Nine obligations, and the evidence each one requires
Regulators do not ask whether you have a privacy policy. They ask you to demonstrate the obligation is met, which means artefacts rather than intentions.
Six stages, in an order that does not waste the first three
Writing policy before discovery produces a document that describes an organisation you do not have.
Discover
Automated and manual discovery across systems, databases, file shares, email, cloud and endpoints. Output is a data inventory and data flow map showing what you hold, where it sits, who touches it and where it goes.
Classify
Personal data separated from sensitive categories, health, financial, biometric, identity documents, because the obligations and the penalties differ sharply between them.
Assess
Current practice measured against the law: lawful basis per activity, consent quality, retention reality, subject rights capability, security measures and transfer mechanisms. Output is a gap register with severity and effort.
Design
Policies, notices, procedures and records built around your actual processing rather than a template. Data protection impact assessments for high-risk activities. A DPO appointed or provided.
Implement
Technical controls put in place: classification labels, access restriction, encryption, retention automation, leakage prevention and monitoring on the systems the inventory identified as material.
Operate
Rights requests answered within the window, breach procedure rehearsed, third parties assessed on a cycle, and evidence produced continuously so an inquiry is a search rather than a project.
Data protection officer as a service
A named DPO holding the statutory role: monitoring compliance, advising on impact assessments, acting as contact point for the regulator and for data subjects, and reporting to your board. Provided as a retained arrangement rather than a full-time salary.
Controller, processor, or both
Most organisations are both, on different datasets, and the obligations differ. We establish which role you hold for each processing activity, because contractual liability and regulatory duty follow that classification.
The controls that make compliance real
Data leakage prevention
A retention and purpose policy is only enforceable if something stops data leaving.
Database security
Most personal data sits in a database. Access there is the control the regulator asks about.
Incident response
Breach notification has a statutory clock. It starts whether or not you have the facts yet.
