Independent security assurance and editable documentation to keep organizations secure, compliant and resilient Questions? contact@rootguardsecurity.com

Privacy and GRC Advisory

Prove your data protection position, not describe it

If you have a privacy notice, an appointed owner and no way to show a customer or a regulator what is actually true, this is for you. We establish your position against the regime that applies to you, record the evidence behind every obligation, and leave you a register your own team maintains.

Basis
Quoted on agreed scope
Regimes
JDPA, UK GDPR, EU GDPR, and equivalents
Ends with
Obligation register and findings
Cadence
One off, or on a cycle

The deliverable

Every obligation lands in one of four states

This is the register you keep. The second column is usually the largest and the cheapest to close, and it is the one a gap analysis cannot tell you about.

MetEvidenced, with what was examined and the date recorded
Not evidencedBelieved to be in place and not demonstrable today
Not metA finding, with an owner and what would close it
Not applicableWritten down with the reason, never silently omitted

The problem

The notice is written. Nothing behind it is evidenced

Most organizations did something about data protection and stopped. A notice went up, somebody was named, and the matter was filed. Then a customer sends a questionnaire, or a subject makes a request, or something is lost, and the questions are operational: where is the data, who can reach it, how long do we keep it, and can you show me.

Your team probably knows most of the answers. What is missing is the evidence that they are true, held somewhere a third party can read, and a way to keep it current without the work starting over every year.

Six capabilities

What the service does

01

Applicability

Which obligations are yours, decided against your processing rather than a template, and recorded with the reason. Obligations that do not apply are written down as not applicable, because a register that silently omits one cannot be defended later.

02

Evidence against every obligation

Each requirement assessed against an artefact and a population, not a policy statement. Met, met but not evidenced, and not met are three different findings, and the middle one is usually the largest group and the cheapest to fix.

03

The operational clocks

A subject access request and a breach notification both run on a deadline. We follow each path end to end through your own published channel, because the written procedure is never the part that fails.

04

Retention as configured

What your systems actually delete, against what your policy says they do. A policy stating seven years and a system with no deletion job are two different facts, and only one of them is true.

05

Transfers and processors

Every flow leaving your jurisdiction or reaching a third party, with the agreement or condition that permits it, or the absence of one.

06

The register you keep

The deliverable that outlives the engagement. Built so your own people update it, with the method handed over, so the next cycle is a refresh rather than a repeat purchase.

What makes it different

The working paper, not the opinion

Most privacy reviews end in a judgement. Somebody experienced looked, and this is what they think. That is worth something, and it is unfalsifiable: a year later nobody can tell whether a conclusion was reached from evidence or from an afternoon.

Every conclusion here is recorded as a working paper: what was examined, across what population, what limitation applies, and what that supports. A complete population where the scale allows, a stated sample and its basis where it does not. That is the artefact your own auditor reads, the thing a customer can test, and the reason the next cycle measures change instead of starting again.

It is also why an interview never settles an obligation on its own. Somebody telling us a control is in place is recorded as somebody telling us, and it is marked as such.

Delivery

How we work with your team

Your team keeps the ground it holds

Where your people already know an answer we record it rather than rediscovering it at your expense. The engagement is shorter and you are not paying us to learn your business.

Your counsel keeps the legal call

We establish facts and flag which questions are legal. Your lawyer receives those with the evidence attached, which is a cheaper instruction than one starting from nothing.

Findings go to whoever owns them

Some are technical, some are contractual, some are a process nobody runs. They are separated by owner rather than delivered as one list that belongs to everybody and therefore to no one.

Outcomes

Your business outcomes

Answer a customer in days, not a quarter

From a register rather than a search across departments. Count the staff days your last security questionnaire consumed and the difference is the return.

Scope an incident while it still matters

Knowing what was in a system takes minutes with a register and days without, and the notification decision does not wait.

Renew the contracts that ask

Client and parent company renewals increasingly turn on a data protection answer. An organization that answers well keeps that conversation about price.

Stop paying for the same work twice

The register and the method are yours. The following cycle measures change rather than starting again.

Boundaries

What this is not

Certification

No regime here certifies data protection compliance, and anybody offering a certificate is selling something that does not exist. What you get is a position with the evidence attached.

Legal advice, or acting as your data protection officer

We are not lawyers, and the officer role requires independent monitoring of the controller, which we do not hold.

Systems testing

Security measures are assessed from evidence and configuration. Establishing whether a technical control operates is a control assessment and a separate engagement.

Questions

Common questions

Which privacy regime do you work to?

Whichever applies to you. The method is the same across regimes: establish what applies, assess each obligation against evidence, record what was examined. Jamaica's Data Protection Act, UK and EU GDPR and equivalent regimes all resolve to a set of assessable obligations, and where you carry more than one we map the overlap rather than pretending one covers the other.

We already have a privacy notice and a policy. Is that not enough?

It is the part everybody does, and it is not where the exposure is. A notice describes an intention. The questions a customer or a regulator asks are operational, and they are answered with records rather than with documents.

How is this different from a gap analysis?

A gap analysis marks obligations red, amber or green, usually from a workshop. Here every conclusion records what was examined, across what population, so somebody outside your organization can check it. That difference is the entire point, and it is what survives being questioned.

Do we have to give you access to our systems?

No. Your own administrators run any extract, and you see the output before it leaves your network. We hold no credential into your environment.

Related services: Data Discovery and RoPA Advisory · Data Protection Impact Assessment · Third-Party Cyber Risk and Vendor Due Diligence

Start with what applies to you

Which obligations are yours is answerable in a conversation, before anybody is engaged. Organizations regularly find they need less than they feared, or that the one thing they skipped is the one carrying a deadline.