Privacy assessment & remediation
An honest, independent view of where you stand - before someone else finds out first.
When privacy goes wrong, it goes wrong fast.
A regulator investigation. A major customer pulling due diligence. A data breach that turns a technical problem into a board crisis. An investor asking questions you can't answer with confidence. These aren't hypothetical risks - they're the moments that expose the gap between having a privacy programme and having one that actually holds up.
Our reviews draw on direct experience of major incidents and near-misses, board-level privacy leadership, and deep knowledge of what regulators look for and where the real gaps tend to sit.
Does any of this sound familiar?
>You've had an incident - or a near-miss - and you're not confident you fully understand your exposure.
>You're growing fast, entering new markets, or launching new products, and privacy hasn't kept pace.
>You have legacy systems where nobody has a clear picture of what data sits where or what controls actually apply.
>A regulator, auditor, major customer, or investor has asked questions you couldn't answer with complete confidence.
>You know there are gaps. You just don't know where they are or how serious they are.
How it works
Privacy, data governance, and cyber don't sit in neat silos, and the issues organisations face rarely do either. A data governance gap often has privacy implications. A cyber governance weakness frequently creates regulatory exposure. And the stakeholders needed to fix one are often different from those needed to fix another. We offer all three modules because the problems are connected - and because addressing them in a joined-up way, under one engagement, is what gives you a complete picture rather than three partial ones.
Pick your area, or combine them. Commission one, two, or all three modules. Where you commission multiple modules, each runs as its own workstream, giving you genuine depth in each area, brought together in a single combined report at the end.
Where documentation is limited or incomplete, structured interviews will be needed - in which case an Assessment is the right starting point rather than a Snapshot. We'll advise before we begin.
The modules
Privacy
How your privacy programme holds up against regulatory expectations - governance frameworks, accountability structures, data flows, consent and tracking, data subject rights, and cross-border considerations. Relevant frameworks include GDPR, UK GDPR, the Data (Use and Access) Act 2025, CCPA, CPRA, LGPD, PIPL, PDPA (Singapore), PDPA (Thailand), PIPA (South Korea), PDPA (Malaysia), KVKK (Turkey), and emerging global requirements.
Data governance
How data is owned, managed, and governed across your organisation - data ownership structures, lineage and flow mapping, data quality, classification, and visibility across systems, marketing, and analytics. Includes application of our KYD (Know Your Data) methodology where relevant.
Cyber governance
How your cyber governance position holds up from a regulatory and organisational perspective - governance frameworks and accountability structures, incident response preparedness, third-party and supply chain cyber risk governance, and alignment between cyber and privacy programmes. Our work is informed by experience across NIS2, the UK Cyber Resilience Act, DORA, and the growing intersection between cyber, privacy, and data governance obligations globally.
Our Cyber module covers regulatory and governance advice - not penetration testing, technical security assessment, or managed security services.
Privacy module tiers
| Tier | What it involves | Delivered as |
|---|---|---|
| Snapshot | Rapid review of key documentation – policies, notices, consent mechanisms, and governance structures. Best where documentation is well developed. | Findings summary with prioritised recommendations. |
| Assessment | Document review plus structured interviews. A fuller picture of how privacy operates in practice across legal, compliance, technology, and the business. | Report with findings and remediation plan, presented to leadership. |
| Extended review | Broader scope - suited to post-incident situations, regulatory preparation, or where privacy intersects with data governance and cyber. Can be mobilised quickly where urgency requires. | Detailed findings report, presented to leadership. |
| Deep dive | Comprehensive review across documentation, interviews, and full analysis. For organisations preparing for a regulatory moment, major transaction, or serious programme rebuild. | Comprehensive report with risk assessment and remediation roadmap, presented to leadership. |
All tiers are available for the Privacy module as a standalone commission.
Our Data governance and Cyber governance modules follow the same tier structure and are available alongside or independently. Details on request.
What gets delivered
- Snapshot - written findings summary with prioritised recommendations
- Assessment - written report with findings and prioritised remediation plan, presented to leadership
- Extended review - detailed findings report with remediation priorities, presented to leadership
- Deep dive - comprehensive report with findings, risk assessment, and detailed remediation roadmap, presented to leadership
On concluding the module, you'll know exactly where you stand - what the real risks are, what matters most, and what to do about it. Whether you're preparing for scrutiny, dealing with the aftermath of an incident, or simply want to get ahead of a problem before it finds you, you'll have an honest picture and a clear path forward.
Privacy, data governance, and cyber done well isn't just protection. It's the foundation for moving faster, responding with confidence, and turning compliance into commercial advantage.