SMEs and professional firms
Businesses that want an up-to-date record of processing, correct appointments and aligned documents, without scattered spreadsheets.
Area of expertise
A SaaS platform to manage the record of processing activities, appointments, documents, security controls, deadlines and incidents, supported by your DPO or privacy consultant.
Privacy & Compliance Portal
The ALAconnect Privacy & Compliance Portal is a multi-company SaaS platform that centralises GDPR and NIS2 documentation and obligations: record of processing activities, appointments, privacy notices, security controls, deadlines, incidents and data subject requests. Each client has a private area; the assigned DPO or consultant works on the client's data, and official documents are generated automatically in Word and PDF.
The portal supports the obligations set out in Regulation (EU) 2016/679 (GDPR), Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018, Legislative Decree 138/2024 transposing the NIS2 Directive, the determinations of the Italian National Cybersecurity Agency (ACN) and Legislative Decree 24/2023 on whistleblowing. The service is available to businesses in every Italian region.
Who it is for
The portal is designed for owners, managers and IT contacts who need to keep privacy and security obligations in order.
Businesses that want an up-to-date record of processing, correct appointments and aligned documents, without scattered spreadsheets.
Organisations handling health data that need patient privacy notices, periodic checks and traceable activities.
Organisations that need to understand whether Legislative Decree 138/2024 applies to them as an essential or important entity, and what it entails.
Companies in the supply chain whose clients ask for evidence of the security measures in place.
Features
Each module documents an obligation and keeps its evidence, so the compliance status can always be verified.
The ALAconnect portal starts from ATECO business codes and company size, including group data, and estimates whether the company may be an essential or important NIS2 entity. It also assesses the GDPR risk level and whether a DPO should be appointed. The official ACN decision, once communicated, always prevails over the estimate.
The record of processing is completed step by step, with legal basis, retention periods, recipients and security measures for each processing activity. The export is always up to date and ready to present.
The portal manages processors (Art. 28), authorised persons (Art. 29), system administrators and joint controllers. For NIS2 it tracks the required roles, such as the point of contact and the CSIRT liaison.
Privacy notices for employees, patients, video surveillance, whistleblowing and candidates, as well as appointments, policies and procedures, are generated in DOCX and PDF with the company's data and logo. Every document has revisions, approval and history.
Documents are sent by email with a personal link. The portal records the date, time and IP address of the acknowledgement, so delivery stays documented.
Checklists cover the NIS2 baseline security measures according to ACN specifications, GDPR audits, the Italian system administrators provision and WEEE disposal. Each control has a status, notes, an action plan and a completion percentage.
The calendar keeps track of annual reviews, backup restore tests, training, system administrator checks and ACN windows. Automatic reminders are sent at 30, 7 and 0 days, with follow-ups for overdue tasks.
The portal imports hosts monitored by Wazuh into the asset inventory and produces dated technical evidence: monitoring coverage, inventories, vulnerabilities and secure configurations, linked to NIS2 controls.
The incident register calculates deadlines automatically: 72 hours for notifying the Italian Data Protection Authority (Garante) and, where NIS2 applies, 24 hours, 72 hours and 1 month for communications to CSIRT Italia.
Requests for access, rectification, erasure and the other rights under Articles 15-22 GDPR are recorded with the 1-month response deadline and their processing status.
How it works
The portal requires no installation: it runs in the browser and grows with the company's obligations.
ALAconnect activates the company's private area and access for its contacts.
A wizard collects company data and estimates GDPR and NIS2 obligations.
Existing privacy documentation is uploaded and reorganised in the portal.
The DPO or consultant keeps records, controls and deadlines up to date with the company.
Security and access
The data in the portal is confidential business data: the platform is designed and managed accordingly.
Why ALAconnect
ALAconnect is a managed service provider with over 25 years of experience: it manages its clients' networks, servers, backups and security, and with the Privacy & Compliance Portal it links documented obligations to the technical measures actually in place.
The DPO can be provided by ALAconnect or be an external professional chosen by the company: either way, they work in the portal on the same data. When systems need attention, the same team handles cybersecurity, managed IT support and backup and business continuity.
FAQ
Short answers to the questions owners and IT contacts ask us most often.
The DPO is a professional who assesses, advises on and monitors GDPR compliance. The ALAconnect Privacy & Compliance Portal is the tool in which the DPO and the company document obligations, track deadlines and keep evidence. The DPO can be provided by ALAconnect or be an external professional chosen by the company.
No. The portal is a tool for managing and evidencing obligations: it helps organise, document and keep them up to date. Compliance depends on the measures the company actually adopts and on the assessment of the DPO or privacy consultant.
The profiling wizard compares ATECO codes, company size and group data with the criteria of Legislative Decree 138/2024 and estimates whether the company may be an essential or important entity. It is a supporting estimate: registration on the ACN platform and the Agency's official communication are what count.
Yes. During activation, existing documentation such as the record of processing, appointments and privacy notices is uploaded and reorganised in the portal. From then on, documents are updated and regenerated by the platform with revisions and history.
Only authorised users: your company's contacts, the assigned DPO or consultant and the platform administrators. Each client's data is isolated, privileged access requires two-factor authentication and activities are logged.
Yes. The portal manages patient privacy notices, staff appointments, the record of health data processing, periodic checks and deadlines. It suits dental practices, outpatient clinics and other healthcare facilities that want to keep their privacy documentation in order.
Every deadline, such as annual reviews, backup restore tests, training or system administrator checks, triggers automatic email reminders at 30, 7 and 0 days. If a task remains overdue, the portal sends follow-ups to the people responsible.
No. The Privacy & Compliance Portal is a SaaS service used from the browser, on a computer or tablet. The only optional technical integration is with Wazuh, for companies using the SIEM/XDR monitoring managed by ALAconnect.
Privacy & Compliance Portal
We will show you how to manage your company's GDPR and NIS2 obligations in one place. Tailored plans: request a demo or a quote.
Request a demo of the Privacy & Compliance Portal