Privacy Policy & Data Sovereignty
How Harris & Group Law Firm protects executive information, legal communications, and corporate data across European and global operating jurisdictions.
Last Updated: September 2026 • Milan Headquarters
1. Regulatory Framework & Data Controller
Harris & Group Law Firm ("H&G", "the Firm", "we", or "our"), headquartered at Via Monte Napoleone 8, 20121 Milano MI, Italy, acts as the Data Controller under Regulation (EU) 2016/679 (General Data Protection Regulation / GDPR) and the Italian Data Protection Code (Legislative Decree no. 196/2003, as amended by Legislative Decree no. 101/2018). We handle all personal data under strict compliance with Italian bar ethics and international confidentiality standards.
2. Attorney-Client Privilege & Information Collection
All corporate, financial, and personal information submitted through our intake forms, secure portals, or client consultations is protected under legal professional privilege (Segreto Professionale, Art. 200 Italian Code of Criminal Procedure). We collect names, corporate emails, jurisdiction details, and matter briefings solely to evaluate engagement, verify conflicts of interest, and deliver high-stakes advocacy.
3. Legal Basis & Purposes of Processing
Data processing is executed under strict legal grounds: (a) Performance of a Contract / Pre-contractual Steps pursuant to Art. 6(1)(b) GDPR; (b) Compliance with Statutory Legal Obligations pursuant to Art. 6(1)(c) GDPR, including Anti-Money Laundering (AML) directives; and (c) Legitimate Interest pursuant to Art. 6(1)(f) GDPR for safeguarding firm IT infrastructure and establishing, exercising, or defending legal claims.
4. Cross-Border Data Transfers
As an international law firm with liaison desks outside the European Economic Area (EEA), any cross-border data transfer is safeguarded through EU Standard Contractual Clauses (SCCs), adequacy decisions under Art. 45 GDPR, or encrypted client communications approved under European Data Protection Board (EDPB) directives.
5. Retention Schedules & Encryption Standards
Inquiry data that does not lead to formal engagement is purged or anonymized within 180 days. Client mandate archives are stored in encrypted European cloud datacenters and retained for a minimum of 10 years in compliance with Italian Civil Code obligations (Art. 2220) and statutory limitation periods.
6. Your Rights Under GDPR
You maintain statutory rights to access (Art. 15 GDPR), rectify (Art. 16), erase (Art. 17), restrict processing (Art. 18), obtain data portability (Art. 20), and object (Art. 21). Requests regarding your personal data should be directed to our Data Protection Officer at privacy@harrisgroup-law.it.
Initiate Data Governance Inquiries
For formal GDPR requests or data protection disclosures, contact our privacy desk in Milan at privacy@harrisgroup-law.it or submit a request via our Confidential Contact Portal.