — no hourly billing, no surprises — and every enquiry gets a reply within one business day.