Understand the data and the purpose
Map what personal information is collected, why it is used, where it is stored, and who receives it. Identify the organisation’s roles and the people responsible for each activity. This gives advisers the context needed to assess requirements and gaps.
Connect policies to working processes
A privacy notice is one part of a wider programme. Consider supplier arrangements, access, retention, individual requests, incident handling, and staff guidance. The engagement should distinguish drafting documents from implementing and checking the processes behind them.
Make the proposal comparable
Ask which activities, locations, systems, and deliverables are included. Confirm whether implementation support, staff training, recurring advice, or DPO services are part of the fee. Complexity and ongoing responsibilities affect effort, so a price without a scope can be misleading.
Agree ownership and follow-up
Assign control owners and establish a review cycle. Changes in software, suppliers, or business activities may require reassessment. Specialist advice supports the organisation, but it does not transfer all accountability or guarantee compliance. Confirm legal interpretations with qualified advisers.
Further reading
Put the guidance to work
Connect risk management, GDPR, NIS2, DORA, and ISO 27001 preparation with practical CISO and DPO support.
Governance & compliance