Privacy · P0

Privacy & Data Protection Readiness

Customers, regulators and enterprise procurement now ask the same question in different words: what personal data do you hold, why, where does it go, and who can prove it? Most growing companies have a privacy policy and a cookie banner but no data inventory, no tested subject-request process and no way to say which of the state, GDPR or sector rules actually reach them.

This assessment provides a readiness indicator based on the information provided. It does not constitute legal advice or a determination that any privacy law applies or has been complied with. Applicability and compliance should be confirmed with qualified privacy counsel.

Who it is for

The companies this problem finds first.

B2B SaaS selling into regulated or EU customers

Consumer and marketplace businesses with U.S. multi-state footprints

Healthcare-adjacent and fintech-adjacent companies that are not the covered entity but process the data

Any company that has received a DPA, a DPIA request or a subject-access request it could not answer quickly

When it comes up

The moments that turn this from a someday into a now.

  • Customer DPA or privacy addendum
  • Expansion into the EU, UK or a new U.S. state
  • Data subject request or complaint
  • New product using customer data for analytics or AI
  • Breach or near miss involving personal data
  • Insurer or board asks about privacy exposure
What we assess

8 areas, one control library.

Every area maps to controls already in the platform's single control library, so evidence collected here counts toward every other framework the business has adopted.

Privacy governance and accountability

Data inventory and records of processing

Data lifecycle: collection, use, retention, deletion

Data subject rights handling

Third-party and processor management

International data transfers

Privacy incident and breach readiness

Privacy by design and DPIA

What you get

Deliverables you can hand to a buyer, a board or a regulator.

  • Privacy applicability map (which laws MAY reach you and why)
  • Data inventory and records-of-processing baseline
  • Data subject request readiness test
  • DPIA tracker and privacy-by-design checklist
  • Third-party and transfer risk register
  • Privacy incident readiness workflow with legal-review checkpoints
  • Remediation roadmap 0-30 / 31-90 / 91-180 / 181-365 days
Frameworks behind it

The sources every control cites.

Requirement statements are plain-English summaries for planning; the source instrument controls. Which of these reach your business is a question the assessment records with its reasoning, not one this page answers.

  • NIST Privacy Framework 1.0
  • General Data Protection Regulation (Regulation (EU) 2016/679)
  • California Consumer Privacy Act (as amended by CPRA)
  • Virginia Consumer Data Protection Act (VCDPA)
  • Colorado Privacy Act (CPA)
  • Connecticut Data Privacy Act (CTDPA)
  • Texas Data Privacy and Security Act (TDPSA)
  • Utah Consumer Privacy Act (UCPA)
  • Florida Digital Bill of Rights (FDBR)
  • ISO/IEC 27001
Value by role

What each executive gets out of it.

CEO

Close enterprise and EU deals without privacy becoming the last-minute blocker.

CFO

Turn an unbounded regulatory exposure into a scoped, prioritised programme with known cost.

CTO / engineering

Know exactly which systems hold personal data and what has to happen when a customer asks for it back.

General counsel

Documented applicability reasoning and a tested breach workflow with legal review built in.

CISO / security lead

One data inventory that serves privacy, security and incident response instead of three spreadsheets.

How it fits

Integrated capabilities, not a separate programme.

Engagement tiers

Compliance · Enterprise Growth · Continuous Assurance. Tiers describe depth and cadence; there is no per-regulation price.

Usually bought by

General counsel, DPO / privacy, Chief product officer, CISO / security lead, CEO

Part of these packages

SaaS Enterprise Readiness · Healthcare Security · Fintech Security · EU Expansion

FAQ

The objections, answered directly.

Those are outputs. Regulators and enterprise buyers ask for the inputs: the inventory, the request process, the processor list and the reasoning about which laws apply.

As a processor you carry contractual obligations in every DPA you signed, and several U.S. state laws and GDPR reach processors directly.

Counsel decides legal applicability; this service gives them the facts, the data map and the operational evidence they cannot produce themselves, and it keeps every legal question on a review queue.

Start with the free check.

Privacy Readiness Check: a short, scored indicator of where you stand and the evidence that would close each gap. A consultant follows up to scope the full readiness engagement.

Start the free Privacy Readiness CheckSpeak with an advisor