OXYGY and Bird & Bird partnered with a global retailer operating in 18 countries to implement GDPR and CCPA compliance strategies. The initiative aimed to introduce a robust data protection program and support the deployment of new data management software, empowering the company to meet stringent regulatory requirements while building a strong foundation for data governance.

The global retailer faced a daunting task in aligning with GDPR and CCPA regulations. With limited expertise and ownership of data privacy across the different markets, the organization grappled with fragmented data management and governance practices. These challenges extended across five critical workstreams: Legal, IT Systems, Data Governance, Change Management, and Project Management. To achieve compliance, the company needed a cohesive strategy that would not only meet complex regulatory demands but also embed lasting internal capabilities for ongoing governance and resilience.
To address these challenges, OXYGY, Bird & Bird, and the client worked together, blending expertise with a practical and results-driven approach. OXYGY developed a change management strategy, engaged decision-makers to align on priorities and provided hands-on project management to drive progress. They strengthened internal data privacy capabilities, introduced a forward-thinking governance model, and delivered targeted training to empower data custodians to sustain momentum and take ownership. On the technology front, they led the rollout of advanced data management software, streamlining and centralizing data protection processes to establish a solid foundation for enduring governance. Bird & Bird complemented these efforts with their legal and compliance expertise, crafting a tailored GDPR compliance strategy that seamlessly integrated into operations. They developed critical documentation, processes for handling data breaches and subject access requests, and guided the system’s implementation.
The project achieved transformative results for the global retailer. The team successfully set up a bottom-up data protection compliance program, designing and implementing new data protection procedures that aligned with GDPR and CCPA standards. The introduction and administration of the new data management tool empowered the client to manage data governance effectively across its operations. Additionally, the project delivered required documentation, introduced critical processes to handle regulatory requirements, and established a fully functioning governance team. These efforts not only ensured regulatory compliance but also equipped the retailer with the tools and expertise needed to navigate an increasingly complex data privacy landscape.
Voices from the project

This has been a demanding but rewarding project for its international scope and tight deadlines. The turning point has been winning trust and commitment of the data custodians in the 18 countries to ensure true compliance adoption and at the same time develop their capabilities. The integration of a UK based central team and of the local custodians evolved in the future data governance.
Explore More Transformation Successes




