Data privacy programmes.
CCPA, India's DPDP Act and the growing patchwork of state and national privacy laws. One programme built on a single data inventory, rather than a separate scramble for each jurisdiction.
At a glance
- Regimes
- CCPA and CPRA, DPDP Act, GDPR, sectoral laws
- Timeline
- 2 to 4 months
- Foundation
- A single data inventory serving every regime
- Deliverables
- Notices, rights workflows, vendor terms, training
- Maintenance
- Annual review as new laws commence
What this actually is.
Privacy law is fragmenting faster than most legal teams can track, and the instinct to run a separate project per jurisdiction produces duplicated work and inconsistent answers. Nearly every regime asks the same underlying questions. Build the inventory once and the jurisdictional differences become configuration.
What we cover.
Who needs this.
- Businesses with users across multiple states or countries
- Companies subject to India's DPDP Act alongside international regimes
- Organisations receiving consumer rights requests they cannot currently fulfil
- Teams whose privacy policy no longer matches what the product does
Frequently asked.
Which US state laws apply to us?
It depends on where your consumers are, your revenue, and how much personal data you process. Several states now have comprehensive laws with differing thresholds. We run the applicability analysis first so you are not building for laws that do not reach you.
How does India's DPDP Act change things for us?
It introduces notice and consent obligations, purpose limitation, security safeguards, breach reporting and data principal rights, with meaningful penalties. If you already run a GDPR programme, much transfers across, but consent handling and the specifics of breach reporting need direct attention.
Can one privacy notice cover everything?
Usually yes, with jurisdiction-specific sections, which is far more maintainable than parallel notices that drift apart. Some regimes require particular disclosures in particular formats, and we handle those as additions.
Do we need consent for everything?
No, and over-relying on consent creates fragility. Different regimes recognise different lawful bases, and choosing the right basis per activity is more durable than a consent banner covering processing that never needed consent.
Related services.
If you process the personal data of people in the EU or UK, GDPR applies whether or not you have an office there. We build the data map, the assessments and the processes that make that defensible.
CMP 05ISO 42001 AI GovernanceThe first international standard for artificial intelligence management systems. If you build or deploy AI, enterprise procurement will start asking for this, and today almost nobody can answer.
SectorE-commerceYour attack surface is a payment flow that must stay frictionless, and fraud that looks exactly like ordinary traffic until you inspect the logic.
Find out what stands between you and certification.
Start with a gap assessment. You get a specific list of what is missing and a realistic timeline, whether or not you continue with us.