Skip to content

Data & Privacy

We map where your personal and sensitive data lives, then build the controls, retention rules, and privacy reviews that keep it accounted for.

Get in touch

Why data and privacy need their own program

Nobody can say where the data is

Personal data spreads across SaaS tools, warehouses, and spreadsheets faster than anyone documents it. We run discovery and classification first, because you can't protect or delete what you can't find.

Privacy law you're already subject to

GDPR, CCPA, and sector rules apply whether or not anyone in the business has read them. We interpret what they require of your processing, then help you build practices that hold up.

Requests you have to answer on a deadline

Access, deletion, and portability requests carry statutory clocks. We set up the intake, verification, and fulfillment process so a request becomes routine work rather than a scramble across five teams.

Data you never needed to keep

Retention drift turns old records into liability with no offsetting value. We define retention schedules by data type and put deletion on a schedule your systems will actually follow.

Vendors processing data on your behalf

Your processors' failures become your notification obligation. We review vendor contracts, data flows, and sub-processors, so you know who holds what and what happens if one of them is breached.

We account for your personal and sensitive data end to end, from the moment it arrives to the day it's deleted.

Privacy obligations land on companies that never built a data function. Our Data & Privacy work starts with discovery — what you hold, where it sits, who touches it — and ends with controls, retention schedules, and a request process your team can run without calling us every time.

Services provided

Data discovery and classification

We inventory the personal and sensitive data you hold across systems and label it by sensitivity. That inventory becomes the reference every later control, contract, and retention decision points back to.

Privacy impact assessments

We run DPIAs on new products, features, and vendor integrations before they ship, documenting the lawful basis, the risk, and the mitigations while changes are still cheap to make.

Data protection controls

We apply encryption, access restrictions, and monitoring in proportion to how sensitive each data set is, so the tightest controls sit where the real exposure is rather than everywhere at once.

Retention and deletion policies

We set how long each type of record is kept and why, then work with your engineers to make deletion automatic. Policy that only exists on paper doesn't survive an audit.

Subject request handling

We design the workflow for access, correction, and deletion requests: intake, identity verification, search across systems, and a response record you can produce later if a regulator asks.

Vendor and processor review

We assess the third parties handling your data, check the contract terms and safeguards behind each transfer, and flag the relationships that need renegotiating or ending.

How we approach privacy work

Privacy work fails when legal writes the policy and nobody changes the systems. We work with both sides, counsel and engineering, so what's written down matches what your infrastructure does. In practice, that means:

  • A data inventory that shows what you hold and where
  • Retention schedules with deletion automated, not left to good intentions
  • DPIAs run before launch, while design changes are still cheap
  • A subject request process your team can run on deadline
  • Vendor and transfer reviews covering the processors behind your data
We knew roughly what data we collected. We didn't know how many places it had ended up. The inventory was uncomfortable reading and exactly what we needed.
General Counsel, consumer software company
IDNotion consultants at work

Ready to get started?

Tell us what you're building or protecting, and we'll tell you where we would start.