Service
Privacy & Compliance
Data protection and compliance work translated into systems: obligations, owners, evidence and deadlines held in one place with a current view of status.
- Who it is for
- Organisations with data protection or sector compliance obligations that are currently tracked in spreadsheets, email and shared drives.
- Engagement shape
- Assessment, then implementation of the tracking system
- Typical duration
- 3 to 6 weeks assessment, implementation scoped to findings
- Starts with
- A review of the data you hold and how obligations are tracked today
Problems this addresses
Situations that lead here
If one of these is a statement you could make about your own business, this is the relevant service.
- “Our compliance process has no visibility.”
- “We cannot show what personal data we hold or why.”
- “New data protection obligations apply and we have not assessed exposure.”
- “Audit preparation consumes weeks of senior time.”
What it includes
The work, in order
Each part produces something reviewable rather than ending in a document nobody reads.
Data mapping
What personal data is collected, where it lives, why it is held, who can reach it and how long it is kept — recorded against systems rather than described in prose.
Obligation register
Requirements broken into assignable work with owners, evidence and deadlines, so status is a query rather than a meeting.
Process and notice design
Consent, subject rights, retention and breach response designed as workflows the team can actually run.
Evidence automation
Where the system can produce evidence — logs, approvals, timestamps — it does so automatically instead of relying on manual capture.
What you keep
Deliverables
Everything below remains yours and is usable by another team if the engagement ends.
- Data inventory and processing record
- Obligation register with owners and evidence requirements
- Gap assessment with prioritised remediation plan
- Subject rights, retention and breach response workflows
- Reporting view of current compliance status
Questions
Answered directly
Is this legal advice?
No. Legal interpretation stays with your counsel. This work turns their interpretation into systems, workflows and evidence that operate day to day.
Which regimes do you work with?
Primarily India's DPDP Act and GDPR, plus sector requirements in clinical and financial contexts. The method is the same: obligations become tracked work with evidence attached.
Can this run alongside an existing GRC tool?
Yes. If a tool is already in place the work focuses on making it accurate and on wiring evidence into it automatically.
Considering privacy & compliance?
A review of the data you hold and how obligations are tracked today. Send the business context and the constraint behind it, and I will reply with a direct read on the approach I would take.