Is Your Business Ready for GDPR?
Is your company GDPR compliant? Discover how TN Solutions helps you meet EU data protection requirements and avoid heavy fines.

How to get compliant with GDPR
On 25 May 2018, the way personal data is handled online changed for good.
The rapid pace of technological change made it necessary to rethink how personal data is processed. More protection for citizens, simpler rules for businesses, and new obligations for public bodies too. These are the changes introduced by the new EU Regulation 2016/679 (the General Data Protection Regulation), which officially entered into force on 24 May 2016 and became directly applicable in every Member State from 25 May 2018.
The regulation introduces clearer rules on notices and consent, sets limits on the automated processing of personal data, lays the groundwork for new individual rights, and establishes strict criteria for transferring data outside the EU and for handling personal data breaches. In practice, this means every business had to comply with the new rules by that date to avoid heavy fines, which meant:
Assessing the risk that data processing poses
Ensuring an adequate level of data security and protection
Identifying and appointing a Data Protection Officer (DPO)
How can TN Solutions help?
TN Solutions, with years of proven experience in privacy consulting, supports data controllers and processors in meeting the requirements of the EU Privacy Regulation. Starting from a thorough review of a company's existing data protection practices, our team builds a targeted strategy covering every aspect touched by GDPR: consent to data use, users' right to have their information erased, cybersecurity measures to prevent data breaches, and dedicated training for staff who handle personal data day to day.
Specifically, TN Solutions walks companies through the process step by step and provides consulting on every aspect connected to data protection law, including:
Notices for employees, clients and consumers;
Reviewing data protection compliance and assessing adequate security measures;
Information governance;
Data retention policy;
Training on the correct handling of personal data.
GDPR Today: An Ongoing Duty, Not a Deadline You Hit Once
Since 2018, GDPR compliance hasn't been a one-off deadline tied to 25 May — it's an ongoing obligation that follows the business over time: every new way of processing data (new management software, a new marketing platform, a new cloud provider) needs to be assessed against the same principles, and security measures need to stay current rather than being set once and forgotten. For businesses that fall within the scope of the NIS2 directive — energy, transport, healthcare, digital infrastructure and other sectors named in the regulation — personal data protection sits alongside broader obligations on network and information system security. TN Solutions supports client businesses through this adaptation process, without replacing the legal assessment that remains the responsibility of a lawyer or a qualified DPO.
A Practical Checklist: What Compliance Actually Looks Like
Beyond the general principles, GDPR translates into a handful of concrete documents and technical measures that a data protection assessment will typically check for:
- A Records of Processing Activities register (Article 30) — a document listing what personal data is processed, why, for how long, and who it's shared with. Most businesses that process personal data as part of normal operations (employee records, customer data, a CRM, a marketing list) are expected to keep one, not just companies above a certain size.
- Appropriate technical and organizational security measures (Article 32) — this is where IT and compliance overlap directly: encryption of data at rest and in transit where appropriate, access controls so employees only see the data relevant to their role, and a way to restore availability and access to data quickly in the event of an incident.
- A breach notification procedure. Under Article 33, a personal data breach that poses a risk to individuals must be reported to the competent supervisory authority (the Garante Privacy in Italy) within 72 hours of the controller becoming aware of it — which only works in practice if there's already a defined internal process for detecting and escalating an incident quickly, rather than figuring it out for the first time during a live incident.
- A data retention policy — many businesses keep personal data far longer than the reason they collected it justifies, which is itself a compliance gap and, incidentally, expands what an attacker gains from a breach.
None of this replaces the legal assessment of a lawyer or a qualified DPO — the technical measures above only work as part of a compliance program that's been reviewed against your specific processing activities.
In practice, the businesses that struggle most with GDPR aren't the ones that ignored it in 2018 — they're the ones that completed a one-time compliance project back then and never revisited it since. A new CRM, a new marketing tool, a new employee onboarding a personal device: each of these changes the answer to "what data do we process and how is it protected," and the register and security measures need to be updated accordingly rather than treated as a document filed away once and forgotten.
Frequently asked questions
From when is GDPR applicable across all EU member states?
EU Regulation 2016/679 (GDPR) entered into force on 24 May 2016 and became applicable in every member state, including Italy, from 25 May 2018.
What do companies need to do to comply with GDPR?
They need to assess the risk that data processing poses, ensure an adequate level of data security and protection, and identify and appoint a Data Protection Officer (DPO) to avoid penalties.
How can TN Solutions help businesses with GDPR?
TN Solutions supports data controllers and processors with a targeted strategy covering consent to data use, the right to erasure, cybersecurity measures against data breaches, and dedicated staff training.
Technology partners
Want to discuss it with our team?
We analyse your infrastructure for free and propose the most suitable solution.







