Project-based work, scoped to the problem in front of you
Not every organisation needs an appointed DPO. Sometimes you need one piece of work done properly, by someone who understands both the legal requirement and how your systems actually operate. That's what this covers.
Scope a projectWorkstreams
Data Protection Impact Assessments (DPIAs)
Full DPIAs for high-risk processing, or a second opinion on one your team has already drafted.
Transfer Impact Assessments (TIAs)
Assessing cross-border data flows against UK GDPR Chapter V requirements, including practical TIA templates your team can reuse.
Vendor & DPA review
Reviewing processor agreements against Article 28 requirements, and flagging where a supplier's terms fall short.
ICO accountability & audit readiness
Mapping your evidence against the ICO accountability framework and building a minimum-document-set action plan.
Policy & documentation
Drafting or overhauling privacy notices, retention schedules, and internal data protection policies.
Training
Practical, jargon-light training sessions for marketing, HR, product and engineering teams.
Got a specific piece of work in mind?
Send over a rough outline and I'll come back with a scoped proposal, or book a call to talk it through first.