Privacy work at scale, for organisations that couldn't get it wrong.
Three engagements with global organisations across retail, mining and healthcare — the problems they faced, what was delivered, and what changed as a result. The same thinking now applied to UK businesses at a fixed fee.
These case studies are anonymised. Our work is covered by confidentiality, so we describe engagements by sector and scale rather than naming clients. Named references are available on request.
Privacy by design for global transformation.
A major finance and procurement transformation involved significant volumes of employee, supplier and business-partner data across multiple jurisdictions. Privacy requirements needed to be embedded into the programme itself — not bolted on after implementation.
A global retail organisation operating across more than thirty markets, each with its own regulatory expectations, business functions and data-handling practices to reconcile.
Privacy-by-design support throughout the transformation
DPIAs and privacy risk assessments
Records of Processing Activities
International data-transfer assessments
Supplier and third-party privacy reviews
Data retention and minimisation requirements
Access controls and protection of employee data
Cross-functional work with legal, technology, security and business teams
Privacy requirements were integrated into the programme's design and implementation, helping the organisation identify risks earlier and establish a more consistent approach to compliance across multiple markets.
Data privacy during corporate separation.
The separation created privacy and data-governance questions around which organisation could access and use personal data, how information could be transferred between entities, and what controls were required during the transition itself.
A global mining organisation undergoing a significant corporate separation, with personal data spread across shared systems, jurisdictions and business functions on both sides of the split.
Privacy advice supporting the separation programme
Review of data-processing activities
Data mapping and RoPA updates
DPIAs and privacy risk assessments
Review of data-sharing arrangements
International transfer considerations
Privacy notices and documentation updates
Practical privacy controls advised to programme stakeholders
Privacy risks and responsibilities were identified as part of the separation process, supporting a controlled transition of data and clearer accountability between the two organisations.
Building a global privacy governance framework.
The organisation needed a consistent privacy-governance approach while dealing with different regulatory requirements, business functions and international data-processing activities — all involving sensitive personal information.
An international healthcare and medical-device organisation processing special-category data across multiple jurisdictions, with varying local expectations and no single governance standard in place.
Global privacy advisory support
DPIAs and privacy risk assessments
Data-processing and vendor reviews
International data-transfer guidance
Privacy policies and governance documentation
Support with data-subject rights
Stakeholder guidance and privacy awareness
Applying privacy requirements to operational activities
The work strengthened the organisation's privacy-governance framework and gave stakeholders clearer processes for identifying, assessing and managing privacy risks across the business.
Fifteen years of this, now priced for smaller businesses.
The same privacy thinking applied at global scale is what sits behind a fixed-fee GDPR health check for a practice with fourteen staff. The scale changes; the discipline doesn't.
Your business doesn't need to be global to need this.
Book a free 30-minute consultation and we'll tell you what's actually proportionate for a business your size — including if the answer is very little.
