Sprggun

Mobile Navigation Menu

Privacy & data protection

For organisations that need privacy to work in practice - not just on paper.

Regulators are more active than ever - under GDPR, UK GDPR, the Data (Use and Access) Act 2025, CCPA, CPRA, LGPD, PIPL, and frameworks across Asia-Pacific, Latin America, and beyond. The ICO, the CNIL, the Irish Data Protection Commission, the EDPB, and supervisory authorities across the US and Asia-Pacific are looking past documentation to what organisations actually do with personal data, and whether they can demonstrate it. Customers increasingly are too.

Privacy is one of the few areas where getting it wrong is simultaneously a regulatory problem, a reputational problem, and a commercial problem. Done well, it's a trust enabler: something customers, investors, and partners actively look for.

Our work is founder-led, drawing on board-level privacy leadership at a FTSE 100 organisation, senior roles within US technology organisations, and experience across financial services, FMCG, workforce solutions, and high-growth environments.

Most organisations we work with have policies, a privacy notice, maybe a DPO. What they often don’t have is a programme that could withstand a regulator walking in, a journalist asking questions, or a major customer doing due diligence.


Two service packages - available as standalone engagements or as part of a broader privacy programme:

Fractional Chief Privacy Officer (CPO)

Senior privacy leadership for organisations that need a privacy leader at board and executive level:

  • Privacy deep dive - an independent assessment of your privacy position, required before any retainer engagement
  • Fractional CPO retainer - Foundation, Core, Extended, or Complex (8-20 hours per month)
  • Senior privacy advisory to board and executive leadership - tailored to the organisation's strategic and regulatory context
  • Regulatory engagement and supervisory authority relationships - including named DPO registered with relevant supervisory authorities where required

This is not an administrative or DPIA service. It's the kind of senior presence that changes how an organisation thinks about privacy - and that can speak with authority to a regulator, an investor, or a board.

Not a framework. Not a template. Senior judgement, built from doing the job.

Find out more: Fractional CPO

Privacy assessment & remediation

Independent privacy audit, data governance review, and cyber governance - modular, tiered, and designed to give you an honest picture of your exposure before someone else finds it:

  • Privacy - independent GDPR, UK GDPR, and Data (Use and Access) Act 2025 audit, privacy programme review, regulatory readiness, and cross-border data transfer review
  • Data governance - KYD (Know Your Data), data ownership, lineage and flow mapping, and classification
  • Cyber governance - governance frameworks, incident response preparedness, third-party and supply chain risk, and alignment with NIS2, DORA, and the UK Cyber Resilience Act
  • Four tiers: Snapshot, Assessment, Extended review, Deep Dive - commission one module or all three

An honest, independent view of where you stand - before you are put under pressure.

Find out more: Privacy assessment & remediation

Beyond our two core service packages, we also provide the wider privacy and data governance work that sits behind both:

Gap analysis and programme design

We start by understanding where you actually are - identifying risks, control gaps, and maturity across your privacy programme, data governance, and cyber governance position. From there, we design governance frameworks, accountability structures, policies, and operating models that reflect how your organisation works in practice, not how a generic template assumes it does.

Data mapping, data governance and KYD

It is impossible to govern what you don't understand. Our KYD (Know Your Data) methodology gives you a structured picture of what personal data you hold, how it flows across systems, third parties, and borders, and what controls actually apply - including marketing, analytics, and cross-border transfers. The foundation everything else is built on.

Operational controls

Purpose limitation, data retention, consent and tracking mechanisms, and privacy frameworks - built around how your organisation operates and how regulators assess compliance in practice, not just on paper.

Reviews, audits, and regulatory readiness

Independent programme reviews, control effectiveness assessments, and audit readiness work - across GDPR, UK GDPR, the Data (Use and Access) Act 2025, and the growing range of global privacy frameworks. Whether you're preparing for regulatory scrutiny, a major transaction, or simply want an honest picture of where you stand, we give you findings you can act on and a clear path forward.


When we're done, you'll know where your data is, how it's used, and will be confident in your position.

Your privacy programme will run in practice, not just on paper - so that when a regulator, an auditor, a major customer, or an investor asks hard questions, you can answer them with confidence. For organisations that would benefit from ongoing senior privacy leadership as the business and regulatory landscape evolves, our fractional CPO service provides exactly that - the expertise to adapt, respond, and stay ahead, without a full-time hire.