Skip to main content

Practice area 04

Privacy Program Development and Management

Compliance is a state you can reach and then quietly lose. A program is the machinery that keeps you there: a known owner, a current inventory, an assessment triggered by the events that matter, and a review cycle that runs whether or not anyone is worried this quarter.

Frameworks in scope

  • GDPR Article 30 and 35
  • CPRA risk assessments
  • ISO/IEC 27701
  • NIST Privacy Framework
Schedule a Consultation
04.1

Program design and build

We design the program around your size and structure rather than an idealised org chart. For a company with no dedicated privacy staff, that means a small number of clear obligations attached to existing roles. For a company with a privacy team, it means charter, authority and reporting lines that let the team make decisions stick.

  • Governance structure with named accountability and a defined reporting line to leadership.
  • Policy set: internal privacy policy, retention schedule, rights handling, vendor management, incident escalation.
  • Control mapping that shows which single control satisfies obligations under more than one regime.
  • Metrics leadership can actually read, tied to risk and to statutory deadlines rather than to activity counts.
04.2

Data mapping

Nearly every privacy failure traces back to data no one remembered holding. Mapping is the foundation the rest of the program stands on, and it is worth doing at a level of detail you can maintain. We build an inventory at system level, keyed to purpose, legal basis, retention, recipients and transfers, and we design it so updating it is part of shipping software rather than an annual project.

  • System and process inventory covering production systems, SaaS tools and shadow IT.
  • Data flows, including onward disclosures, sub-processors and cross-border transfers.
  • Records of processing that satisfy Article 30 rather than approximating it.
  • A retention schedule with defined disposal, and a route to apply it to backups and archives.
  • Maintenance triggers tied to procurement, new features and new markets.
04.3

DPIAs and PIAs

Assessments are where a privacy program either earns its place or becomes paperwork. Done properly, an assessment is a design conversation held early enough to change the design. We provide a method, a threshold test that tells teams when an assessment is genuinely required, and enough facilitation that the first several are done to standard.

  • Screening questions that route most projects through in minutes and flag the ones that need real analysis.
  • Facilitated DPIAs for high-risk processing, including profiling, monitoring, sensitive categories and large-scale use.
  • CPRA and state-law risk assessments prepared to the form regulators are asking for.
  • Mitigations recorded with owners and dates, so an assessment produces changes rather than observations.
04.4

Ongoing management

Many companies need a privacy function but not a full-time hire. We can hold the program on a retained basis: chairing the review cycle, handling escalations, keeping the inventory and assessments current, briefing the board, and standing in front of customer security reviews and diligence questionnaires.

What you receive

Work product, dated and defensible.

Every engagement in this area is scoped to end in artefacts you can hand to a regulator, a customer or an acquirer without rewriting them first.

  • Program charter, governance model and policy set
  • Maintained data inventory and Article 30 records
  • Retention schedule with disposal procedures
  • DPIA and PIA method, templates and threshold test
  • Completed assessments for current high-risk processing
  • Board reporting pack and program metrics

How the engagement runs

Four stages, agreed before we start.

  1. 01

    Baseline

    Establish what exists today: systems, data, contracts, policies, and the people who are already doing privacy work informally.

  2. 02

    Design

    Agree the governance model, the policy set, and the assessment method, sized to the company you are rather than the one on the org chart.

  3. 03

    Implement

    Build the inventory, run the first assessments, and put the review cycle in motion with the owning teams.

  4. 04

    Manage

    Run or support the program on a retained basis, with scheduled reviews and a standing escalation route.

Common questions

Asked before most engagements.

We are twenty people. Is a privacy program overkill?

The obligations do not scale down as neatly as the headcount does, but the program should. At that size it is usually one owner, one inventory, a short policy set, and a screening test for new projects. What matters is that it exists and is current.

Do we need to appoint a Data Protection Officer?

Only some organisations do, and the criteria are specific. Appointing one when you are not required to carries obligations of its own. We work through the test and document the decision either way.

Can you run the program rather than advise on it?

Yes. Retained program management is a normal engagement here, including chairing reviews, maintaining the inventory, and handling customer diligence directly.

Build the program once, properly.

We will look at what you already have and tell you what is missing before you commit to anything.