Policies and Processes

ASK A QUESTION

Good data protection isn’t one policy. It’s a set of them that fit together and match how your business runs. We help you build that set, or tighten up the one you’ve already got.

Whether you’re a new business putting policies in place for the first time or an established one that knows its current set has gaps, the work is the same: figure out what your business actually does with personal data, then write the policies and processes to match.

No two businesses need the same thing. A recruitment agency handles far more personal data, and more sensitive data, than a marketing agency working B2B, so their frameworks look nothing alike. That’s why a downloaded pack of policies rarely fits.

We can advise on and prepare:

  • data protection policies
  • privacy notices
  • data retention policies
  • subject access request policies and procedures
  • data breach policies
  • data breach impact assessments
  • legitimate interests assessments
  • data processing agreements
  • data sharing agreements
  • information security policies
  • website compliance
  • data protection audits

There’s no point having policies that sit in a folder no one opens. We build frameworks your team can understand and follow while they’re getting on with their jobs, because a policy only protects you if people use it.

A policy in a drawer protects no one. We write the kind of policies people can actually follow.

Head of DepartmentDiane PearcePartner

We work with businesses at every stage: one writing its data protection framework from scratch, or one whose policies have grown piecemeal and no longer line up. Wherever you sit on that scale, here’s where our data protection work applies.

If you’re not sure which of these fits your situation, call us, and we’ll point you in the right direction.