Area of expertise

Privacy & Compliance Portal: GDPR and NIS2 under control, in one place

A SaaS platform to manage the record of processing activities, appointments, documents, security controls, deadlines and incidents, supported by your DPO or privacy consultant.

Privacy & Compliance Portal

What is the ALAconnect Privacy & Compliance Portal

The ALAconnect Privacy & Compliance Portal is a multi-company SaaS platform that centralises GDPR and NIS2 documentation and obligations: record of processing activities, appointments, privacy notices, security controls, deadlines, incidents and data subject requests. Each client has a private area; the assigned DPO or consultant works on the client's data, and official documents are generated automatically in Word and PDF.

The portal supports the obligations set out in Regulation (EU) 2016/679 (GDPR), Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018, Legislative Decree 138/2024 transposing the NIS2 Directive, the determinations of the Italian National Cybersecurity Agency (ACN) and Legislative Decree 24/2023 on whistleblowing. The service is available to businesses in every Italian region.

At a glance

  • One portal for the GDPR and NIS2 obligations of one or more companies.
  • Privacy documents generated automatically in DOCX and PDF, with revisions and history.
  • Deadline calendar with automatic reminders and checklists with progress tracking.
  • Incident and data breach register with deadlines for the Garante and CSIRT Italia.
  • Hosted in Italy on infrastructure managed by ALAconnect, with an ALAconnect or external DPO.

Who it is for

For those who must prove compliance, not just declare it.

The portal is designed for owners, managers and IT contacts who need to keep privacy and security obligations in order.

01

SMEs and professional firms

Businesses that want an up-to-date record of processing, correct appointments and aligned documents, without scattered spreadsheets.

02

Healthcare facilities and dental practices

Organisations handling health data that need patient privacy notices, periodic checks and traceable activities.

03

Companies assessing NIS2

Organisations that need to understand whether Legislative Decree 138/2024 applies to them as an essential or important entity, and what it entails.

04

Suppliers of NIS2 entities

Companies in the supply chain whose clients ask for evidence of the security measures in place.

Features

Features of the Privacy & Compliance Portal

Each module documents an obligation and keeps its evidence, so the compliance status can always be verified.

01

Guided GDPR and NIS2 profiling

The ALAconnect portal starts from ATECO business codes and company size, including group data, and estimates whether the company may be an essential or important NIS2 entity. It also assesses the GDPR risk level and whether a DPO should be appointed. The official ACN decision, once communicated, always prevails over the estimate.

02

Record of processing activities (Art. 30 GDPR)

The record of processing is completed step by step, with legal basis, retention periods, recipients and security measures for each processing activity. The export is always up to date and ready to present.

03

Appointments and roles

The portal manages processors (Art. 28), authorised persons (Art. 29), system administrators and joint controllers. For NIS2 it tracks the required roles, such as the point of contact and the CSIRT liaison.

04

Automatic Word and PDF documents

Privacy notices for employees, patients, video surveillance, whistleblowing and candidates, as well as appointments, policies and procedures, are generated in DOCX and PDF with the company's data and logo. Every document has revisions, approval and history.

05

Online acknowledgement and acceptance

Documents are sent by email with a personal link. The portal records the date, time and IP address of the acknowledgement, so delivery stays documented.

06

Checklists and controls

Checklists cover the NIS2 baseline security measures according to ACN specifications, GDPR audits, the Italian system administrators provision and WEEE disposal. Each control has a status, notes, an action plan and a completion percentage.

07

Deadline calendar with reminders

The calendar keeps track of annual reviews, backup restore tests, training, system administrator checks and ACN windows. Automatic reminders are sent at 30, 7 and 0 days, with follow-ups for overdue tasks.

08

Wazuh (SIEM/XDR) integration

The portal imports hosts monitored by Wazuh into the asset inventory and produces dated technical evidence: monitoring coverage, inventories, vulnerabilities and secure configurations, linked to NIS2 controls.

09

Incidents and data breaches

The incident register calculates deadlines automatically: 72 hours for notifying the Italian Data Protection Authority (Garante) and, where NIS2 applies, 24 hours, 72 hours and 1 month for communications to CSIRT Italia.

10

Data subject requests

Requests for access, rectification, erasure and the other rights under Articles 15-22 GDPR are recorded with the 1-month response deadline and their processing status.

How it works

From activation to ongoing management, in four steps.

The portal requires no installation: it runs in the browser and grows with the company's obligations.

  1. 01

    Activation

    ALAconnect activates the company's private area and access for its contacts.

  2. 02

    Profiling

    A wizard collects company data and estimates GDPR and NIS2 obligations.

  3. 03

    Import

    Existing privacy documentation is uploaded and reorganised in the portal.

  4. 04

    Ongoing management

    The DPO or consultant keeps records, controls and deadlines up to date with the company.

Security and access

A compliance platform must be secure first.

The data in the portal is confidential business data: the platform is designed and managed accordingly.

Platform security

  • Two-factor authentication for administrators and consultants.
  • Each client's data isolated from the others.
  • Encryption of application secrets.
  • Activity log with integrity verification.
  • Hosted in Italy on infrastructure managed by ALAconnect, with automatic security updates.

Roles and access

  • Platform administrator: manages companies, users and configuration.
  • DPO or consultant: works on the obligations of the assigned companies.
  • Company contact: fills in, approves and reviews their company's data.
  • Read-only user: views documents and status without editing.

Why ALAconnect

One partner for IT, security and privacy.

ALAconnect is a managed service provider with over 25 years of experience: it manages its clients' networks, servers, backups and security, and with the Privacy & Compliance Portal it links documented obligations to the technical measures actually in place.

The DPO can be provided by ALAconnect or be an external professional chosen by the company: either way, they work in the portal on the same data. When systems need attention, the same team handles cybersecurity, managed IT support and backup and business continuity.

FAQ

Frequently asked questions about the Privacy & Compliance Portal

Short answers to the questions owners and IT contacts ask us most often.

What is the difference between the portal and an external DPO?

The DPO is a professional who assesses, advises on and monitors GDPR compliance. The ALAconnect Privacy & Compliance Portal is the tool in which the DPO and the company document obligations, track deadlines and keep evidence. The DPO can be provided by ALAconnect or be an external professional chosen by the company.

Does the portal automatically make my company GDPR compliant?

No. The portal is a tool for managing and evidencing obligations: it helps organise, document and keep them up to date. Compliance depends on the measures the company actually adopts and on the assessment of the DPO or privacy consultant.

How do I know if my company falls under NIS2?

The profiling wizard compares ATECO codes, company size and group data with the criteria of Legislative Decree 138/2024 and estimates whether the company may be an essential or important entity. It is a supporting estimate: registration on the ACN platform and the Agency's official communication are what count.

Can I import the privacy documents I already have?

Yes. During activation, existing documentation such as the record of processing, appointments and privacy notices is uploaded and reorganised in the portal. From then on, documents are updated and regenerated by the platform with revisions and history.

Who can access my company's data?

Only authorised users: your company's contacts, the assigned DPO or consultant and the platform administrators. Each client's data is isolated, privileged access requires two-factor authentication and activities are logged.

Is the portal suitable for medical and dental practices?

Yes. The portal manages patient privacy notices, staff appointments, the record of health data processing, periodic checks and deadlines. It suits dental practices, outpatient clinics and other healthcare facilities that want to keep their privacy documentation in order.

How do deadline reminders work?

Every deadline, such as annual reviews, backup restore tests, training or system administrator checks, triggers automatic email reminders at 30, 7 and 0 days. If a task remains overdue, the portal sends follow-ups to the people responsible.

Do I need to install anything?

No. The Privacy & Compliance Portal is a SaaS service used from the browser, on a computer or tablet. The only optional technical integration is with Wazuh, for companies using the SIEM/XDR monitoring managed by ALAconnect.

Privacy & Compliance Portal

Want to see the portal in action?

We will show you how to manage your company's GDPR and NIS2 obligations in one place. Tailored plans: request a demo or a quote.

Request a demo of the Privacy & Compliance Portal
Need support?