GDPR · ePrivacy · EU AI Act

Services

Tailored GDPR, ePrivacy, and EU AI Act compliance services for businesses and organisations operating in the European digital landscape.

Services & Pricing
Free Discovery

Scoping Call

Free — 20 minutes

Bring the specific problem, whether that is a customer DPA you have been asked to sign or an app store submission that came back rejected. The call establishes which instruments reach your business and what the work involves. Within two working days you receive a written scope with a fixed fee.

Identification of applicable instruments Assessment of where exposure sits Written scope Fixed fee
GDPR · ePrivacy · DSA · DMA

Compliance Review

From €100 — fixed fee agreed at scoping

A review of what you publish and what you have committed to contractually, against every EU instrument that reaches your business. Scope runs from a single privacy policy up to a full review across GDPR, ePrivacy, the DSA, the DMA and EU consumer law.

Privacy policy, cookie policy & consent banner review DPA & subprocessor list review DSA obligations (notice and action, transparency, contact points) DMA business-user position review Written report ordered by exposure
Code-Level Compliance

Technical Legal Audit

Scoped individually

This audit reads the codebase rather than the documentation. It establishes what the application collects, where it transmits, and what it retains, then measures that against what your privacy policy, your DPA and your app store declarations say it does. Where the two diverge, the published document is the one a regulator holds you to.

SDK & third-party dependency inventory Outbound network call & data flow map Consent implementation traced against ePrivacy & Art. 7 GDPR Retention as implemented vs. retention as stated App Store & Play Store declarations verified against behaviour Discrepancy report with remediation
DPAs, Policies & Notices

Documentation Drafting

From €150 per document — quoted per engagement

Drafting for your actual processing rather than adaptation of a template. Commercial data processing agreements and negotiated data protection schedules are the bulk of this work, including marking up the DPA a customer or a vendor has put in front of you.

DPAs & negotiated data protection schedules ROPA DPIA Privacy policy & cookie policy Article 50 AI transparency notice Subprocessor list Breach response plan
Regulation (EU) 2024/1689

AI Act Classification & Documentation

From €200 — scoped to the system

Classification under Regulation (EU) 2024/1689 and the documentation that follows from the classification. Most engagements conclude that a system carries transparency obligations alone, and that conclusion, put in writing with reasoning, is what you hand to a customer running vendor due diligence.

Written classification with reasoning GPAI obligations for third-party foundation models Article 50 transparency notices & synthetic content marking Annex IV technical documentation for high-risk systems Training data governance documentation AI risk assessment
Article 37 GDPR — Retainer

Fractional DPO

From €200/month — minimum 6-month term

A named privacy lead on retainer appointed as your DPO under Article 37 GDPR where the appointment is mandatory.

Named DPO appointment & supervisory authority notification Data subject contact point (Art. 38(4)) DSAR triage & response Breach assessment & Art. 33 notification decisions (72hr window) And more
Frequently Asked Questions

Common questions

Which jurisdictions do you advise on?
NWLexTech advises on EU privacy and digital regulation — GDPR across EU/EEA member states, the ePrivacy Directive (and member-state implementations), the EU AI Act, the Digital Services Act (DSA), the Digital Markets Act (DMA), and EU consumer protection law as it intersects with digital services. We also advise on UK GDPR, the Data Protection Act 2018, and PECR for UK-facing organisations. Non-EU/UK organisations with EU or UK user bases (US SaaS, global platforms) are a core part of the practice — we advise on extraterritorial GDPR exposure, EU Representative requirements, and cross-border transfer mechanisms (SCCs, adequacy, TIAs). Where matters require locally-admitted counsel in a specific member state (e.g. regulatory representation, formal legal opinions, litigation), we work alongside a partner law firm in that jurisdiction.
What's your typical turnaround?
Discovery calls are scheduled within 48 hours of an accepted inquiry. Document Alignment Reviews are returned within 5–7 working days from receipt of all documents and intake answers. Full drafting engagements (privacy policies, DPAs, ROPAs, DPIAs, AI transparency notices) are delivered within 10–14 working days. Hourly advisory and quick-turn questions are addressed within the same working week, often same-day. AI Act classification and documentation engagements are scoped individually because timelines depend on system complexity and the documentation available. Anything urgent (regulator deadline, incident response, deal-driven) is flagged at intake and prioritised accordingly.
Do you sign NDAs?
Yes. A standard mutual NDA can be signed before any substantive discussion — happy to use either party's template. For engagements that proceed without a separate NDA, the engagement letter contains a comprehensive confidentiality clause covering all client information, documents, and discussions, with carve-outs only for legally required disclosures.
What are your payment terms?
Fixed-fee engagements (Document Alignment Reviews, drafting, AI Act consultancy) require a 50% deposit on signature of the engagement letter, with the balance due on delivery. Hourly advisory is invoiced monthly in arrears with 14-day payment terms. We accept bank transfer (SEPA, Faster Payments, SWIFT), Wise, and Stripe. Default invoicing currency is EUR; GBP and USD accepted by arrangement. VAT applied where applicable.
What happens after I submit an inquiry?
You'll receive an acknowledgement email within a few hours and a substantive response within 24 working hours proposing a free 15-minute discovery call. The discovery call is used to understand the regulatory framing of your problem, confirm scope fit, and identify whether what you need is a review, a drafting engagement, or hourly advisory. Within two working days of the call, you'll receive a written scoping proposal with a fixed fee and timeline. On acceptance, we send an engagement letter and the deposit invoice, and the work begins on receipt of the deposit and intake materials.
Are you a law firm? What is the nature of your services?
NWLexTech is a specialist privacy, AI governance, and digital regulation consultancy — not a law firm, and we do not provide regulated legal practice in any jurisdiction. The practice is led by a specialist with formal EU legal training (LL.M. in EU law) and credentials in privacy and AI governance. Our deliverables — compliance reviews, drafted documentation, risk assessments, advisory memos — are consultancy work product, not regulated legal advice or formal legal opinions, and should not be relied on as a substitute for advice from a locally-admitted lawyer where one is required.
Get In Touch

Send an Inquiry

Tell us about your compliance needs and we'll get back to you within 24 hours with tailored guidance.

Your information will be used in accordance with our Privacy Policy.