Governance, Risk & Compliance

Data Protection & Privacy Engineering

GDPR compliance built into systems rather than bolted onto them.

The situation

Privacy work fails when it stays in the legal department. We connect the legal obligation to the technical control: mapping real data flows rather than declared ones, running DPIAs that engineers can act on, designing retention and minimisation into the architecture, and handling the international transfer analysis that most organisations still have wrong.

For EU institutions and bodies the equivalent instrument is Regulation (EU) 2018/1725, which we know from the inside.

What the client receives

Schedule of deliverables

  1. 01Data mapping and Article 30 records of processing
  2. 02DPIA and prior-consultation support
  3. 03Lawful basis and legitimate interest assessments
  4. 04International transfer analysis, SCCs and transfer impact assessments
  5. 05Privacy by design and default control patterns for engineering teams
  6. 06Data subject rights procedure and breach notification playbook
  7. 07DPO-as-a-service

Frameworks and standards

Assessment is carried out against named references, so a conclusion can be traced back to the requirement it was measured against.

  • GDPR (EU) 2016/679
  • Regulation (EU) 2018/1725
  • ISO/IEC 27701
  • EDPB guidelines

Discuss this engagement

Tell us about the processing in question and the obligation behind it and we will set out the scope, the method and the reporting format.

Contact us