What we do · Privacy & Data Regulation
Privacy and Data Regulation · Boxes printed
What we do·Privacy & Data Regulation

Privacy & Data Regulation

Four privacy audits, a maturity assessment, and the named DPO role — but never the role and the audits together.

What actually breaks

The record of processing is a document, not a map.

A processing inventory is built for a regulation, signed off, and filed. Meanwhile systems are integrated, a vendor is switched, a marketing tool starts collecting something new, and a retention rule is quietly never enforced because nobody built the job that enforces it.

The inventory still describes the organization as it was on the day it was signed. The first person to notice the gap is usually a regulator or a subject making a request, and by then the question is not what your policy said but what your systems did.

The comparison

Bought as a project. Delivered as a product.

Neither column is a caricature. The left is how this work is bought almost everywhere, including by people who dislike it.

How this is normally bought
An inventory verified against a previous inventory
Procedures reviewed as written
A privacy audit by the firm that runs your privacy function
Findings ordered by convenience
How it works here
Verified against what the systems actually do
Procedures tested on real cases — real requests, real breaches, real transfers
Hard stop, published — if we hold your DPO role we cannot audit your framework
Sequenced by obligation deadline, because the regulator's calendar is the one that counts
The schedule

Five to six weeks, tested against systems.

A privacy framework audit, week by week.

Week 1
Inventory verification and scope lock

The record of processing tested against system reality, and the control points agreed from the gaps.

Partner gate
Weeks 2–4
Lifecycle testing

Collection to deletion — rights handling, breach response, retention, transfers, vendor diligence, on real cases.

Week 5
Findings and peer review

Each finding framed to the obligation it touches, with the regulatory exposure stated plainly.

Partner gate
Week 6
Report and readout

Remediation sequenced by obligation deadline.

Partner gate
Why it repeats

The same machine, pointed at your data.

Privacy is the area where the distance between the written procedure and the operating reality is easiest to measure, which makes it the easiest place to prove a method works.

1
audit, one service — and never both at one client
5
parts in the box, like every other engagement
3
partner gates
0
findings written from documentation alone

Methodology 2026.2 — bumps when a box, a gate or a testing standard changes — never for a copy edit. Read it at working depth, including what we hold back and why, on the method page.

Engagements

8 engagements, every box printed.

Tap any one to read its scope box — what we analyze, how scope gets chosen, what is tested, what the report contains, and what the remediation plan does and doesn’t include. Prices come from one published formula.

Family A · Assurance

Assurance — an opinion your Audit Committee can rely on. Bought by the Chief Audit Executive.

B1  Privacy Framework and Procedures Audit — 45 control points · 710 credits · $35,500 +
The box710 credits · $35,500
  • 01Processing inventory verification — the record of processing tested against what the systems actually do
  • 02Procedure testing — subject rights, breach response, retention, transfers and vendor due diligence, tested on real cases
  • 0345 control points tested — across the lifecycle from collection to deletion
  • 04Final report — findings framed to the obligation, with the regulatory exposure of each stated plainly
  • 05Remediation plan — sequenced by obligation deadline, not by convenience
Count agreed at scope lock, before fieldworkThe formula never moves

Hard stop: we cannot run this where Signify holds your outsourced DPO role. See independence.

B2  Records of Processing Audit — 32 control points · 520 credits · $26,000 +
The box520 credits · $26,000
  • 01The Article 30 record tested against reality — every processing activity in the register traced to a system, a purpose and a lawful basis that actually exists
  • 02Shadow processing identified — activities running in the business that never reached the record, found from system inventories and interviews rather than from the record itself
  • 0332 control points tested — 14 record completeness and accuracy, 10 processor and sub-processor coverage, 8 retention and deletion
  • 04Final report — every gap rated, evidence attached, each conclusion traceable to a test
  • 05Remediation plan — prioritized, owners proposed, effort estimated. The plan is yours to run
Count agreed at scope lock, before fieldworkThe formula never moves

A record nobody has opened since it was written is a document, not a control.

B3  International Data Transfer Audit — 26 control points · 482 credits · $24,100 +
The box482 credits · $24,100
  • 01Transfer inventory built from systems — where personal data actually leaves the jurisdiction, including the transfers nobody documented
  • 02Mechanism tested per transfer — adequacy, standard contractual clauses, binding rules or derogation, checked against what the contract really says
  • 0326 control points tested — 12 mechanism validity, 8 transfer impact assessment, 6 onward-transfer and sub-processor chain
  • 04Final report — findings rated, each transfer traceable to its evidence
  • 05Remediation plan — prioritized, with the transfers to stop named separately from the transfers to paper
Count agreed at scope lock, before fieldworkThe formula never moves

The common failure is not an absent mechanism. It is a mechanism signed once and never revisited after the vendor changed hosting.

B4  Consent and Lawful Basis Audit — 30 control points · 530 credits · $26,500 +
The box530 credits · $26,500
  • 01Lawful basis mapped per processing purpose — and tested, because a basis asserted in a policy is not a basis evidenced in a system
  • 02Consent mechanics tested where consent is the basis — capture, granularity, withdrawal, and whether withdrawal actually stops the processing
  • 0330 control points tested — 12 basis validity and documentation, 10 consent capture and withdrawal, 8 data-subject rights fulfilment
  • 04Final report — findings rated, evidence attached, every conclusion traceable to a test
  • 05Remediation plan — prioritized, owners proposed, effort estimated
Count agreed at scope lock, before fieldworkThe formula never moves

Withdrawal is where this audit usually finds its first material issue.

Family C · Function build

Function build — your own function’s infrastructure.

B6  Privacy 360 Build & Pilot Operate (Large/Mid) — ~12 domains · 2400 credits · $120,000 +
The box2400 credits · $120,000
  • 01Program design across twelve domains — governance, records, lawful basis, rights, transfers, retention, vendors, breach, privacy by design, training, monitoring and DPO effectiveness, designed as an operating model rather than as a policy set
  • 02The record of processing built in Privacy360™ — every activity, lawful basis, retention period and transfer route, derived from what the systems actually do rather than from what a questionnaire returned
  • 03Operating procedures written for the people who will run them — rights requests, DPIA gating, vendor assessment and breach response, each with an owner, a trigger and a service window
  • 04A pilot quarter operated alongside your team — we run the rhythm once, in your environment, with your people beside us. A program handed over on paper is a program nobody has ever executed
  • 05Handover with the evidence of one full cycle — the register live, every procedure exercised at least once, and the gaps that only surfaced under real load written down rather than smoothed over
Count agreed at scope lock, before fieldworkThe formula never moves

A build, not an assessment. Because we design and pilot this program we cannot later provide assurance over it — that closes B1, B2, B3, B4 and the B5 maturity assessment for as long as the build stands. Sized for an estate with multiple jurisdictions, or processing that crosses more than one regulator.

B7  Privacy 360 Build & Pilot Operate (Mid/Small Entity) — ~12 domains · 1000 credits · $50,000 +
The box1000 credits · $50,000
  • 01The same twelve domains, scoped to a single-jurisdiction estate — the framework does not shrink, the evidence base does
  • 02Record of processing built in Privacy360™ — verified against the systems, not assembled from a survey somebody completed about their own area
  • 03Operating procedures written to be run by a part-time owner — rights requests, DPIA gating, vendor assessment and breach response, sized for someone who does this alongside another job, because in an entity this size they always do
  • 04A pilot quarter operated alongside your team — one full cycle run with you before anything is handed over
  • 05Handover with the evidence of that cycle — register live, procedures exercised, and the gaps that only appear under real load named
Count agreed at scope lock, before fieldworkThe formula never moves

A build, not an assessment, and it forecloses the privacy assurance engagements exactly as B6 does. The difference between the two is estate size and jurisdiction count, not framework coverage — the twelve domains are the same twelve. Which side of the line you fall on is scoped before you buy, not after.

B8  DPO as-a-service (Per Quarter) — Operate · 200 credits · $10,000 +
The box200 credits · $10,000
  • 01The named DPO of record — appointed, notified to the supervisory authority where that is required, and reachable by regulators and data subjects at a published address
  • 02The record of processing kept current in Privacy360™ — changes captured as they happen rather than reconstructed at quarter end
  • 03A DPIA gate on new processing — assessed before it ships, not after somebody complains
  • 04Quarterly pack and readout — what changed, what was assessed, what was refused, and what has quietly become unevidenced
  • 05Breach-window availability — because a seventy-two hour clock does not wait for the next quarter
Count agreed at scope lock, before fieldworkThe formula never moves

Holding your DPO role closes every privacy audit we sell — B1, B2, B3, B4 and the B5 maturity assessment. A DPO’s statutory task is monitoring compliance, so auditing any of it would be auditing our own work. The role and the assurance are mutually exclusive, and the choice is yours before you buy either. Priced and bought one quarter at a time.

Family B · Assessment

Assessment — a diagnostic, no assurance opinion. Bought by the function’s own head, except where the item is a procedure.

B5  Privacy Programme Maturity Assessment — ~12 domains · 560 credits · $28,000 +
The box560 credits · $28,000
  • 01Framework and target-state agreement — the standard and the maturity level you are aiming for, agreed before assessment
  • 02Evidence-based scoring across 12 domains — governance, records, lawful basis, rights, transfers, retention, vendors, breach, privacy by design, training, monitoring, and DPO effectiveness
  • 03Current-state maturity rating per domain, with the evidence behind each score attached
  • 04Gap analysis to target state — costed by effort band
  • 05Roadmap — sequenced, dependencies named. An assessment, not an audit — no assurance opinion is expressed
Count agreed at scope lock, before fieldworkThe formula never moves

Anything here can join a plan built in any other area — a penetration test can sit inside an internal audit year. Build a plan →

Bought as a bundle

Privacy Framework & Data Quality

The privacy program scored, and the record it rests on audited. The privacy program scored against the framework across twelve domains, and the record of processing audited for whether it matches what the systems actually do.

Composition
B5 · B2
Credits
1,080 cr
At base rate
$54,000

Same engagements, same menu prices — buying the block as a year changes nothing except that it is worth buying at once. Read the full card, including what it forecloses →

What we do · Privacy & Data Regulation

One thing worth knowing before you buy.

Every recurring service we run forecloses the assurance over it. If we keep your framework alive we cannot audit it, and if we audit it we cannot keep it alive. You choose which, we print the consequence before you buy rather than after, and where an Audit Committee relationship already exists we protect it.