European data regulation consulting
One Europe on paper. Three regimes in practice.
The EU runs on the GDPR and the digital rulebook built around it. Switzerland runs on the revFADP. Norway applies the GDPR through its own law and its own regulator. Privello builds one compliance program that answers all three, so a US or international company can enter Europe with a file that holds up.
Where to start
Three doors into the same discipline
Europe's data rulebook is dozens of instruments, and no company needs all of them on day one. Every Privello engagement starts at one of three doors and extends only as far as the business actually reaches.
Market Entry
For companies about to sell, hire, or collect data in Europe for the first time. GDPR and Swiss revFADP compliance, a cookie and consent setup that survives scrutiny, the EU Data Act where connected products are involved, and the representative appointments that entry triggers.
Enter the European marketFinancial Sector
For fintech, payments, and crypto, where two data obligations land on the same systems at once: GDPR data privacy — including the personal data your KYC and screening generate — and DORA operational resilience. One advisor, one evidence base, no contradictions between vendors.
Align privacy and DORARepresentation Advisory
For companies with no establishment in Europe. The GDPR, the DSA, the AI Act, and NIS2 each carry their own representative duty. Privello scopes all four in one analysis, arranges the appointments with established European providers, and keeps one reconciled file behind them.
Appoint one presenceThe differentiator
"Europe" is not one jurisdiction
Ask most compliance vendors about Europe and you will get a GDPR answer. That answer is incomplete twice over. Switzerland is outside the EU and the EEA entirely: since 1 September 2023 its regime is the revised Federal Act on Data Protection, with its own regulator, its own transfer rules, and its own Swiss–U.S. Data Privacy Framework. Norway is inside the EEA, so the GDPR applies, but through the Norwegian Personal Data Act, under Datatilsynet, alongside local instruments like the ekomlov cookie rules and the Transparency Act.
Privello covers the EU, Switzerland, and Norway as one triangle — a combination the established European compliance shops do not offer as a single practice.
Start with the Swiss gap- European Union. GDPR (Reg. 2016/679) plus the rulebook around it: ePrivacy, the Data Act, the DSA, the AI Act, NIS2, and DORA.
- Switzerland. The revFADP overlay, mapped onto your GDPR program rather than duplicated, with the Swiss–U.S. transfer file documented separately.
- Norway. EEA GDPR through the Personal Data Act, plus ekomlov cookies, Åpenhetsloven due diligence, and the Article 27 duty nobody else mentions.
- One file. A single record that answers a regulator, an enterprise buyer, or a procurement questionnaire in any of the three.
The engagement
Assess, build, embed. Then prove it.
Every engagement follows the same arc. First understand how personal data actually moves through the business, not how the org chart says it should. Then close the gaps in order of risk. Then leave behind documentation and workflows the company's own team can run.
The file matters commercially, not just legally. Enterprise buyers now ask for a transfer mechanism, a data-processing agreement, and a breach process before they sign. Clean documentation closes deals as often as it closes audits.
Start a conversation- Assess Data map and gap report against the GDPR, the revFADP, and any sector rules in play Interviews with the people who actually touch the data
- Build ROPA, notices, DPAs, and DPIAs drafted; representatives appointed where entry requires them Transfer mechanism selected and documented, with the impact assessment behind it
- Embed Breach-response plan and DSAR playbook written down and rehearsed Team trained; vendor and sub-processor reviews running on a schedule
- Business as usual The program runs day to day, and the file proves it.
Why Privello
Between the legal memo and the checkbox tool
Privacy compliance is usually sold two ways: law-firm memos that never become operational, or software dashboards nobody configures. Privello was built for the gap between them.
An attorney's rigor, a consultant's delivery
Privello is led by a U.S.-licensed attorney (State of Texas) and Certified Information Privacy Professional/Europe (CIPP/E) who reads the regulations in the original, not in a vendor summary. The engagement is consulting, not legal representation, but the analysis is built to survive a regulator's questions.
Deliverables a team can run
Notices in plain language, a ROPA that matches the real operation, DPAs your vendors will actually sign, and workflows with named owners. Not a hundred-page binder that goes in a drawer.
Senior attention, one desk
The person who scopes the engagement is the person who does the work. One advisor across privacy and operational resilience, instead of separate vendors reconciling their differences on your invoice.
Start small
The fixed-price Cookie Compliance Audit
European enforcement usually begins at the cookie banner, and the evidence is public: tags that fire before consent, refusal buried a click deeper than acceptance, analytics quietly exporting to the U.S. The audit finds all of it in about two weeks and hands you a prioritized fix list. It is the lowest-risk way to see how Privello works.
Begin
Tell us where your data goes
Which markets you are entering, what personal data the business touches, and where it flows. One conversation is usually enough to outline where you stand and what to fix first. Every engagement is scoped in writing at a fixed fee — no hourly billing, no surprises — and every enquiry gets a reply within one business day.