Datadata-law#40F2FE#0A7C8A

GDPR Product Audit

GDPR tested against your real product, from the first form to the last supplier receiving data.

The real map of your data and the documentation that holds it up.

§ 1

Approach

Your privacy policy describes the product someone imagined, and the regulator inspects the one that is live.

The product comes first

We review the website, the app and their traffic before reading a single document. Every SDK, every pixel and every supplier that receives data goes on the map, whether or not the policy mentions it.

Suppliers and transfers

Much of the risk lives outside your code: analytics, support, email and AI tools. We check under which contract and on what basis each flow travels, including when it ends up in the United States.

Documents that match

The record of processing, the processor agreements and the website texts are drafted from the map. What you declare then matches what you do, which is the first thing an inspection tests.

§ 2

Engagement

EU digital companies
The real map of your data and the documentation that holds it up.
€3,500 + VAT
3 weeks

El importe exacto se cierra en la hoja de encargo antes de pagar, con los gastos previsibles incluidos. Si el encargo se alarga, no pagas más.

§ 3

Process

How the engagement unfolds

Pre-Consultation NDA

A unilateral confidentiality agreement signed by PASSAS before the video consultation, available at no additional cost on request. It binds the firm alone — no signature is required from the client — and adds an explicit contractual layer on top of the professional secrecy obligations inherent to the practice of law.

Initial Consultation

A 60-minute working session by video call in which we analyse your situation, your specific needs and our ability to help you. We assess whether we can take on the matter and give you the fixed price in advance. You can book it directly through the Google Calendar link on our website and pay €90 by Stripe.

Data Flow Map

A technical inventory of the real path personal data takes through the product: forms, SDKs, cookies and trackers, APIs, suppliers and AI tools, server locations and transfers outside the EEA. It is built by inspecting the website, the app and their traffic, and it flags every point where what happens and what the privacy policy declares do not match.

Compliance Memorandum

Legal analysis of the business model that determines which rules affect the company, what legal risks exist and what documentation is mandatory before operating. Covers the sectoral regulatory framework, data protection obligations, essential contracts and any applicable authorisation or licensing requirements.

Data Pack

The documentation required for GDPR compliance and, more broadly, for any rules on data protection and on the processing and transfer of data, including international transfers, both in dealings with users and with the providers that process data on your behalf, with the legal mechanisms needed to operate without regulatory exposure.

Web Pack

The legal documentation required to operate online: legal notice, privacy policy, cookie policy and, where applicable, terms of sale. Drafted with legal precision and adapted to the specific activity, not carried over from another website. Complies with the GDPR and with information society services rules.

§ 4

Team

Who handles it

Guillermo Passas Varo, founding partner of PASSAS

I see legal practice as a discipline of precision. I work where the law meets technology and cross-border operations, and I read code and contracts with the same attention. Before accepting an engagement I tell you whether it is worth pursuing and what it costs, at a fixed price.

§ 5

Questions

What people ask before instructing this service

How does this differ from a standard GDPR compliance package?

A standard package starts from a questionnaire and delivers templates. This audit starts from the product as it runs: we inspect the website, the app and their traffic to find out what data leaves, to whom and on what basis. The documents are drafted afterwards, from what we found.

What do you need from us?

Access to the live website and app, the list of suppliers you know about and someone on your technical team for occasional questions. Everything else we obtain by inspecting the product.

Does it include a data protection impact assessment?

If the audit finds processing that requires one (article 35 GDPR), we flag it and the engagement letter prices it separately, because its scope depends on the specific processing.

How much does it cost and how long does it take?

From €3,500 + VAT, delivered within three weeks. The exact figure is fixed in the engagement letter before you pay, and depends on the number of products, suppliers and international flows.

What if my company is outside the EU?

Then the right engagement is EU Data Compliance, which adds the article 3(2) analysis, the EU representative and transfers to your country.

Book your Virtual Consultation with a lawyer. Today.

60 minutes on Google Meet with a qualified lawyer specialising in artificial intelligence, data, litigation or international law. €90 including VAT, deducted from the first invoice if we take on your matter. You leave with legal judgement and a fixed price for whatever comes next.

Choose your lawyer and a time in the calendar. No forms first, no sales calls.