• IT
Choose your location?
  • Global Global
  • Australian flag Australia
  • French flag France
  • German flag Germany
  • Irish flag Ireland
  • Italian flag Italy
  • Polish flag Poland
  • Qatar flag Qatar
  • Spanish flag Spain
  • UAE flag UAE
  • UK flag UK

Case Study: GDPR Programme Support for a Large International Insurance Company

22 October 2024
We helped our large insurance client to ensure they remained compliant with GDPR in flexible, cost-effective manner which gave them tight control over their limited budget. 

1. What Was the Situation?

The client, a large international insurance company, needed support for its GDPR compliance programme but faced a lack of junior legal resources. The company’s legal and programme teams required assistance with research tasks, initial issue spotting, and drafting policies using available precedents and online resources. Additionally, the client needed procedural support for compiling information for Data Subject Access Requests (DSARs) from employees.

The client wanted to avoid high hourly rates and needed to work within strict programme budget approvals, seeking predictable costs rather than open-ended billing. They required junior-level support but did not want senior-level involvement except when necessary. The legal team preferred to manage the junior resource in-house, as their own commercial lawyers had some data protection experience. However, they also wanted flexibility to access senior legal advice when needed, without exceeding budget constraints.

2. How Did We Help the Client?

We provided a remote junior lawyer from our team in Poland with sufficient data protection knowledge to meet the client's needs. This solution allowed the client to manage the junior directly under the supervision of their own senior lawyers to undertake research, drafting, and procedural tasks such as:

  • Conducting legal research and spotting initial GDPR compliance issues.
  • Drafting data protection policies using existing precedents and online resources.
  • Supporting procedural aspects of DSAR responses, including reviewing and compiling employee data.

In addition to providing junior support, we agreed to offer senior lawyer assistance from Poland on a flexible basis. The client opted for a set number of up to 21 hours per month at a pre-agreed reduced hourly rate. This senior support would only be drawn down if needed, ensuring that the client had access to more experienced guidance for complex matters without exceeding cost parameters. Crucially, these hours would not be exceeded without the client’s explicit approval, and if the hours went unused, the client would not be charged. This arrangement provided the client with additional flexibility and peace of mind, knowing they could access senior expertise within a controlled budget.

3. How Did They Benefit?

The client benefited from a tailored, cost-effective solution by utilising a junior resource from Poland for the majority of tasks, enabling them to meet their programme needs without exceeding their budget. The pre-agreed day rate for the junior ensured predictable costs, while the agreed hours for senior support provided flexibility to draw on more experienced legal guidance when needed, without any hidden or unexpected charges.

This model gave the client complete control over costs, allowing them to access senior expertise only when necessary, ensuring the budget for the GDPR programme was adhered to. By limiting the need for senior involvement to more complex matters and handling junior-level tasks efficiently, the client’s legal team could focus on higher-level strategic work.

The arrangement also allowed the client to scale support as needed. Having both junior and senior resources available within defined cost parameters meant the client could manage their GDPR programme effectively, ensuring compliance with data protection regulations while maintaining budget control. The additional flexibility of not being charged for unused senior support hours provided further financial predictability, contributing to the overall success of their GDPR compliance efforts.

Find out more about how we can help you manage short-term challenges and keep your projects on track with our Data Protection Extend & Accelerate service

Further Reading