IT security intelligence. Since 2006.Cloudflare services ↗
TRUST-IT / Practical guide

How to scope a practical GDPR consulting engagement

The right scope depends on how your organisation uses personal information. Start with processing activities, responsibility, and evidence rather than a generic package.

Mapping data processing and privacy controls

Understand the data and the purpose

Map what personal information is collected, why it is used, where it is stored, and who receives it. Identify the organisation’s roles and the people responsible for each activity. This gives advisers the context needed to assess requirements and gaps.

Connect policies to working processes

A privacy notice is one part of a wider programme. Consider supplier arrangements, access, retention, individual requests, incident handling, and staff guidance. The engagement should distinguish drafting documents from implementing and checking the processes behind them.

Make the proposal comparable

Ask which activities, locations, systems, and deliverables are included. Confirm whether implementation support, staff training, recurring advice, or DPO services are part of the fee. Complexity and ongoing responsibilities affect effort, so a price without a scope can be misleading.

Agree ownership and follow-up

Assign control owners and establish a review cycle. Changes in software, suppliers, or business activities may require reassessment. Specialist advice supports the organisation, but it does not transfer all accountability or guarantee compliance. Confirm legal interpretations with qualified advisers.

Further reading

Put the guidance to work

Connect risk management, GDPR, NIS2, DORA, and ISO 27001 preparation with practical CISO and DPO support.

Governance & compliance

What’s your next
technology challenge?

Talk to our team