- Purpose inferred after data arrives
- Role allocation left implicit
- Full datasets shared by default
- Access granted without closure plan
- Supplier use considered late
- Retention handled inconsistently
Build Privacy Into Data and AI Delivery From Purpose to Closure
Data privacy in consulting starts with knowing why personal information is needed, what role each party has, who may access it, how it can be used or shared, and what should happen when the work ends. DataConsultant uses an engagement-specific approach so privacy questions can be connected to client instructions, contracts, technology choices, third parties and accountable decisions.
This page provides general assurance information. Applicable privacy obligations, controls and responsibilities depend on the actual service, data, systems, locations, parties and signed terms.
Why Data Privacy Needs Deliberate Design
Common conditions that can create uncertainty in data, analytics and AI engagements.
Current State → Target State
From informal handling assumptions to a scoped, reviewable privacy model.
- Purpose defined before access
- Roles documented by processing context
- Minimum necessary data used
- Access tied to role and environment
- Third parties reviewed by risk
- Closure addresses return or deletion
Review the Privacy Questions Before Sensitive Data Is Shared
Use the Trust Team route to discuss processing roles, data categories, supplier questions, contractual requirements or a privacy questionnaire.
What Our Data Privacy Approach Covers
A practical information lifecycle for consulting engagements involving personal data.
Data Privacy Capability Map
A connected governance model for purpose, responsibility, safeguards and review.
GovernancePurpose · Control · Evidence · Review
Privacy Roles Depend on the Processing Context
The first governance decision is to establish who determines the purpose and permitted use of personal information.
One organisation can have different roles across different activities.
DataConsultant’s public Privacy Policy distinguishes between personal information used for its own website and business purposes and client data processed solely for a client project. For client-directed processing, the client generally determines the purpose and permitted use, while handling is governed by the applicable agreement, documented client instructions and agreed requirements.
DataConsultant business purposes
Website, enquiries, relationship management, administration, security, recruitment, billing and other business activities may involve DataConsultant determining why and how information is used, as described in the Privacy Policy.
Client-directed project processing
When personal data is processed solely for a client project, the client generally determines the project purpose and permitted use. DataConsultant follows the applicable agreement and documented instructions.
Client-controlled environments
Clients may control accounts, permissions, systems, configurations, source data and internal approvals. Those responsibilities should remain explicit when DataConsultant personnel are granted access.
Technology and other providers
Cloud platforms, SaaS tools, specialists or other approved providers may have separate responsibilities. Their role should be assessed rather than attributed automatically to DataConsultant.
Privacy by Design: Six Decision Gates
Privacy review should follow the work from scoping to closure rather than occur only at the end.
Scope
Identify the use case, personal data, people, systems, locations and intended outcomes.
DecisionIs personal data necessary for the agreed work?
Allocate Roles
Clarify who gives instructions, owns notices, approves access and accepts residual risk.
DecisionAre responsibilities documented and understood?
Minimise
Reduce fields, records, environments or copies where the same objective can be met with less data.
DecisionIs the proposed data proportionate to the purpose?
Set Safeguards
Define access, handling, sharing, supplier and environment requirements for the actual context.
DecisionAre controls suitable before access is granted?
Review Change
Reassess when scope, data categories, use, providers, locations or system design materially changes.
DecisionDoes the original privacy assessment still fit?
Close
Remove access and address return, deletion, justified retention, handover and outstanding actions.
DecisionAre residual data and responsibilities understood?
Third Parties, Locations and Cross-Border Questions
External services and delivery locations can change the privacy analysis and should be reviewed before they become hidden dependencies.
Provider purpose and role
Confirm why a provider is needed, what information it may access, whether it processes personal data and what contractual role it has for the activity.
Locations and transfers
Identify relevant jurisdictions, service locations, data locations, remote-access patterns and any engagement-specific transfer restrictions before relying on a transfer mechanism.
Downstream sharing
Review approved recipients, subprocessors where applicable, onward use, access boundaries, notification expectations and client approval requirements.
Exit and residual data
Address provider offboarding, access removal, export, return, deletion, backups and any justified residual retention rather than treating termination as an administrative step only.
Assurance Evidence Should Match the Review Need
Privacy due diligence may require different levels of information without exposing unnecessary confidential or security-sensitive detail.
From public information to client-specific review
Trust information is most useful when it distinguishes what can be read publicly from what requires context, approval or controlled disclosure.
- Use the public Privacy Policy for formal website and business-level privacy information.
- Use Trust Center pages for general governance, role and lifecycle explanations.
- Use the Trust Team for questionnaires, contractual privacy requirements and engagement-specific evidence.
- Do not send passwords, credentials, production datasets or highly sensitive material through an initial general enquiry.
Regulatory Context Without Blanket Compliance Claims
Privacy laws and client policies inform the review, but applicability depends on the actual processing facts.
EU General Data Protection Regulation
The GDPR may be relevant where its territorial and processing conditions apply. Engagement review should identify roles, purpose, data, individuals, locations and contractual responsibilities rather than infer compliance from this page.
Digital Personal Data Protection Act, 2023
India’s Digital Personal Data Protection Act, 2023 may be relevant to digital personal data within its scope. Applicability, commencement and obligations should be reviewed against the current law and the specific processing activity.
Policies, contracts and sector obligations
Client privacy standards, confidentiality terms, data-processing clauses, sector rules and internal risk requirements may create additional controls or evidence expectations for a particular engagement.
Formal Privacy Notice and Engagement-Specific Terms
Use the correct source for the question being reviewed.
Privacy Policy
The public Privacy Policy explains how DataConsultant handles personal information for website, communications, business relationships and other activities described in that notice.
Project-specific agreements
Service agreements, statements of work, confidentiality provisions, data-processing terms, security schedules and documented client instructions may define additional or different requirements for a specific engagement.
Privacy due diligence
Procurement, privacy, legal and security teams can use the Trust Team route for processing-role questions, questionnaires, supplier context, contractual requirements or available assurance information.
Trust documentation
The Trust Documents area explains how approved public, request-based, confidential and planned materials are distinguished. It should not be read as proof that every listed document exists in a final approved form.
Data Privacy FAQs
Answers for privacy, legal, procurement, security and technical reviewers.
What does the Data Privacy Trust Center page cover?
Does DataConsultant always act in the same privacy role?
How should personal data be scoped before a consulting engagement begins?
Can DataConsultant work with personal data in a client-controlled environment?
How are privacy and information security connected?
How are third parties or subprocessors considered?
Does this page confirm compliance with GDPR or the Digital Personal Data Protection Act, 2023?
How are retention and deletion handled?
Can our privacy or procurement team request additional assurance information?
Where can I find DataConsultant’s formal privacy notice?
Need to Review a Privacy Requirement for a Proposed Engagement?
Share the service being evaluated, relevant data categories, processing context, review question, requested evidence or questionnaire, and target decision date. Avoid including personal data, credentials or confidential datasets in the initial message.