Privacy and GRC Advisory
If you have a privacy notice, an appointed owner and no way to show a customer or a regulator what is actually true, this is for you. We establish your position against the regime that applies to you, record the evidence behind every obligation, and leave you a register your own team maintains.
The deliverable
This is the register you keep. The second column is usually the largest and the cheapest to close, and it is the one a gap analysis cannot tell you about.
The problem
Most organizations did something about data protection and stopped. A notice went up, somebody was named, and the matter was filed. Then a customer sends a questionnaire, or a subject makes a request, or something is lost, and the questions are operational: where is the data, who can reach it, how long do we keep it, and can you show me.
Your team probably knows most of the answers. What is missing is the evidence that they are true, held somewhere a third party can read, and a way to keep it current without the work starting over every year.
Six capabilities
01
Which obligations are yours, decided against your processing rather than a template, and recorded with the reason. Obligations that do not apply are written down as not applicable, because a register that silently omits one cannot be defended later.
02
Each requirement assessed against an artefact and a population, not a policy statement. Met, met but not evidenced, and not met are three different findings, and the middle one is usually the largest group and the cheapest to fix.
03
A subject access request and a breach notification both run on a deadline. We follow each path end to end through your own published channel, because the written procedure is never the part that fails.
04
What your systems actually delete, against what your policy says they do. A policy stating seven years and a system with no deletion job are two different facts, and only one of them is true.
05
Every flow leaving your jurisdiction or reaching a third party, with the agreement or condition that permits it, or the absence of one.
06
The deliverable that outlives the engagement. Built so your own people update it, with the method handed over, so the next cycle is a refresh rather than a repeat purchase.
What makes it different
Most privacy reviews end in a judgement. Somebody experienced looked, and this is what they think. That is worth something, and it is unfalsifiable: a year later nobody can tell whether a conclusion was reached from evidence or from an afternoon.
Every conclusion here is recorded as a working paper: what was examined, across what population, what limitation applies, and what that supports. A complete population where the scale allows, a stated sample and its basis where it does not. That is the artefact your own auditor reads, the thing a customer can test, and the reason the next cycle measures change instead of starting again.
It is also why an interview never settles an obligation on its own. Somebody telling us a control is in place is recorded as somebody telling us, and it is marked as such.
Delivery
Where your people already know an answer we record it rather than rediscovering it at your expense. The engagement is shorter and you are not paying us to learn your business.
We establish facts and flag which questions are legal. Your lawyer receives those with the evidence attached, which is a cheaper instruction than one starting from nothing.
Some are technical, some are contractual, some are a process nobody runs. They are separated by owner rather than delivered as one list that belongs to everybody and therefore to no one.
Outcomes
From a register rather than a search across departments. Count the staff days your last security questionnaire consumed and the difference is the return.
Knowing what was in a system takes minutes with a register and days without, and the notification decision does not wait.
Client and parent company renewals increasingly turn on a data protection answer. An organization that answers well keeps that conversation about price.
The register and the method are yours. The following cycle measures change rather than starting again.
Boundaries
No regime here certifies data protection compliance, and anybody offering a certificate is selling something that does not exist. What you get is a position with the evidence attached.
We are not lawyers, and the officer role requires independent monitoring of the controller, which we do not hold.
Security measures are assessed from evidence and configuration. Establishing whether a technical control operates is a control assessment and a separate engagement.
Questions
Whichever applies to you. The method is the same across regimes: establish what applies, assess each obligation against evidence, record what was examined. Jamaica's Data Protection Act, UK and EU GDPR and equivalent regimes all resolve to a set of assessable obligations, and where you carry more than one we map the overlap rather than pretending one covers the other.
It is the part everybody does, and it is not where the exposure is. A notice describes an intention. The questions a customer or a regulator asks are operational, and they are answered with records rather than with documents.
A gap analysis marks obligations red, amber or green, usually from a workshop. Here every conclusion records what was examined, across what population, so somebody outside your organization can check it. That difference is the entire point, and it is what survives being questioned.
No. Your own administrators run any extract, and you see the output before it leaves your network. We hold no credential into your environment.
Which obligations are yours is answerable in a conversation, before anybody is engaged. Organizations regularly find they need less than they feared, or that the one thing they skipped is the one carrying a deadline.