Practice area 04
Privacy Program Development and Management
Compliance is a state you can reach and then quietly lose. A program is the machinery that keeps you there: a known owner, a current inventory, an assessment triggered by the events that matter, and a review cycle that runs whether or not anyone is worried this quarter.
Frameworks in scope
- GDPR Article 30 and 35
- CPRA risk assessments
- ISO/IEC 27701
- NIST Privacy Framework
Program design and build
We design the program around your size and structure rather than an idealised org chart. For a company with no dedicated privacy staff, that means a small number of clear obligations attached to existing roles. For a company with a privacy team, it means charter, authority and reporting lines that let the team make decisions stick.
- Governance structure with named accountability and a defined reporting line to leadership.
- Policy set: internal privacy policy, retention schedule, rights handling, vendor management, incident escalation.
- Control mapping that shows which single control satisfies obligations under more than one regime.
- Metrics leadership can actually read, tied to risk and to statutory deadlines rather than to activity counts.
Data mapping
Nearly every privacy failure traces back to data no one remembered holding. Mapping is the foundation the rest of the program stands on, and it is worth doing at a level of detail you can maintain. We build an inventory at system level, keyed to purpose, legal basis, retention, recipients and transfers, and we design it so updating it is part of shipping software rather than an annual project.
- System and process inventory covering production systems, SaaS tools and shadow IT.
- Data flows, including onward disclosures, sub-processors and cross-border transfers.
- Records of processing that satisfy Article 30 rather than approximating it.
- A retention schedule with defined disposal, and a route to apply it to backups and archives.
- Maintenance triggers tied to procurement, new features and new markets.
DPIAs and PIAs
Assessments are where a privacy program either earns its place or becomes paperwork. Done properly, an assessment is a design conversation held early enough to change the design. We provide a method, a threshold test that tells teams when an assessment is genuinely required, and enough facilitation that the first several are done to standard.
- Screening questions that route most projects through in minutes and flag the ones that need real analysis.
- Facilitated DPIAs for high-risk processing, including profiling, monitoring, sensitive categories and large-scale use.
- CPRA and state-law risk assessments prepared to the form regulators are asking for.
- Mitigations recorded with owners and dates, so an assessment produces changes rather than observations.
Ongoing management
Many companies need a privacy function but not a full-time hire. We can hold the program on a retained basis: chairing the review cycle, handling escalations, keeping the inventory and assessments current, briefing the board, and standing in front of customer security reviews and diligence questionnaires.
What you receive
Work product, dated and defensible.
Every engagement in this area is scoped to end in artefacts you can hand to a regulator, a customer or an acquirer without rewriting them first.
- Program charter, governance model and policy set
- Maintained data inventory and Article 30 records
- Retention schedule with disposal procedures
- DPIA and PIA method, templates and threshold test
- Completed assessments for current high-risk processing
- Board reporting pack and program metrics
How the engagement runs
Four stages, agreed before we start.
- 01
Baseline
Establish what exists today: systems, data, contracts, policies, and the people who are already doing privacy work informally.
- 02
Design
Agree the governance model, the policy set, and the assessment method, sized to the company you are rather than the one on the org chart.
- 03
Implement
Build the inventory, run the first assessments, and put the review cycle in motion with the owning teams.
- 04
Manage
Run or support the program on a retained basis, with scheduled reviews and a standing escalation route.
Common questions
Asked before most engagements.
We are twenty people. Is a privacy program overkill?
The obligations do not scale down as neatly as the headcount does, but the program should. At that size it is usually one owner, one inventory, a short policy set, and a screening test for new projects. What matters is that it exists and is current.
Do we need to appoint a Data Protection Officer?
Only some organisations do, and the criteria are specific. Appointing one when you are not required to carries obligations of its own. We work through the test and document the decision either way.
Can you run the program rather than advise on it?
Yes. Retained program management is a normal engagement here, including chairing reviews, maintaining the inventory, and handling customer diligence directly.
Related practice areas
- 01
Data Privacy Compliance
GDPR, CCPA and CPRA, HIPAA and the widening set of US state privacy laws, mapped to how your company actually handles personal data.
Read more - 02
AI Governance and Ethics Consulting
Risk assessments, governance frameworks and policy for teams deploying machine learning, so responsible AI becomes a control rather than a statement of intent.
Read more - 03
Data Security and Breach Response
Incident response planning before an event, and counsel-led investigation, notification and regulator handling during one.
Read more
Build the program once, properly.
We will look at what you already have and tell you what is missing before you commit to anything.