Solutions · Risk & regulatory
Data Protection & Privacy
Privacy regulation keeps arriving and keeps changing: GDPR and UK GDPR, POPIA in South Africa, the Australian Privacy Act, CCPA in California. We audit where you stand and give you a clear path to compliance.
What we do
- Audit current handling of personal information against the applicable regimes
- Identify data protection risks and the gaps behind them
- Apply accelerators that turn obligations into navigable steps
- Keep you tracking changes to existing standards and new ones
Outcomes
- A documented view of exposure across jurisdictions
- Practical remediation rather than a list of legal text
- Evidence of compliance when it is asked for
- Faster response to new regulation
A moving target
Privacy regulation keeps arriving and keeps changing. GDPR and UK GDPR, POPIA in South Africa, the Australian Privacy Act, CCPA in California: the scope differs, the direction does not. Each new regime sets a precedent that others follow, and the organisations caught out are usually the ones that treated compliance as a one-off project.
The difficulty is rarely the intent of the law. It is interpretation: what a requirement means for your data, your systems and your suppliers, and what evidence a regulator would accept.
How we help
- Audit. A data protection audit establishes whether you comply today, identifies where the risks sit, and makes concrete recommendations rather than generic findings.
- Accelerators. Knowing what must be done is one thing; doing it is another. Our accelerators turn obligations into clear, navigable steps, so exposure inside the organisation is understood and closed quickly.
- A continual baseline. Standards evolve. Our frameworks give you a process to return to, with pulse checks built in, so the next amendment is an update rather than a programme.
Where it meets governance
Data protection depends on the same foundations as everything else we do: knowing what data you hold, where it came from, who may use it and for what. Organisations with governance and lineage in place answer a privacy request in hours. Organisations without spend weeks finding out what they have, and that gap is exactly what enforcement exposes.
Common questions
What is the General Data Protection Regulation (GDPR)?
The GDPR is a regulation in EU law covering data protection and privacy in the European Union and the European Economic Area, including the transfer of personal data outside those areas. Its primary aim is to strengthen an individual's control and rights over their personal data, and to simplify the regulatory environment for international business.
What is the California Consumer Privacy Act (CCPA)?
The California Consumer Privacy Act of 2018 gives consumers more control over the personal information businesses collect about them, with regulations that set out how to apply the law. It secures new privacy rights for California consumers, including the right to know what personal information a business collects and how it is used.
What about POPIA and the Australian Privacy Act?
Both matter more to our clients than California does. South Africa's Protection of Personal Information Act and the Australian Privacy Act cover similar ground to the GDPR, with differences in scope, timelines and enforcement. We assess against every regime that applies to you rather than treating one as the template.
Ready to move AI into production with proof?
Leave your details and we will arrange a conversation.