SECOMPSSECOMPS
Home/Services/Data Privacy
CMP 07

Data privacy programmes.

CCPA, India's DPDP Act and the growing patchwork of state and national privacy laws. One programme built on a single data inventory, rather than a separate scramble for each jurisdiction.

At a glance

Regimes
CCPA and CPRA, DPDP Act, GDPR, sectoral laws
Timeline
2 to 4 months
Foundation
A single data inventory serving every regime
Deliverables
Notices, rights workflows, vendor terms, training
Maintenance
Annual review as new laws commence
01Overview

What this actually is.

Privacy law is fragmenting faster than most legal teams can track, and the instinct to run a separate project per jurisdiction produces duplicated work and inconsistent answers. Nearly every regime asks the same underlying questions. Build the inventory once and the jurisdictional differences become configuration.

02Scope

What we cover.

Unified data inventoryOne map of personal data across systems, purposes, recipients and retention, serving every applicable regime.
Applicability analysisWhich laws actually apply to you based on where your users are, your revenue and your data volumes.
Consumer rights workflowsAccess, deletion, correction, opt-out of sale or sharing, and limiting sensitive data use, working end to end.
Notices and disclosuresPrivacy policies and collection notices that describe what you genuinely do, in each required form.
Consent and preference managementWhere consent is the basis, capturing it defensibly and honouring withdrawal across systems.
Vendor and processor termsContractual requirements flowed down to the vendors handling data on your behalf.
Retention and deletionSchedules that are enforced technically rather than documented aspirationally.
Breach notification readinessDiffering thresholds and deadlines across regimes, resolved into one internal process.
03Fit

Who needs this.

  • Businesses with users across multiple states or countries
  • Companies subject to India's DPDP Act alongside international regimes
  • Organisations receiving consumer rights requests they cannot currently fulfil
  • Teams whose privacy policy no longer matches what the product does
04Questions

Frequently asked.

Which US state laws apply to us?

It depends on where your consumers are, your revenue, and how much personal data you process. Several states now have comprehensive laws with differing thresholds. We run the applicability analysis first so you are not building for laws that do not reach you.

How does India's DPDP Act change things for us?

It introduces notice and consent obligations, purpose limitation, security safeguards, breach reporting and data principal rights, with meaningful penalties. If you already run a GDPR programme, much transfers across, but consent handling and the specifics of breach reporting need direct attention.

Can one privacy notice cover everything?

Usually yes, with jurisdiction-specific sections, which is far more maintainable than parallel notices that drift apart. Some regimes require particular disclosures in particular formats, and we handle those as additions.

Do we need consent for everything?

No, and over-relying on consent creates fragility. Different regimes recognise different lawful bases, and choosing the right basis per activity is more durable than a consent banner covering processing that never needed consent.

Find out what stands between you and certification.

Start with a gap assessment. You get a specific list of what is missing and a realistic timeline, whether or not you continue with us.