Fixed fees, partner-reviewed, SLA-backed. Built for the Lithuanian tech sector and EU-wide privacy work.
All prices shown are indicative only and are provided for general information. They do not constitute an offer or a commercially binding commitment. Fees depend on your organisation's specific needs, the scope of work and the volume and nature of the personal data processed. A tailored quote is issued only after your situation has been reviewed. Request a quote and Miglė will contact you directly. Request a quote →
All prices shown are indicative only and are provided for general information. They do not constitute an offer or a commercially binding commitment. Fees depend on your organisation's specific needs, the scope of work and the volume and nature of the personal data processed. A tailored quote is issued only after your situation has been reviewed. Request a quote and Miglė will contact you directly. Request a quote →
Outsourced DPO for organisations up to 50 employees. Quarterly check-in, email support on day-to-day privacy and data protection matters within the DPO's scope, annual training, horizon-scanning digest. DSARs, written reports and breach response are not included. Initial review available as a €2,000 bolt-on.
Outsourced DPO for organisations up to 250 employees. Initial review included. Monthly check-in, email support on day-to-day privacy and data protection matters within the DPO's scope, up to 1 DSAR per month (no rollover), quarterly written report, annual training, horizon-scanning digest. Breach response: breaches that do not need to be notified to VDAI are included, plus 1 breach response notifiable to VDAI per year; anything beyond that is out of scope.
Outsourced DPO for organisations above 250 employees. Initial review included. Bi-weekly check-in, email support on day-to-day privacy and data protection matters within the DPO's scope, up to 3 DSARs per month, monthly written report, two training sessions a year, priority breach response, VDAI liaison, horizon-scanning digest.
Four custom training sessions across the year. GDPR + AI + cyber + compliance. Continuously refreshed with new case studies from the horizon-scanning feed.
Final scope and price depend on your organisation's specific needs. The programme begins with an initial session to identify your needs, analyse them and propose a tailored training plan. Training can be delivered in person, online or in a hybrid format; in-person sessions are highly recommended.
Structured audit of your GDPR posture across HR, IT, products, marketing, sales, monitoring, websites, vendors. Produces a gap analysis, prioritised action plan, and starter RoPA where needed.
Response to a Data Subject Access Request (single subject). Identity verification, scope confirmation, response drafting, redaction guidance. Other rights requests (erasure, rectification, restriction) at lower price.
Time-sensitive breach response. Within 4 hours: initial assessment, VDAI notification draft (Article 33 GDPR), data subject notice draft (Article 34 GDPR), 72-hour clock. Base fee plus hourly above scope.
Response to a VDAI (Lithuanian DPA) information request, audit notice, complaint follow-up, or draft decision. Draft response prepared by Hexy, reviewed and signed by Migle.
Review of your cookie banner, consent flow and tracker inventory against ePrivacy + GDPR. Includes dark-pattern audit, consent record assessment, and remediation list.
Privacy Policy + Terms of Service + Cookie Policy + starter Record of Processing Activities (RoPA). Single Lithuanian/EU compliant set tailored to your business.
Article 35 GDPR Data Protection Impact Assessment. Full memo covering necessity, proportionality, risk register, and safeguards. Required before deploying high-risk processing.
Triage your AI systems against EU AI Act obligations. Risk classification (unacceptable / high / limited / minimal), conformity requirements, GPAI assessment, compliance timeline.
Full AI Act compliance programme for high-risk AI deployers and providers. Technical documentation, human-oversight design, transparency notices, conformity assessment pathway, ongoing monitoring framework.
Three-day deep dive on what else you can legally and commercially do with the data you already hold. Covers reuse, secondary purposes, anonymisation pathways, data products, monetisation, sharing arrangements.
Half-day in-person or remote GDPR workshop, up to 30 participants. Built around real Lithuanian and EU case studies — VDAI decisions, ECJ judgments, fines. Tailored to your sector.
90-minute AI Act training session. Covers prohibited practices, high-risk obligations, transparency requirements, organisational impact. Live Q&A.
Review of a mutual or one-way non-disclosure agreement. Redlines plus a summary of key risks. 4-hour turnaround for standard NDAs.
Draft a mutual or one-way NDA from scratch, tailored to your business context and Lithuanian law.
Review of a Data Processing Agreement (controller or processor side). Article 28(3) GDPR compliance check plus redlines.
Review of an incoming Master Services Agreement or SaaS subscription contract. Redlines plus risk-summary memo.
Initial assessment of a privacy / data-protection dispute (VDAI appeal, civil claim, court case). Fixed initial fee, then retainer plus hourly. Court representation in Vilnius and Lithuanian regional courts.
HEXLaw uses artificial intelligence to assist with legal analysis, drafting, and research. All AI-generated outputs are reviewed and approved by Migle Dewsbury, an assistant to an attorney-at-law (advokato padėjėja), before delivery to clients - as required under the EU AI Act.