Data Privacy & Compliance Review
Check how you handle personal data against GDPR / POPIA expectations.
A gap list against privacy principles with proportionate fixes.
Privacy reviews die of vagueness — “we take privacy seriously” — so the seats force specifics: the Privacy Counsel maps each data use to a lawful basis, the Compliance Officer checks the machinery that regulators actually inspect (records, requests, retention), and the Security Engineer verifies that the policy on paper matches what the systems do — the gap where most real breaches live. The Risk Officer ranks the exposure by what a complaint or audit would actually find, and the Pragmatist keeps the fixes proportionate to the team’s size, blocking the compliance-theatre checklist nobody maintains.
Review how we handle personal data and flag the privacy and compliance gaps. WHAT WE DO WITH DATA: [what personal data you collect, how, why, where it is stored, who you share it with, how long you keep it] JURISDICTIONS / FRAMEWORKS: [e.g. GDPR, POPIA, sector rules that apply] THE FEATURE OR CHANGE TRIGGERING THIS: [if any] Debate: 1. Lawful basis and consent — do we have a clear, valid reason for each use. 2. Data minimisation — are we collecting more than we need "just in case". 3. Retention and deletion — do we keep data too long; can we honour deletion requests. 4. Sharing and cross-border transfer — third parties and the risks. 5. The individual's rights — access, correction, deletion, portability. 6. Proportionate controls versus box-ticking. FINAL SYNTHESIS: - A gap list against the core privacy principles, severity-ranked. - The lowest-friction fix for each significant gap. - A clear note that this is general guidance, not legal advice, and a qualified privacy professional should validate.
An illustrative excerpt for a hypothetical brief of this type: A ten-person edtech startup storing student progress data has grown from one school to forty, added a US analytics vendor, and has never answered a deletion request because none has arrived yet. Every real run is generated fresh from your specifics, debated across rounds, and audited before the verdict.
Children’s educational data changes every default: consent flows through schools and parents, the lawful-basis analysis is stricter, and “legitimate interest” does far less work than the current policy assumes. The forty-school version of this company needs what the one-school version could improvise: a written basis per data use. Most will be fine — the point is knowing which ones are not.
The policy says data is deleted on school offboarding; the architecture says otherwise — analytics events flow to the US vendor and nothing in the described stack deletes on request there. That is the classic paper-practice gap: the deletion request that has never arrived will one day arrive, and the honest current answer is that it cannot be fully honoured. Fixing the vendor data path is engineering work; schedule it before the request, not after.
The cross-border transfer to the US vendor needs its paperwork checked now: what transfer mechanism is in the vendor contract, and does the vendor’s processing agreement actually cover children’s data? Schools increasingly send data-protection questionnaires before renewing — the next procurement round will ask, and “we assumed the vendor handles it” fails that questionnaire.
Proportionality, before this becomes a compliance program for a ten-person team: three fixes cover most of the real exposure — the written basis-per-use record, the vendor deletion path, and a tested deletion procedure with a named owner. The forty-page policy rewrite and the committee can wait. Do the three things a regulator or a school audit would actually check first.
Prefer drop-and-go? Use the Data Privacy & Compliance Review tool — team pre-seated, included with Plus.
Which regulations does the review cover — GDPR, POPIA, others?
State the jurisdictions and frameworks in your brief and the debate runs against those expectations — the underlying principles (lawful basis, minimisation, retention, rights) are shared across GDPR, POPIA and their relatives, and the deliverable flags where your specific framework is stricter. It also says plainly that a qualified privacy professional should validate the result.
We’re small — do we honestly need this yet?
The review scales the answer honestly: for a small team the finding is usually “three real gaps and permission to ignore the rest for now” — the proportionate version, not the enterprise checklist. The trigger to run it is usually growth: new data types, new vendors, new markets, or bigger customers asking harder questionnaires.
What is a “paper-practice gap” and why does the review hunt it?
It is the distance between what your policy claims and what your systems do — deletion promised but not implemented, retention limits nobody automated, a vendor processing more than the contract says. Regulators and litigants both go straight for that gap, because it converts a policy into evidence.