WEEKS 01–02
Design
Target state and decisions
Lawful basis per processing activity, consent model, retention positions, and the decisions that need a signature before anything is built.
Fixed scope · Fixed fee · Eight weeks
In eight weeks we build the programme itself — notice, consent, rights, retention, transfers, breach response — and hand you the evidence that it works.
Not a policy pack. Working controls, running workflows and a documented, tested response plan, delivered by the people who scoped the work.
What we build
Itemised privacy noticeConsent capture & withdrawalConsent artefact storeConsent Manager integrationRoPA maintenance processData principal rights workflowGrievance redressalRetention schedule & erasure jobsProcessor agreementsTransfer assessmentsRule 6 security safeguardsAccess review & loggingRule 7 breach response planCERT-In reporting runbookDLT notification templatesVerifiable parental consentDPIASDF obligationsDPO or contact appointmentBoard reporting packRole-based training
Scoped to what applies to you. Where an obligation does not reach your processing, we say so in writing rather than billing for it.
The engagement
Every session is booked in advance against named people. If a phase needs more of your team than this, we tell you before it starts.
WEEKS 01–02
Design
Lawful basis per processing activity, consent model, retention positions, and the decisions that need a signature before anything is built.
WEEKS 03–05
Build
Notices drafted per journey, consent capture and withdrawal specified for your engineers, rights workflow stood up with owners and SLAs inside the statutory window.
WEEKS 06–07
Harden
Processor agreements repapered, transfers assessed, retention schedule wired to erasure jobs, access reviewed and logging retained as Rule 6 requires.
WEEK 08
Test & hand over
The breach plan run against a live clock, training delivered to the roles that need it, and the evidence pack handed to your compliance owner.
What you receive
All in editable form, all yours, whether or not you retain us afterwards.
01
Itemised notice per journey, plus the short-form variants for app and SMS.
02
Capture, withdrawal and artefact schema your engineers can build from.
03
Intake, verification, fulfilment and refusal grounds, with owners and timers.
04
Published route, escalation ladder and response templates.
05
Field-level, reconciled against sectoral record-keeping mandates.
06
Master clauses, security schedule and breach notification terms, repapered.
07
Per destination and per flow, with the position stated and dated.
08
Controls, access model and one-year log retention, with test evidence.
09
Named owners, decision tree, and both clocks on one page.
10
Board, CERT-In and data principal drafts, DLT-registrable where needed.
11
For the high-risk processing identified, completed rather than templated.
12
Plus the change trigger that keeps it current after we leave.
13
Evidence that the response plan was tested, signed and dated.
14
Programme status, residual risks and the quarterly cadence to keep it.
Fit
The fee
Banded by the size of your processing estate and the number of entities. Half your gap assessment fee comes off the first invoice if you continue within sixty days.
Get a scoped quoteQuestions
We specify, you build in your own systems — we do not write production code, deploy infrastructure, or procure tooling. Consent Manager platform licences, DLT registration fees and security tooling are yours. Everything else in the scope document is ours to deliver.
Eight weeks from signature, you can evidence it.
Free consultation · 45 min · scope and fee in writing within two working days.