EU Regulatory Consultancy for Digital Businesses

Expert Guidance on the GDPR, ePrivacy Frameworks, EU AI Act, and Digital Compliance Standards

We provide SaaS and technology companies in the European market clear data protection and AI regulation consulting. Our advice is practical and tailored for software development lifecycles.

View Services & Pricing
Founder

Expertise Grounded in Law And Technology

NWLexTech is led by Nirajan Wagle, a CIPP/E certified data protection consultant. Nirajan holds an LL.M. in Innovation, Technology and the Law from the University of Edinburgh and LL.B from the University of Essex. We combine regulatory knowledge with direct experience building software. Our technical background ensures our compliance strategies integrate seamlessly into your development workflow.

CIPP/E Certified
LL.M., Innovation, Technology and the Law — University of Edinburgh
LL.B., University of Essex
Direct software development experience
Services & Pricing

What we offer

Fixed-fee advisory for the compliance work that actually reaches your product, plus structured courses for teams who want to build the knowledge in-house.

Core 01 — Advisory
Free Discovery

Scoping Call

Free — 20 minutes

Bring the specific problem, whether that is a customer DPA you have been asked to sign or an app store submission that came back rejected. The call establishes which instruments reach your business and what the work involves. Within two working days you receive a written scope with a fixed fee.

Identification of applicable instruments Assessment of where exposure sits Written scope Fixed fee
GDPR · ePrivacy · DSA · DMA

Compliance Review

From €100 — fixed fee agreed at scoping

A review of what you publish and what you have committed to contractually, against every EU instrument that reaches your business. Scope runs from a single privacy policy up to a full review across GDPR, ePrivacy, the DSA, the DMA and EU consumer law.

Privacy policy, cookie policy & consent banner review DPA & subprocessor list review DSA obligations (notice and action, transparency, contact points) DMA business-user position review Written report ordered by exposure
Code-Level Compliance

Technical Legal Audit

Scoped individually

This audit reads the codebase rather than the documentation. It establishes what the application collects, where it transmits, and what it retains, then measures that against what your privacy policy, your DPA and your app store declarations say it does. Where the two diverge, the published document is the one a regulator holds you to.

SDK & third-party dependency inventory Outbound network call & data flow map Consent implementation traced against ePrivacy & Art. 7 GDPR Retention as implemented vs. retention as stated App Store & Play Store declarations verified against behaviour Discrepancy report with remediation
DPAs, Policies & Notices

Documentation Drafting

From €150 per document — quoted per engagement

Drafting for your actual processing rather than adaptation of a template. Commercial data processing agreements and negotiated data protection schedules are the bulk of this work, including marking up the DPA a customer or a vendor has put in front of you.

DPAs & negotiated data protection schedules ROPA DPIA Privacy policy & cookie policy Article 50 AI transparency notice Subprocessor list Breach response plan
Regulation (EU) 2024/1689

AI Act Classification & Documentation

From €200 — scoped to the system

Classification under Regulation (EU) 2024/1689 and the documentation that follows from the classification. Most engagements conclude that a system carries transparency obligations alone, and that conclusion, put in writing with reasoning, is what you hand to a customer running vendor due diligence.

Written classification with reasoning GPAI obligations for third-party foundation models Article 50 transparency notices & synthetic content marking Annex IV technical documentation for high-risk systems Training data governance documentation AI risk assessment
Article 37 GDPR — Retainer

Fractional DPO

From €200/month — minimum 6-month term

A named privacy lead on retainer appointed as your DPO under Article 37 GDPR where the appointment is mandatory.

Named DPO appointment & supervisory authority notification Data subject contact point (Art. 38(4)) DSAR triage & response Breach assessment & Art. 33 notification decisions (72hr window) And more
Courses 02 — Education
€35 / Lifetime Access

Learn Data Protection

A comprehensive independent study guide for European Data Protection learning. Updated for 2025/2026 GDPR standards. Includes detailed resources with over 300 interactive MCQs.

MOD // 01
Origins & History
  • Data protection power, people, and personal information
  • Hesse (Germany) to Sweden: early laws
  • OECD Guidelines and CoE Convention 108
  • Evolution: Directive 95/46/EC to GDPR
MOD // 02
EU Institutions
  • History of EU treaties and integration
  • Institutions (Parliament, Commission, Council)
  • Constitutional principles: supremacy & direct effect
  • The role of the CJEU in privacy
MOD // 03
Core Concepts
  • Personal data vs. special categories (Art 9)
  • The 7 principles (lawfulness, fairness, minimisation…)
  • Controllers, processors, and joint controllers
  • Legal bases for processing (Art 6)
MOD // 04
Data Subject Rights
  • Right of access (Art 15) & rectification (Art 16)
  • Right to erasure — 'right to be forgotten' (Art 17)
  • Restriction (Art 18) & portability (Art 20)
  • Right to object & automated decision-making (Art 21–22)
MOD // 05
Intl. Transfers
  • Adequacy decisions (Art 45) & the Schrems legacy
  • Standard Contractual Clauses (SCCs) & IDTAs
  • Binding Corporate Rules (BCRs)
  • Derogations for specific situations (Art 49)
MOD // 06
Practical Ops
  • RoPA: building the Article 30 record
  • DPIA: running impact assessments (Art 35)
  • Breach mgmt: response & notification (Art 33)
  • PbD: implementing privacy by design (Art 25)

*NW Lex Tech is an independent training provider and is not affiliated with, endorsed by, or associated with the IAPP.

Preview

AI Governance

Gain insights into AI Governance theory and practice. Learn about governance framework concepts and management strategies for AI systems. Preview modules included.

AI Act Frameworks Risk Mgmt
Coming Soon

*This course is for educational purposes only and does not constitute legal advice or guarantee regulatory compliance.