The DPDP Rules are phasing in through 2026 and 2027. Organisational compliance is mandatory by 13 May 2027.

What this means for you

Home / Engagement

How the work runs, from first call to handover.

The engagement moves through a sequence of named steps. Each one closes with documents your team keeps and a decision your leadership has signed off. Which steps apply, and how far each goes, depends on your business. We agree all of that in writing before the work starts.

Every step produces documents

Nothing closes on a conversation. Each step ends with written output your team reviews, adopts and keeps.

Scope is agreed before the start

You know which steps apply, what each produces and what we need from your team before any invoice exists.

Decisions stay with you

Where a choice is genuinely open, we write up the options and the risks. Your leadership decides and we record it.

Steps can run in parallel

Drafting often begins while discovery finishes in a quieter corner of the business. The sequence guides the work, it does not block it.

Step

Intake and engagement

Before any assessment work, we establish that we can act for you, write down what we are doing, and name the people on your side who will own each part of it. Engagements that skip this step stall halfway through because nobody is clear who decides.

This is also where we flag anything that would change the shape of the work, such as a group structure, a parent company abroad, or an existing adviser already handling part of the picture.

What you receiveDocuments
Conflict and matter checkA short note confirming we can act for you, covering your group entities, funders, major vendors and any connected parties.
Engagement letter and scopeWhich steps apply, what each produces, what we need from you, the fee for each, and how changes to scope get agreed.
Governance charterNamed owners for each area: who signs off decisions, who handles complaints, who runs the systems, and who we contact when something is unclear.
Kick off planThe interview schedule, the systems we will need access to, and the dates each step is expected to close.
Step

Discovery and mapping

This is the step that does the real work. We interview the people who actually use each system, not only the people who own them, because the gap between the two is where unrecorded data usually lives. Sales keeps a personal spreadsheet. Support runs a WhatsApp group. Someone built a form in 2022 that still collects responses.

By the end of it you have a written record of every activity in the business that touches personal data, which almost no small or medium business has before starting.

What you receiveDocuments
Interview recordsStructured notes from each function: sales, operations, support, technology, human resources and finance, with the systems each one named.
Record of processing activitiesOne row per activity: what data, about whom, for what purpose, from where, who receives it, where it is stored, how long it is kept and who owns it.
Data flow diagramsDiagrams showing how data moves through your business, from the moment it is collected to the moment it should be deleted.
Vendor and tool registerEvery third party that receives personal data from you, what they receive, and what your contract with them currently says about it.
Step

Gap Assessment

Discovery tells us what you do. This step tells you what your current arrangements actually achieve. We take each activity from the map and work out whether the way you collect, use and share that data is genuinely supported by what customers were told and what they agreed to.

Most of the uncomfortable findings surface here. A consent box that covers three unrelated things. A notice that does not mention the vendor who receives the data. A marketing list whose origin nobody can explain. We write down what is actually true, with the reasoning, so the fixes that follow are aimed at something real.

What you receiveDocuments
Activity by activity analysisEach processing activity assessed against what currently supports it, with the reasoning recorded so your team can follow it later.
Consent quality reviewWhat your consent mechanisms actually capture, whether they are bundled, whether anyone can withdraw, and what records exist of who agreed to what.
Records about childrenWhere your business holds data about anyone under eighteen, what permission exists, and what needs to change. Prepared where this applies to you.
Marketing and profiling reviewHow your lists were built, what your advertising tools collect, and whether what you tell people matches what the tools actually do.
Step

Compliance Support

This is the largest step, and it is where most of the value sits. We write the documents your business needs, built from your own data map rather than from a template.

Not every item below applies to every client. A business with no customers under eighteen does not need the children's package. A business with no app does not need in product consent screens. The scope agreed at the start decides what gets drafted.

What you receiveDocuments
Rewritten privacy noticeBuilt from your actual processing record, consistent with every notice you use, in English and one further language where you need it.
Internal data protection policyHow your own team handles personal data: access, sharing, devices, exports, corrections and what to do when someone asks a question.
Rights and grievance procedureHow a request to see, correct or delete data gets received, checked, actioned and logged, with response templates and timelines.
Vendor contract terms and checklistData protection terms to add to your vendor agreements, plus a checklist for assessing the next vendor before you sign.
Breach response planWho does what in the first hours, what gets recorded, who has to be told and when, with the notification templates already written.
Retention scheduleHow long each category of data is kept, what triggers deletion, how deletion happens and who is responsible for running it.
Targeted risk assessmentA focused assessment of the one or two activities in your business that carry the most risk, with the mitigations written out.
Step

Implementation support

Documents on their own change nothing. Someone has to build the consent screen, configure the deletion job, close the old access and update the website. This step turns the drafted material into a list of tasks your developers or vendors can actually pick up.

We stay available while that happens, reviewing each item as it goes live rather than discovering at the end that the consent screen records the wrong thing.

What you receiveDocuments
Implementation trackerTicket level tasks for consent capture, logging, deletion, access changes and notices, each with an owner and a target date.
Consent and verification flow specificationExactly what each screen asks, what gets stored when someone agrees, and what happens when they change their mind.
Tool selection noteWhere a tool is genuinely needed, a shortlist with the trade offs. Where your existing setup is enough, we say so and you spend nothing.
Step

Training, assurance and close out

The last step tests whether any of it holds. We train the people who touch personal data, then run the new processes against realistic situations. A dummy deletion request. A withdrawal of consent. A simulated lost laptop on a Friday evening.

What fails gets fixed or recorded as an open item with a date. You finish with a pack that shows what you assessed, what you decided and what you built, which is the thing that matters if anyone ever asks.

What you receiveDocuments
Training materials and attendance recordA short session for all staff and deeper sessions for the people handling requests, data exports or vendor relationships.
Assurance and test reportResults of the breach exercise, the test requests and the withdrawal test, with anything that failed written down and assigned.
Close out reportWhat was done, what risk remains, what is still open, and an index pointing to every document produced during the engagement.
Review calendarWhat to check and when, loaded into your own calendar, so the work stays current after we step away.
Within the engagement

Breach response

Something goes wrong eventually. A laptop is left in a cab, a vendor emails a spreadsheet to the wrong address, or an old server turns out to have been reachable for a month. Most of the damage comes from the hours afterwards, when nobody is certain who decides, what to write down, or whether the clock has already started.

We build the plan before you need it, as part of Compliance Support. It names the people who act in the first hours, sets the order they act in, and fixes what gets recorded at each point. We draft the notification letter templates specific to your business, so nobody is writing them under pressure, and we run one practice exercise with your team against a scenario drawn from your own systems.

What you receiveProcedure
Breach response planWho is called first, who decides, who speaks to affected people and who files the notification, with a named substitute for every role.
First hours checklistOne page for whoever takes the call: what to contain, what to preserve, what not to delete, and what to write down while it is still fresh.
Notification letters templates specific to youThe letter to affected people and the notification to the Data Protection Board, written ahead of time with the facts left blank, so the only work on the day is filling them in.
Incident registerA record of every incident, including the ones that turn out to be nothing, carrying the assessment that decided whether it had to be reported.
Practice exercise and findingsOne run through a realistic scenario with your team, and a short note on where it stalled and what we changed because of it.
Within the engagement

Requests from customers and staff

People can ask to see the data you hold about them, have it corrected, have it erased, or withdraw a consent they gave you earlier. Your own staff can ask, and so can a parent on behalf of a child. Every request starts a clock, and a request that sits unread in a shared inbox for three weeks has already failed.

We build the route that receives them. It is drafted during Compliance Support and tested during Implementation support, so that by handover a request arriving at your published address reaches a named owner, gets checked against identity, gets actioned across every system holding a copy, and gets answered inside the timeline.

What you receiveProcess
Request handling procedureThe route from arrival to answer: where requests land, who owns them, how you confirm the person is who they say they are, and what to do when you cannot.
Response templatesA prepared reply for each kind of request, including the ones you are entitled to refuse, with the reason written in language the person will understand.
Request registerA log of what was asked, what you did and when. This is what you produce if anyone asks whether you actually answer people.
Deletion mapWhere each category of data really lives, including backups, exports and vendor systems, so erasure reaches every copy rather than the first one you find.
End to end testWe submit live requests as a member of the public before handover, then record how long each one took and where it got stuck.
Within the engagement

More than one framework

If you sell to customers in the European Union, hold records on staff based abroad, process data on behalf of a client who answers to another country's rules, or take card payments, a second set of obligations lands on the same systems you already run. Handled separately they produce two registers, two sets of notices and two sets of training that quietly disagree with each other.

We settle which frameworks reach you during Applicability and roles, then build once. One set of controls, one record of what you hold and why, and a mapping that shows how each control answers each framework. Where two frameworks genuinely ask for different things, we write up both positions with the risk attached and your leadership decides which one governs.

What you receiveRecord
Scope noteWhich frameworks reach your business and why, including the ones people commonly assume apply to them and do not.
Control mappingOne table setting each control you operate against the requirement it satisfies in each framework, so a single piece of evidence answers more than one question.
One record of processingA single register built to carry the fields every applicable framework asks for, rather than one register per framework drifting apart over time.
Conflict noteWhere two frameworks ask for different things, both positions written out with the risk, and the decision your leadership took recorded against it.
Added where needed

Modules that attach to the engagement.

Some businesses need more than the core sequence. These attach to the relevant step rather than running separately, and each is agreed before it starts.

Optional

Full impact assessments

A detailed assessment for a high risk activity, covering why it is necessary, what alternatives exist, who could be harmed and what reduces that.

Optional

Extended assurance testing

Unannounced test requests submitted as a member of the public, sampling of your consent records, and a test of whether a vendor can actually return your data.

Optional

Training your own trainers

A facilitator guide and two sessions with your internal trainers, so you can run induction for new staff without bringing us back each time.

Optional

Data sharing programme

Where you share data with partners, sponsors or group companies, a sharing agreement, a due diligence checklist and rules on what may be shared.

Optional

Plain language explainers

A short notice and script written for the people whose data you hold, including customers, parents or members, rather than for your lawyers.

Optional

Periodic review

A set number of hours each month for escalations, new tools, new activities and a scheduled check that what we built is still being followed.

End to end or modular, your choice. Every step listed above can run as a single engagement or stand alone as a module. The first conversation establishes what you need, and the engagement letter records exactly that.

Next

Find out which of these steps your business needs.

A thirty minute call is enough to tell. You leave knowing the three gaps that matter most, whether or not you engage us.