Skip to main content
Trust Center · Data Privacy

Build Privacy Into Data and AI Delivery From Purpose to Closure

Data privacy in consulting starts with knowing why personal information is needed, what role each party has, who may access it, how it can be used or shared, and what should happen when the work ends. DataConsultant uses an engagement-specific approach so privacy questions can be connected to client instructions, contracts, technology choices, third parties and accountable decisions.

Purpose and role clarity
Data minimisation by context
Access and handling boundaries
Review, closure and evidence

This page provides general assurance information. Applicable privacy obligations, controls and responsibilities depend on the actual service, data, systems, locations, parties and signed terms.

Why Data Privacy Needs Deliberate Design

Common conditions that can create uncertainty in data, analytics and AI engagements.

Unclear processing purpose
Ambiguous privacy roles
Excessive data collection
Broad or stale access
Unmapped sharing
Unreviewed third parties
Cross-border uncertainty
Undefined retention
Weak incident coordination
Poor evidence traceability

Current State → Target State

From informal handling assumptions to a scoped, reviewable privacy model.

Current StateTypical privacy ambiguity
  • Purpose inferred after data arrives
  • Role allocation left implicit
  • Full datasets shared by default
  • Access granted without closure plan
  • Supplier use considered late
  • Retention handled inconsistently
Target StateA more accountable privacy posture
  • Purpose defined before access
  • Roles documented by processing context
  • Minimum necessary data used
  • Access tied to role and environment
  • Third parties reviewed by risk
  • Closure addresses return or deletion

Review the Privacy Questions Before Sensitive Data Is Shared

Use the Trust Team route to discuss processing roles, data categories, supplier questions, contractual requirements or a privacy questionnaire.

Contact the Trust Team →

What Our Data Privacy Approach Covers

A practical information lifecycle for consulting engagements involving personal data.

Collect / ReceiveSource, categories, individuals and context
Define PurposeNeed, permitted use and decision context
Control AccessPeople, systems, permissions and environment
UseInstructions, minimisation and handling limits
ShareRecipients, providers and approval conditions
RetainPurpose, contract, law and operating need
Return / DeleteProject closure, access removal and residual copies

Data Privacy Capability Map

A connected governance model for purpose, responsibility, safeguards and review.

Purpose & NecessityWhy personal data is required for the agreed work
Roles & AccountabilityWho determines purpose, gives instructions and approves risk
Minimisation & QualityUse only relevant data and understand material limitations
Access & SecurityPermissions and safeguards proportionate to context
Privacy
Governance
Purpose · Control · Evidence · Review
Third PartiesProvider role, access, contract and downstream use
Transparency & RightsNotices, requests and client coordination where applicable
Retention & ClosureReturn, deletion, justified retention and access removal
Evidence & ReviewRecords, decisions, exceptions and due-diligence support

Privacy Roles Depend on the Processing Context

The first governance decision is to establish who determines the purpose and permitted use of personal information.

One organisation can have different roles across different activities.

DataConsultant’s public Privacy Policy distinguishes between personal information used for its own website and business purposes and client data processed solely for a client project. For client-directed processing, the client generally determines the purpose and permitted use, while handling is governed by the applicable agreement, documented client instructions and agreed requirements.

Due-diligence point: do not infer a role from the company name or technology alone. Confirm the actual processing purpose, instructions, systems, data flows and contractual allocation for the engagement.

DataConsultant business purposes

Website, enquiries, relationship management, administration, security, recruitment, billing and other business activities may involve DataConsultant determining why and how information is used, as described in the Privacy Policy.

Client-directed project processing

When personal data is processed solely for a client project, the client generally determines the project purpose and permitted use. DataConsultant follows the applicable agreement and documented instructions.

Client-controlled environments

Clients may control accounts, permissions, systems, configurations, source data and internal approvals. Those responsibilities should remain explicit when DataConsultant personnel are granted access.

Technology and other providers

Cloud platforms, SaaS tools, specialists or other approved providers may have separate responsibilities. Their role should be assessed rather than attributed automatically to DataConsultant.

Privacy by Design: Six Decision Gates

Privacy review should follow the work from scoping to closure rather than occur only at the end.

01

Scope

Identify the use case, personal data, people, systems, locations and intended outcomes.

Decision

Is personal data necessary for the agreed work?

02

Allocate Roles

Clarify who gives instructions, owns notices, approves access and accepts residual risk.

Decision

Are responsibilities documented and understood?

03

Minimise

Reduce fields, records, environments or copies where the same objective can be met with less data.

Decision

Is the proposed data proportionate to the purpose?

04

Set Safeguards

Define access, handling, sharing, supplier and environment requirements for the actual context.

Decision

Are controls suitable before access is granted?

05

Review Change

Reassess when scope, data categories, use, providers, locations or system design materially changes.

Decision

Does the original privacy assessment still fit?

06

Close

Remove access and address return, deletion, justified retention, handover and outstanding actions.

Decision

Are residual data and responsibilities understood?

Shared Responsibility for Personal Data

Privacy assurance is stronger when responsibility boundaries are visible before delivery starts.

Illustrative responsibility model. Final responsibilities are determined by the actual processing context and applicable agreements.
Privacy areaDataConsultantClientTechnology / other provider
Purpose and instructionsWork within the agreed scope and documented instructions where processing is client-directed.Define lawful business purpose, permitted use, restrictions and project instructions within its control.Operate according to its service terms, configuration and agreed processing role.
Data selectionQuestion unnecessary fields or copies where identified during delivery.Provide appropriate data, classification, minimisation decisions and authority to disclose.Support available configuration, filtering or processing controls where part of the selected service.
AccessUse assigned accounts and approved access consistent with the delivery model.Approve and govern access to client-controlled systems, users and environments.Provide the product or platform access-control capabilities selected and configured by accountable parties.
Third partiesIdentify proposed delivery dependencies and support relevant review where applicable.Communicate approval, contractual, data-location or supplier restrictions that apply to the engagement.Disclose and manage its own downstream dependencies according to applicable terms.
Retention and closureFollow agreed return, deletion, access-removal and handover steps for the scope under DataConsultant control.Give timely instructions, retain what it must retain, and close access in client-controlled environments.Apply provider retention and deletion capabilities according to the service configuration and terms.
Requests and incidentsEscalate relevant issues through agreed channels and support engagement-specific coordination.Own internal legal, regulatory, individual-request and incident decisions within its role and jurisdiction.Provide contractual support and incident information according to its role and service terms.

Third Parties, Locations and Cross-Border Questions

External services and delivery locations can change the privacy analysis and should be reviewed before they become hidden dependencies.

Provider purpose and role

Confirm why a provider is needed, what information it may access, whether it processes personal data and what contractual role it has for the activity.

Locations and transfers

Identify relevant jurisdictions, service locations, data locations, remote-access patterns and any engagement-specific transfer restrictions before relying on a transfer mechanism.

Downstream sharing

Review approved recipients, subprocessors where applicable, onward use, access boundaries, notification expectations and client approval requirements.

Exit and residual data

Address provider offboarding, access removal, export, return, deletion, backups and any justified residual retention rather than treating termination as an administrative step only.

Assurance Evidence Should Match the Review Need

Privacy due diligence may require different levels of information without exposing unnecessary confidential or security-sensitive detail.

From public information to client-specific review

Trust information is most useful when it distinguishes what can be read publicly from what requires context, approval or controlled disclosure.

  • Use the public Privacy Policy for formal website and business-level privacy information.
  • Use Trust Center pages for general governance, role and lifecycle explanations.
  • Use the Trust Team for questionnaires, contractual privacy requirements and engagement-specific evidence.
  • Do not send passwords, credentials, production datasets or highly sensitive material through an initial general enquiry.
Public informationPrivacy Policy, public Trust Center content and other approved public notices.
Trust Center detailExpanded explanations of roles, lifecycle decisions, responsibilities, third parties and review principles.
Controlled assuranceApproved process or control information that may require relevance review or confidentiality conditions before disclosure.
Client-specific due diligenceQuestionnaires, data-processing terms, system or supplier context and contractual requirements for the proposed engagement.

Regulatory Context Without Blanket Compliance Claims

Privacy laws and client policies inform the review, but applicability depends on the actual processing facts.

Relevant law context

EU General Data Protection Regulation

The GDPR may be relevant where its territorial and processing conditions apply. Engagement review should identify roles, purpose, data, individuals, locations and contractual responsibilities rather than infer compliance from this page.

Relevant law context

Digital Personal Data Protection Act, 2023

India’s Digital Personal Data Protection Act, 2023 may be relevant to digital personal data within its scope. Applicability, commencement and obligations should be reviewed against the current law and the specific processing activity.

Client requirements

Policies, contracts and sector obligations

Client privacy standards, confidentiality terms, data-processing clauses, sector rules and internal risk requirements may create additional controls or evidence expectations for a particular engagement.

Important: discussion of a privacy law or framework is not a statement that DataConsultant holds a privacy certification, regulatory approval or universal compliance status. Legal interpretation belongs with appropriately qualified legal and privacy advisers.

Formal Privacy Notice and Engagement-Specific Terms

Use the correct source for the question being reviewed.

Privacy Policy

The public Privacy Policy explains how DataConsultant handles personal information for website, communications, business relationships and other activities described in that notice.

Read the Privacy Policy

Project-specific agreements

Service agreements, statements of work, confidentiality provisions, data-processing terms, security schedules and documented client instructions may define additional or different requirements for a specific engagement.

Privacy due diligence

Procurement, privacy, legal and security teams can use the Trust Team route for processing-role questions, questionnaires, supplier context, contractual requirements or available assurance information.

Ask a Privacy Question

Trust documentation

The Trust Documents area explains how approved public, request-based, confidential and planned materials are distinguished. It should not be read as proof that every listed document exists in a final approved form.

Review Trust Documents

Data Privacy FAQs

Answers for privacy, legal, procurement, security and technical reviewers.

What does the Data Privacy Trust Center page cover?
It explains the privacy questions that should be considered when DataConsultant handles personal information for website and business activities or when personal data is involved in a client engagement. It covers purpose, data roles, minimisation, access, use, sharing, retention, deletion, third parties, responsibilities, evidence and review.
Does DataConsultant always act in the same privacy role?
No. The role depends on the activity. DataConsultant’s public Privacy Policy explains that it may determine why and how personal information is used for its own website and business purposes, while a client generally determines the purpose and permitted use when DataConsultant processes client data solely for that client’s project. The applicable contract and processing context should confirm the role for a specific engagement.
How should personal data be scoped before a consulting engagement begins?
The parties should identify the intended purpose, relevant data categories, affected individuals, systems, locations, access needs, retention expectations, third-party dependencies and applicable client or legal requirements. Unnecessary personal data should not be requested merely because it is available.
Can DataConsultant work with personal data in a client-controlled environment?
Where the agreed scope requires it, work may take place in client-controlled systems or approved delivery environments. Access, permissions, data handling, monitoring, retention and closure responsibilities should be defined for the actual environment rather than assumed from a generic model.
How are privacy and information security connected?
Privacy defines why personal data may be used, by whom, for what purpose and under what obligations. Information security provides technical and organisational safeguards that may support authorised handling. The two disciplines overlap but are not interchangeable, so both should be considered where personal data is involved.
How are third parties or subprocessors considered?
Where an external provider may receive, store, access or otherwise process personal data, the parties should confirm its role, purpose, information access, locations, contractual terms, downstream dependencies, retention and exit requirements. A public subprocessor list is not asserted on this page.
Does this page confirm compliance with GDPR or the Digital Personal Data Protection Act, 2023?
No. Laws such as the EU General Data Protection Regulation and India’s Digital Personal Data Protection Act, 2023 may be relevant depending on the people, data, locations and processing context. Applicability and obligations require engagement-specific legal and privacy review. This Trust Center page is general assurance information, not legal advice or a certification statement.
How are retention and deletion handled?
Retention should reflect the purpose, applicable agreement, legal requirements, client instructions and operational dependencies. Project closure should address active copies, temporary files, shared workspaces, access removal, return or deletion instructions and any justified residual retention. This page does not publish a universal retention period.
Can our privacy or procurement team request additional assurance information?
Yes. Use the Contact Trust Team route to explain the service under review, your organisation, the privacy question, requested evidence, questionnaire or contractual requirement, and the decision timeline. Availability and disclosure may depend on relevance, approval and confidentiality restrictions.
Where can I find DataConsultant’s formal privacy notice?
The DataConsultant Privacy Policy is the formal public notice for website and business-level personal information handling. Project-specific agreements, data-processing terms, confidentiality provisions and client instructions may define additional or different requirements for a particular engagement.

Need to Review a Privacy Requirement for a Proposed Engagement?

Share the service being evaluated, relevant data categories, processing context, review question, requested evidence or questionnaire, and target decision date. Avoid including personal data, credentials or confidential datasets in the initial message.