
Contracting
Contracts form the backbone of any business relationship. We draft practical, commercially-minded IT contracts that comply with all relevant legislation and regulation, including Master Service Agreements, SLAs, licence agreements and data processing agreements. Drawing on our in-house experience, we negotiate in a pragmatic, solution-oriented way and draft agreements that actually work in practice.
We design the appropriate legal framework for IT contracts, for example a Master Service Agreement with a Statement of Work, Order Form, general terms and conditions, Service Level Agreements and data processing agreements. We also verify, where relevant, that the terms meet specific regulatory requirements, such as DORA.
We contribute to solutions for our clients. Where the mutual relationships and the relationship with the clients are central .
— Lawrence Attorneys

DPO as a Service
For a select group of clients, we act as external Data Protection Officer (DPO). We monitor compliance with the GDPR, advise the board and management, provide awareness and training programmes, and serve as the first point of contact for the Dutch Data Protection Authority.
We report periodically on compliance, risks, and remediation measures in line with Article 39 GDPR. Most importantly, we take full ownership of privacy compliance so that organisations can focus on their core business.
Legal Projects
We like efficient processes. In advance, we agree the scope, steps, fees and timelines so that every project remains predictable and manageable. Using AI-driven project tools, we deliver legal implementations without overruns in time or budget.
Our services range from essential quick fixes to full fast-track GDPR implementation within 2–3 weeks. We also provide comprehensive post-closing integration services to mitigate all risks identified during the due diligence phase and to achieve the intended synergies.

Regulatory Assistance
We have extensive experience in assisting clients with information requests or in (imminent) disputes with supervisory authorities.
We support organizations in their contact with supervisory authorities. This includes the Dutch Data Protection Authority and the Netherlands Authority for Consumers and Markets (ACM) for the Digital Services Act.
But also for DORA in relation to De Nederlandsche Bank (DNB) and the Autoriteit Financiële Markten (AFM).
Incident Support
Lawrence supports organisations with all types of incident response. We coordinate the investigation and conduct the legal analysis.
In the event of data breaches under the GDPR, we prepare the notification to the Dutch Data Protection Authority (AP) and (where necessary) draft the communication to those affected. In addition, we supervise notification and follow-up processes for cyber incidents under NIS2 and DORA.

Litigation
IT disputes require a lawyer who masters both technology and procedural law. We have that combination in-house.
We advise and litigate in disputes concerning failed implementations, SaaS and cloud contracts, licensing issues, and stalled IT projects. In addition, we assist clients in privacy proceedings: enforcement cases by the Dutch Data Protection Authority, fine objections, and claims based on the GDPR.
With the AI Act, DORA, and NIS2, we anticipate a new generation of disputes where regulatory compliance will be the battleground. Where possible, we resolve conflicts through consultation or mediation. And where necessary, we litigate in court with the sharpness required by procedural law. Our litigation experience makes us better contract lawyers, and vice versa.


