Evidence-led
Findings are tied to available records, configurations, metadata, interviews and approved technical observations.
Evaluate how personal data is collected, used, stored, shared, accessed, retained, deleted and governed across the agreed enterprise scope. The assessment connects documented privacy requirements with operational evidence so leaders can see control gaps, exposure, ownership and remediation priorities.
Assessment scope, technical access, evidence handling, jurisdictions, deliverables, timeline and commercial terms are agreed before work begins. This service is not legal advice, statutory audit or certification.
Findings are tied to available records, configurations, metadata, interviews and approved technical observations.
Scope follows personal data from collection and use through sharing, rights handling, retention, deletion and disposal.
Privacy, security, identity, lifecycle, supplier and monitoring evidence is considered where relevant to a finding.
Outputs are organised to support prioritisation, ownership, follow-up investigation and implementation planning.
Privacy obligations are implemented through business processes, applications, identities, vendors, data stores and operating teams. The assessment tests the gap between documented expectations and the evidence that shows how personal data is actually handled.
Applications, data stores, exports, analytics, files or new digital services may process personal data without a complete and current record of purpose, owner and data categories.
Data collected for one business need can be copied, enriched or reused in analytics, operations or AI without equivalent updates to privacy requirements and evidence.
Access, correction, deletion, preference and retention processes may work in core applications while downstream copies, archives, logs or vendors follow different practices.
Business owners, application teams, privacy, security, legal, data and supplier managers may each hold part of the control story without one accountable evidence view.
Broad roles, privileged identities, service accounts, shared folders or weak logging can create privacy exposure even when policy and notice documentation appears complete.
Processors, SaaS platforms, data products, profiling, model training, retrieval and derived attributes can introduce new sharing, inference, retention and transparency questions.
Start with the processes, systems, jurisdictions and control questions creating the most uncertainty. Scope can focus on one priority area or build an enterprise-wide view of privacy readiness.
A Privacy Data Assessment combines business, privacy and technical evidence to evaluate how personal data is handled against agreed requirements and risk criteria. It can review processing inventories, notices, purpose, data categories, flows, minimisation, rights handling, consent or preference signals, retention, access, supplier arrangements, security dependencies and evidence across the agreed scope.
The objective is not to perform a superficial compliance checklist. It is to establish which privacy controls are operating as intended, where evidence is weak or contradictory, where processing creates material risk, who should own remediation and which decisions need specialist legal, security or governance input.
The final scope is tailored to the decision, risk and evidence available. These domains show the typical lenses used to turn privacy requirements and operating evidence into enterprise-ready findings.
Validate where personal data is processed and connect systems, data stores and flows to accountable processing activities.
Review available evidence for why data is collected and used, what individuals are told and where specialist legal confirmation is required.
Assess whether collection, derived attributes, copies and reuse appear proportionate to the documented business need and risk context.
Review request workflows, identity checks, downstream execution, consent or preference records and operational ownership where applicable.
Compare retention requirements with system behaviour, archives, backups, downstream copies and evidence of deletion or disposal.
Review role design, privileged access, service identities, separation, monitoring and other security controls that materially affect privacy risk.
Assess processor and supplier relationships, data sharing, onward use, transfer or residency context and available due-diligence evidence.
Link requirements and observations to policies, owners, approvals, metrics, exceptions, evidence quality, findings and practical next actions.
A useful privacy assessment follows processing across the enterprise rather than treating policy, technology and suppliers as separate control worlds. The map below illustrates the locations and cross-cutting privacy controls that can form the assessment boundary.
Define the priority processing activities, systems and evidence sources first, then connect privacy requirements to operational controls, ownership, exceptions and remediation instead of producing a checklist without evidence.
The engagement can start with imperfect evidence. Missing or conflicting evidence is recorded as a limitation or finding rather than silently replaced with assumptions.
Application inventories, database lists, cloud accounts, storage locations, SaaS systems, architecture diagrams, interfaces and data-platform catalogues.
Processing records, data-flow diagrams, business process maps, collection points, recipient categories, vendors, transfers and downstream uses.
Identity roles, privileged-access records, classifications, retention schedules, deletion procedures, monitoring, DLP or discovery outputs and exceptions.
Data or system owners, privacy and security policies, audit issues, incidents, risk registers, third-party responsibilities and approved legal or compliance interpretations.
| Assessment question | Evidence commonly reviewed | Potential finding type | Decision supported |
|---|---|---|---|
| What personal-data processing is in scope? | Processing records, application inventories, metadata, data-flow diagrams, approved discovery output | Missing activity, incomplete inventory, unowned processing | Scope correction and accountability |
| Is purpose and transparency evidence aligned? | Privacy notices, process maps, product requirements, approved legal inputs, owner interviews | Unclear purpose, notice mismatch, unsupported reuse, missing decision evidence | Purpose, transparency and specialist review |
| Are minimisation and rights controls operating? | Field inventories, collection journeys, consent or preference records, rights workflows, downstream tickets | Excess collection, incomplete rights execution, weak preference enforcement | Control remediation and workflow redesign |
| Who can access personal data and why? | Role models, groups, service identities, privileged-access records, approval and review evidence | Broad access, inherited permissions, weak recertification, unclear owner | Access remediation and accountability |
| Are retention and deletion controls effective? | Retention schedules, archive rules, backup policies, deletion jobs, exception records | Over-retention, inconsistent lifecycle, untested or incomplete deletion | Retention, disposal and exception action |
| Are suppliers, sharing and transfers controlled? | Processor records, contracts, due-diligence evidence, interfaces, exports, residency and transfer documentation | Unknown recipient, weak supplier evidence, undocumented onward use or transfer | Supplier remediation and transfer review |
| Can material privacy controls be evidenced? | Policies, approvals, logs, configurations, reports, tests, exceptions and accountable sign-off | Policy-to-operation evidence gap | Assurance, remediation and retest planning |
Regulatory references are used only when relevant to the organisation, jurisdiction and processing context. The assessment structures evidence and control questions; it does not replace authorised legal interpretation.
The Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 have staged commencement. Where India is in scope, assessment criteria should be checked against the provisions in force on the review date and the organisation's approved legal interpretation.
MeitY DPDP Rules & timeline ↗GDPR Article 5 principles such as purpose limitation, data minimisation and storage limitation, together with Article 30 processing-record expectations, can inform assessment evidence for organisations subject to the Regulation.
EUR-Lex GDPR text ↗ISO/IEC 27701:2025 can provide a current privacy information management reference point for organisations managing personally identifiable information. Use as a benchmark does not imply certification.
ISO/IEC 27701:2025 ↗A structured assessment sequence reduces uncontrolled scanning, protects sensitive evidence and keeps technical observations connected to accountable business and control decisions.
Objectives, systems, business units, jurisdictions, exclusions and decision needs.
Access, handling, minimisation, evidence storage and escalation rules.
Inventories, flows, policies, roles, retention, suppliers and existing findings.
Validate activities, data categories, systems, flows, recipients and accountable owners.
Review transparency, minimisation, rights, consent, retention, access and supplier controls.
Compare documented expectations with workflows, configurations, records, approvals and technical evidence.
Identify evidence-backed gaps, exposure conditions and contributing causes.
Organise remediation by risk, impact, dependency, feasibility and owner.
Review findings, limitations, actions and executive decisions with stakeholders.
Severity is not a hidden proprietary score. The engagement agrees a qualitative prioritisation approach based on evidence and the organisation's risk context, then records the rationale for material findings.
Material findings, decisions, limitations, priorities and recommended next steps.
Validated processing activities, systems, data categories, personal-data locations and evidence references.
Documented sources, movement, recipients, processors, third parties and jurisdiction context where supportable.
Purpose, notice, approved-use, accountability and evidence observations requiring action or specialist confirmation.
Workflow, identity verification, downstream execution, consent records and preference-enforcement observations.
Retention, deletion, archive, backup, minimisation and downstream copy-management observations.
Identity, privilege, segregation, monitoring and related security-control observations that affect privacy risk.
Privacy and supporting security controls mapped to requirements, evidence, owners, gaps and limitations.
Finding rationale, priority, affected processing, accountable owner, dependencies, actions and validation needs.
Decision-focused presentation plus recommended closure evidence and retest approach for selected findings.
Use evidence, ownership and dependency information to separate immediate exposure reduction from longer-term inventory, access, retention, governance and platform improvements.
DataConsultant does not publish a fixed fee for this service. Each model is scoped around systems, evidence, jurisdictions, stakeholder access and expected outputs. Timeline and commercial terms are confirmed in the proposal.
For a defined application, product, business process or privacy control area where operating evidence and risk need to be assessed.
For organisations that need a cross-functional privacy assessment spanning multiple processes, applications, data stores, suppliers and accountable teams.
For larger organisations that need the privacy assessment phased by business unit, geography, data domain, regulation or risk priority.
For teams that need assessment findings translated into backlog items, control improvements, evidence requirements and selected retesting.
For changing environments where new systems, vendors, products, processing activities or AI use cases require periodic privacy evidence refresh.
Scope-led pricing: a reliable quote depends on the number and type of systems, structured and unstructured repositories, data volumes, existing privacy, discovery and governance tooling, access constraints, business units, jurisdictions, stakeholder interviews, third parties, evidence quality, technical review depth, deliverables, onsite needs and whether remediation or retesting is included. No fixed turnaround is stated because the timeline depends on the same factors.
A precise estimate follows a short scoping discussion. These factors determine how much evidence needs to be gathered, how technical the review must be and how many stakeholders need to validate findings.
Policies and checklists can state what should happen, but enterprise privacy decisions also need evidence from business processes, systems, suppliers, access controls, rights workflows and lifecycle operations. The engagement is structured around that evidence gap.
Separate observed facts, stakeholder evidence, tool signals, assumptions and unresolved limitations so decision-makers can see what supports each material finding.
Connect processing purpose, individual-facing obligations and governance expectations with systems, data stores, access, suppliers and lifecycle controls.
Distinguish consulting findings from legal interpretation, client decisions, implementation ownership, formal assurance and residual-risk acceptance.
Translate visibility gaps into actions that can be assigned, sequenced and verified rather than ending with a catalogue of technical matches.
Use the organisation's applicable requirements and available evidence without turning one regulation, certification or privacy platform into a universal control model.
Structure processing inventories, findings, ownership, decisions and control evidence so remediation, audit preparation and ongoing privacy governance can reuse the output.
Share the priority business processes, systems, jurisdictions, privacy programme, known findings and evidence constraints. DataConsultant can shape a focused assessment boundary and practical remediation path.
Answers to common buyer questions about scope, evidence, production access, deliverables, regulation, prioritisation, pricing, timeline and follow-on work.
Share your contact details and requirement. DataConsultant can review the likely assessment boundary, evidence needs, stakeholder involvement and appropriate next step.