GDPR  ·  COMMERCIAL CONTRACTS  ·  EU MARKET ENTRY  ·  CIPP/E

Launch in the EU — and hold up when customers, regulators and investors check.

Legal counsel for SaaS & AI companies entering the EU market — the contracts, GDPR and AI Act work that deals and audits hinge on.

Fixed prices·Plain English·No billable-hour games

30 minutes · no pitch · you leave with a plan

7+ years in-house at international tech & telecom · CIPP/E certified (IAPP)

EU AI Act · Art. 50 · Transparency · In force
AI-generated content rules have applied since 2 August 2026.
See the fixed-price Art. 50 check →

Who I work with

If one of these is you, we should talk.

SaaS founders selling to EU customers

B2B or B2C — if your users are in the EU, European law applies to you, wherever you're incorporated. Most US-template legal docs don't survive contact with it.

AI products generating content

Video, image, audio, or text generation for EU users triggers marking and disclosure duties from August 2026. I scope exactly what Art. 50 requires from your product — and cover the GDPR layer, which for GenAI products is usually the harder part.

Ukrainian & CEE tech expanding west

Entering the EU or US market and need the legal layer done right the first time — in your language, at sane prices, by someone who's done it from the inside.

Teams without a full-time lawyer

Senior legal support on demand — contract reviews, privacy questions, vendor DPAs — without the cost of a hire.

Services & fees

Fixed prices and a written scope agreed before work starts. Every project includes one revision round, a handover call, and 14 days of follow-up questions.
Packages — for a defined business moment
§1

EU Market-Entry Package

Everything you need to sell to EU customers without a regulatory blocker — in four weeks.

Regulatory mapping (GDPR roles, AI Act applicability screening, ePrivacy), geo & sanctions scope, structuring flags (Art. 27 representative, EU entity, VAT), the core document set, and a written 6–12 month roadmap.

4 WEEKS · FIXED DELIVERABLES LIST AGREED UPFRONT

from $2,900
§2

SaaS Legal Pack

The documents your users accept at sign-up — and your enterprise buyers check before signing.

ToS aligned with EU consumer law, GDPR-compliant Privacy Policy, Cookie Policy, AUP, and a standard DPA — plus a practical memo on liability and key risks.

2–3 WEEKS · EDITABLE DOCUMENTS IN PLAIN ENGLISH

from $1,800
§3

GDPR Compliance Audit

Know exactly where you would fail a regulator or an enterprise security review — and what to fix first.

A review of how your company actually handles personal data — lawful bases, ROPA, vendor DPAs, data subject rights, transfers — with risk-ranked findings and a remediation roadmap. DPIA, if required, is scoped separately. Not sure where you stand? Try the free interactive self-check →

3–4 WEEKS · NOT A CHECKBOX EXERCISE

from $2,000
Fixed-fee services
§4

Commercial Contract Review & Drafting

Senior review or drafting of your commercial documents — MSAs, SaaS agreements, SLAs, vendor and partnership contracts, NDAs and other commercial contracts — with markup and plain-language recommendations. Optional add-on: counterparty sanctions screening (EU · OFAC · UK).

3–5 BUSINESS DAYS · RUSH AVAILABLE · SIMPLE DOCUMENTS (NDA) FROM $200

from $450
§5

DPA Review & Drafting

Data Processing Agreements reviewed or drafted with the annexes done properly — technical and organisational measures, sub-processor terms, transfer mechanics. Cross-border transfers needing SCCs and a transfer impact assessment are the usual scope extension.

3–5 BUSINESS DAYS

from $450
§6

Data Protection Impact Assessment (DPIA)

A regulator-ready DPIA for a specific processing operation: description of the processing, necessity and proportionality, risks to individuals, and mitigation measures — following the EDPB methodology. Usually commissioned after an audit flags the need.

1–2 WEEKS · PER PROCESSING OPERATION

from $900
§7

AI Transparency Compliance Check (EU AI Act)

Your product mapped against Art. 50 by a lawyer: which duties actually attach to you as provider or deployer, where the gaps are, and the exact disclosure texts to implement. Delivered as a written memo you can show to an enterprise customer, an investor or a regulator — the free checklist tells you the rules, this tells you where you stand. Included in the EU Market-Entry Package as a screening step.

1 WEEK · FIXED PRICE · PAIRS WELL WITH ANY GDPR PACKAGE

$700fixed
§8

Policy Review & Upgrade

A legal review of the customer-facing documents you already have — ToS, Privacy Policy, Cookie Policy, AUP, Refund Policy — against EU requirements: a redline plus a short memo on what needs fixing and why.

3–5 BUSINESS DAYS PER DOCUMENT

from $300per document
Standalone documents
Privacy Policyfrom $450
Terms of Servicefrom $500
Cookie Policyfrom $300
Acceptable Use Policyfrom $300
Refund Policyfrom $250

Need three or more documents? The SaaS Legal Pack covers ToS, Privacy, Cookie, AUP and a DPA at better value. Already have documents? Review & upgrade — from $300 per document (§8).

Other documents — SLA, EULA, beta and trial terms, referral and affiliate terms, community guidelines, DMCA/takedown policy — from $250 to $700 depending on complexity. Email the details and get a fixed quote within 24 hours →

Ongoing counsel — Fractional Legal Counsel
Lite
$550/ month
  • 6 hours per month
  • Ad-hoc questions & simple reviews
  • Response within 2 business days
Standard
$1,500/ month
  • 17 hours per month
  • + drafting, DPAs, negotiations
  • Response within 1 business day
Pro — Privacy Lead
$2,700/ month
  • 27 hours per month
  • + privacy operations: ROPA, DPIAs, incidents, vendor reviews
  • Same-day response

The monthly fee is fixed. Hours show how much work each plan covers — anything beyond it gets a fixed price agreed before I start. Cancel with 30 days’ notice.

Not sure which one fits? Answer a few quick questions →

Document work? Skip the call.

For contract reviews, DPAs, and policy work, email the document (or a link) with two lines of context — you get a fixed quote within 24 hours. No call required; the quote is binding once you confirm scope.

Email for a fixed quote →

Find your package

Four questions, 60 seconds. You get a recommendation and a starting price — the exact quote comes after a short call.
Diia City · Ukraine

Building a team in Ukraine?

Ukraine runs a special legal regime for tech companies — Diia City: 9% tax on distributed profit, flexible gig contracts with IP assignment built in, and a straightforward path for foreign founders through a Ukrainian entity. I handle residency end-to-end — eligibility audit, application, gig-contract templates, and the internal paperwork.

Ask about Diia City on a call

Free tools

Two self-checks you can run before talking to anyone — including me.

AI Act Transparency Checklist

Does Art. 50 apply to your product, and does it meet obligations that are already in force? A 15-minute self-check: five triggers, scenario-by-scenario items, and the red flags that mean you need more than transparency work.

Download the checklist (PDF)

Fillable PDF · no email required.

Want me to email you when the rules change? Leave your address — optional, and used for nothing else.

Noted — I’ll write only when Art. 50 changes.

GDPR Self-Check

An interactive gap analysis: 40 items across 10 areas — scope, data mapping, ROPA, lawful bases, vendors, data subject rights, transfers, DPIA. Mark each item red, yellow or green, export the summary, and bring it to a call.

Open the self-check →

No email required. Your marks stay in your browser.

How it works

STEP 1

Intro call — free, 20 min

You describe the situation. I tell you honestly whether and how I can help — and what it costs.

STEP 2

Fixed quote in 24h

A one-page proposal with scope, timeline, and price. No hourly surprises, ever.

STEP 3

Delivery

Documents and advice in plain language — built for founders, not for other lawyers.

STEP 4

Support

Handover call plus two weeks of follow-up questions included in every project.

Why me

I've spent 7+ years as in-house counsel at international CPaaS and telecom companies — sitting on the client's side of the table. I know what businesses actually need from a lawyer: decisions and documents, not 40-page memos.

  • CIPP/E certified (IAPP) — the global standard for European data protection
  • Hands-on with GDPR, DPAs, SCCs, and cross-border transfers daily since 2019
  • Practical sanctions-screening experience (OFAC, EU, UK)
  • Fixed prices, fast turnaround, direct communication — no associates in between

Questions founders ask

Are you qualified to advise on EU law?

I advise on GDPR and EU regulatory compliance as a compliance consultant with CIPP/E certification and years of hands-on EU privacy work for international companies. This work doesn't require admission to an EU bar. For matters that do — litigation, formal legal opinions for regulators — I bring in local counsel from my network and coordinate the process.

We're not based in the EU. Does this even apply to us?

If you have users in the EU — yes. GDPR applies to anyone offering services to people in the EU (Art. 3(2)), and the AI Act follows the same logic for AI systems whose output is used there. Where you're incorporated doesn't shield you.

What if my project doesn't fit these packages?

Most don't fit perfectly. Book a call — I'll scope it and give you a fixed quote within a day.

We already have a lawyer.

That's good — most of my clients do too. I usually come in for the EU-specific layer (GDPR, AI Act) that general counsel often outsources anyway. A second pair of senior eyes on EU compliance is cheap insurance.

Do you cover the full AI Act?

My AI Act work is focused on Article 50 — the transparency, marking, and disclosure duties for AI-generated content that apply from 2 August 2026. That's what most SaaS and GenAI products actually face right now, and I've handled it hands-on. High-risk system classification and conformity assessments are a different discipline: if that's your situation, I'll say so on the intro call and can bring in a specialist from my network rather than learn on your budget.

Can a foreign founder use Ukraine's Diia City regime?

Yes. Diia City residency requires a Ukrainian legal entity, but its founders and beneficiaries can be foreign — setting up the entity is part of the scope. The regime offers 9% tax on distributed profit and flexible gig contracts with IP assignment built in. If you're weighing it as part of your setup, we'll cover it on the intro call.

How do I know if my company has GDPR gaps?

Start with the free interactive GDPR self-check — 40 items across 10 areas, from scope and ROPA to transfers and DPIA. Mark what's in place, export the summary, and you'll see your gaps in about 15 minutes. If the red column worries you, that's exactly what the GDPR Compliance Audit turns into a prioritized remediation plan.

Does the GDPR audit include a DPIA?

No — by design. The audit determines whether any of your processing operations require a Data Protection Impact Assessment; the DPIA itself is a separate, fixed-price piece of work (from $900). That keeps the audit price honest for the majority of companies that don't need one.

Why “from” pricing?

Each base price covers a defined scope, described in the service itself. If your situation adds scope — extra products, B2C consumer law, cross-border transfers needing SCCs — the quote goes up, and the proposal lists exactly which factors shaped it. You always get a fixed number before work starts, never an hourly meter.

You're based in Ukraine — how do you ensure continuity?

Fair question. The practice runs cloud-first: documents, communication, and files live in redundant cloud services, with backup power and connectivity at the workplace. Deadlines are agreed in writing before work starts and are treated as contractual. In 7+ years of in-house work through 2022–2026, client deadlines were kept — that standard carries over here.

Our enterprise customers ask for internal policies — can you help?

Yes. Procurement questionnaires and investor due diligence often ask for a Code of Conduct, anti-bribery and whistleblowing policies, an information security policy, or a data retention policy. This isn't a fixed package — the right set depends on your headcount, market and who is asking, so it's scoped individually after a call. Bring the questionnaire you were sent and we'll work from it.

How do payments work?

Fixed fee agreed upfront. Smaller projects are paid on signing; larger ones split 50% to start, 50% on delivery. Retainers are billed monthly in advance. Invoices in USD or EUR.

Launching in the EU? Building with AI?

A 30-minute call is enough to know where you stand. No pitch — just useful answers.

Book a free intro call
Book a free intro call