Data Protection

Practical controls for organizations handling personal data.

Organizations that handle personal data — customer records, patient files, staff information — need practical safeguards, not paperwork for its own sake. Software providers with access to that data carry processor responsibilities, and we help you meet them in the systems themselves.

01

Controller & Processor Mapping

The first question is not technical: who decides about personal data, and who merely processes it on someone else's behalf? Get that wrong and every downstream obligation is attached to the wrong party.

As controller

You decide the purposes and the means. That carries a lawful basis and purpose limitation — the obligation to only process data for a reason you can point to, and only for that reason.

As processor

You act on another party's instructions. That carries contract terms and security duties instead — what you are required to do with the data while you hold it.

02

Protection Assessments

Reviewing how personal data flows through your applications, where it rests, who can reach it, and where the gaps are — reported plainly, in priority order rather than as a wall of findings.

Where it enters

The forms, imports and integrations that bring personal data into your systems in the first place.

Where it rests

The databases, file stores and backups holding it, including the copies nobody remembers making.

Who can reach it

Roles, shared accounts and service access — which is usually where the gaps are.

Where it leaves

Exports, third-party services and vendor transfers, and what happens to it once it is outside.

03

Privacy & Security Controls

Implemented in the software rather than written in a policy and hoped for. A control that is not in the system is not a control.

Access control

Enforced in the application and the data layer, not only described in a document.

Audit trails

Who accessed or changed personal data, and when — answerable after the fact.

Encryption at rest & in transit

Applied where the data actually sits, including backups and exports.

Retention handling

Personal data is removed when it should be, rather than kept indefinitely by default.

04

Policies & DPIA Support

Security policies and the technical input a data protection impact assessment needs: what the system actually does with the data, where it lives, and who can reach it — the evidence an assessment depends on.

Security policies

Written against what your systems actually do, so they can be followed.

DPIA technical input

The engineering evidence your DPO or counsel needs to make the legal call.

Security awareness

For the people who handle the data day to day, which is where most of it goes wrong.

Technical support, not legal advice. We supply the engineering and operational evidence your DPO or counsel needs to make the legal calls. The legal interpretation — lawful basis, consent, whether a processing activity is proportionate — is theirs, not ours.

Handling personal data?

Tell us what you process and where it lives. We will map the flows, name the gaps and prioritise the fixes — in the systems, not on paper.