Data protection consultancy

Project-based work, scoped to the problem in front of you

Not every organisation needs an appointed DPO. Sometimes you need one piece of work done properly, by someone who understands both the legal requirement and how your systems actually operate. That's what this covers.

Scope a project

Workstreams

Data Protection Impact Assessments (DPIAs)

Full DPIAs for high-risk processing, or a second opinion on one your team has already drafted.

Transfer Impact Assessments (TIAs)

Assessing cross-border data flows against UK GDPR Chapter V requirements, including practical TIA templates your team can reuse.

Vendor & DPA review

Reviewing processor agreements against Article 28 requirements, and flagging where a supplier's terms fall short.

ICO accountability & audit readiness

Mapping your evidence against the ICO accountability framework and building a minimum-document-set action plan.

Policy & documentation

Drafting or overhauling privacy notices, retention schedules, and internal data protection policies.

Training

Practical, jargon-light training sessions for marketing, HR, product and engineering teams.

Got a specific piece of work in mind?

Send over a rough outline and I'll come back with a scoped proposal, or book a call to talk it through first.

Book a consultation