Privacy & Data Regulation
Four privacy audits, a maturity assessment, and the named DPO role — but never the role and the audits together.
The record of processing is a document, not a map.
A processing inventory is built for a regulation, signed off, and filed. Meanwhile systems are integrated, a vendor is switched, a marketing tool starts collecting something new, and a retention rule is quietly never enforced because nobody built the job that enforces it.
The inventory still describes the organization as it was on the day it was signed. The first person to notice the gap is usually a regulator or a subject making a request, and by then the question is not what your policy said but what your systems did.
Bought as a project. Delivered as a product.
Neither column is a caricature. The left is how this work is bought almost everywhere, including by people who dislike it.
Five to six weeks, tested against systems.
A privacy framework audit, week by week.
The record of processing tested against system reality, and the control points agreed from the gaps.
Partner gateCollection to deletion — rights handling, breach response, retention, transfers, vendor diligence, on real cases.
Each finding framed to the obligation it touches, with the regulatory exposure stated plainly.
Partner gateRemediation sequenced by obligation deadline.
Partner gateThe same machine, pointed at your data.
Privacy is the area where the distance between the written procedure and the operating reality is easiest to measure, which makes it the easiest place to prove a method works.
Methodology 2026.2 — bumps when a box, a gate or a testing standard changes — never for a copy edit. Read it at working depth, including what we hold back and why, on the method page.
Assurance, or the role itself.
You can have us audit your privacy operation, or you can have us be your privacy operation. What you cannot have is both from us at once — a DPO’s statutory task is monitoring compliance, so auditing that work would be auditing ourselves, whatever the cover page said. The constraint is published here rather than discovered in a negotiation, and it points one way: if you want both, buy the audit first.
Processing inventory verified against what the systems actually do. 710 credits.
The Article 30 record tested against the systems, including the processing nobody wrote down. 520 credits.
Where data actually leaves the jurisdiction, and whether the mechanism still holds. 482 credits.
Basis mapped per purpose and tested — including whether withdrawal stops the processing. 530 credits.
Twelve domains scored on evidence. A diagnostic, not an audit. 560 credits.
The named role held by Signify, with a standing published rhythm in Privacy360™. $10,000 a quarter — and it closes all five privacy engagements above.
8 engagements, every box printed.
Tap any one to read its scope box — what we analyze, how scope gets chosen, what is tested, what the report contains, and what the remediation plan does and doesn’t include. Prices come from one published formula.
Family A · Assurance
Assurance — an opinion your Audit Committee can rely on. Bought by the Chief Audit Executive.
B1 Privacy Framework and Procedures Audit — 45 control points · 710 credits · $35,500 +
- 01Processing inventory verification — the record of processing tested against what the systems actually do
- 02Procedure testing — subject rights, breach response, retention, transfers and vendor due diligence, tested on real cases
- 0345 control points tested — across the lifecycle from collection to deletion
- 04Final report — findings framed to the obligation, with the regulatory exposure of each stated plainly
- 05Remediation plan — sequenced by obligation deadline, not by convenience
Hard stop: we cannot run this where Signify holds your outsourced DPO role. See independence.
B2 Records of Processing Audit — 32 control points · 520 credits · $26,000 +
- 01The Article 30 record tested against reality — every processing activity in the register traced to a system, a purpose and a lawful basis that actually exists
- 02Shadow processing identified — activities running in the business that never reached the record, found from system inventories and interviews rather than from the record itself
- 0332 control points tested — 14 record completeness and accuracy, 10 processor and sub-processor coverage, 8 retention and deletion
- 04Final report — every gap rated, evidence attached, each conclusion traceable to a test
- 05Remediation plan — prioritized, owners proposed, effort estimated. The plan is yours to run
A record nobody has opened since it was written is a document, not a control.
B3 International Data Transfer Audit — 26 control points · 482 credits · $24,100 +
- 01Transfer inventory built from systems — where personal data actually leaves the jurisdiction, including the transfers nobody documented
- 02Mechanism tested per transfer — adequacy, standard contractual clauses, binding rules or derogation, checked against what the contract really says
- 0326 control points tested — 12 mechanism validity, 8 transfer impact assessment, 6 onward-transfer and sub-processor chain
- 04Final report — findings rated, each transfer traceable to its evidence
- 05Remediation plan — prioritized, with the transfers to stop named separately from the transfers to paper
The common failure is not an absent mechanism. It is a mechanism signed once and never revisited after the vendor changed hosting.
B4 Consent and Lawful Basis Audit — 30 control points · 530 credits · $26,500 +
- 01Lawful basis mapped per processing purpose — and tested, because a basis asserted in a policy is not a basis evidenced in a system
- 02Consent mechanics tested where consent is the basis — capture, granularity, withdrawal, and whether withdrawal actually stops the processing
- 0330 control points tested — 12 basis validity and documentation, 10 consent capture and withdrawal, 8 data-subject rights fulfilment
- 04Final report — findings rated, evidence attached, every conclusion traceable to a test
- 05Remediation plan — prioritized, owners proposed, effort estimated
Withdrawal is where this audit usually finds its first material issue.
Family C · Function build
Function build — your own function’s infrastructure.
B6 Privacy 360 Build & Pilot Operate (Large/Mid) — ~12 domains · 2400 credits · $120,000 +
- 01Program design across twelve domains — governance, records, lawful basis, rights, transfers, retention, vendors, breach, privacy by design, training, monitoring and DPO effectiveness, designed as an operating model rather than as a policy set
- 02The record of processing built in Privacy360™ — every activity, lawful basis, retention period and transfer route, derived from what the systems actually do rather than from what a questionnaire returned
- 03Operating procedures written for the people who will run them — rights requests, DPIA gating, vendor assessment and breach response, each with an owner, a trigger and a service window
- 04A pilot quarter operated alongside your team — we run the rhythm once, in your environment, with your people beside us. A program handed over on paper is a program nobody has ever executed
- 05Handover with the evidence of one full cycle — the register live, every procedure exercised at least once, and the gaps that only surfaced under real load written down rather than smoothed over
A build, not an assessment. Because we design and pilot this program we cannot later provide assurance over it — that closes B1, B2, B3, B4 and the B5 maturity assessment for as long as the build stands. Sized for an estate with multiple jurisdictions, or processing that crosses more than one regulator.
B7 Privacy 360 Build & Pilot Operate (Mid/Small Entity) — ~12 domains · 1000 credits · $50,000 +
- 01The same twelve domains, scoped to a single-jurisdiction estate — the framework does not shrink, the evidence base does
- 02Record of processing built in Privacy360™ — verified against the systems, not assembled from a survey somebody completed about their own area
- 03Operating procedures written to be run by a part-time owner — rights requests, DPIA gating, vendor assessment and breach response, sized for someone who does this alongside another job, because in an entity this size they always do
- 04A pilot quarter operated alongside your team — one full cycle run with you before anything is handed over
- 05Handover with the evidence of that cycle — register live, procedures exercised, and the gaps that only appear under real load named
A build, not an assessment, and it forecloses the privacy assurance engagements exactly as B6 does. The difference between the two is estate size and jurisdiction count, not framework coverage — the twelve domains are the same twelve. Which side of the line you fall on is scoped before you buy, not after.
B8 DPO as-a-service (Per Quarter) — Operate · 200 credits · $10,000 +
- 01The named DPO of record — appointed, notified to the supervisory authority where that is required, and reachable by regulators and data subjects at a published address
- 02The record of processing kept current in Privacy360™ — changes captured as they happen rather than reconstructed at quarter end
- 03A DPIA gate on new processing — assessed before it ships, not after somebody complains
- 04Quarterly pack and readout — what changed, what was assessed, what was refused, and what has quietly become unevidenced
- 05Breach-window availability — because a seventy-two hour clock does not wait for the next quarter
Holding your DPO role closes every privacy audit we sell — B1, B2, B3, B4 and the B5 maturity assessment. A DPO’s statutory task is monitoring compliance, so auditing any of it would be auditing our own work. The role and the assurance are mutually exclusive, and the choice is yours before you buy either. Priced and bought one quarter at a time.
Family B · Assessment
Assessment — a diagnostic, no assurance opinion. Bought by the function’s own head, except where the item is a procedure.
B5 Privacy Programme Maturity Assessment — ~12 domains · 560 credits · $28,000 +
- 01Framework and target-state agreement — the standard and the maturity level you are aiming for, agreed before assessment
- 02Evidence-based scoring across 12 domains — governance, records, lawful basis, rights, transfers, retention, vendors, breach, privacy by design, training, monitoring, and DPO effectiveness
- 03Current-state maturity rating per domain, with the evidence behind each score attached
- 04Gap analysis to target state — costed by effort band
- 05Roadmap — sequenced, dependencies named. An assessment, not an audit — no assurance opinion is expressed
Anything here can join a plan built in any other area — a penetration test can sit inside an internal audit year. Build a plan →
Privacy Framework & Data Quality
The privacy program scored, and the record it rests on audited. The privacy program scored against the framework across twelve domains, and the record of processing audited for whether it matches what the systems actually do.
Same engagements, same menu prices — buying the block as a year changes nothing except that it is worth buying at once. Read the full card, including what it forecloses →
What we do · Privacy & Data Regulation
One thing worth knowing before you buy.
Every recurring service we run forecloses the assurance over it. If we keep your framework alive we cannot audit it, and if we audit it we cannot keep it alive. You choose which, we print the consequence before you buy rather than after, and where an Audit Committee relationship already exists we protect it.
Part of the Signify family
Solve · Build · Teach · Sustain. Four properties, one design language — consulting, software, interactive learning and sustained advisory, built in Philadelphia since 2019.
Premium management consulting across strategy, cybersecurity, audit, GRC and regulatory readiness. Every engagement partner-led.
signifysolution.comConsulting, new age. Seven practitioner-built products — the tools that stay behind at clients as running value.
signifyhive.comPlay, test, think. Games, assessments, simulations and Points of View — learn the work by doing it.
signifyinsights.com You are hereConsulting, sustained. Time-boxed, and scope-boxed engagements at transparent rates. Clear pricing. Explicit scope.
signifyimpact.com