Data Protection Strategy
Classification, retention and access control that satisfy regulators and auditors.
Data protection usually breaks down on a simple question: where is the personal data? Organisations that cannot answer it accurately cannot honour a deletion request, and cannot scope a breach.
We build classification, retention and access control that satisfy regulators and auditors — starting with knowing what you hold and why.
How we approach it
We map data flows before writing policy. Policy that does not match reality creates the appearance of compliance without the substance, which is worse than none.
Why this matters
-
You know what you hold
A maintained inventory of personal data, purpose and location.
-
Requests handled properly
Access, deletion and portability requests answered within statutory time.
-
Retention enforced
Automated deletion so old data does not accumulate indefinitely.
-
Evidence for audit
Documentation demonstrating accountability under UK GDPR.
What is included
-
Data mapping
Flows, systems, purposes and lawful bases documented.
-
Classification
A scheme applied consistently across systems and storage.
-
Retention and deletion
Schedules implemented as automation, not as policy alone.
-
Access control
Least-privilege access with review cycles and logging.
How we deliver it
-
01
Assess
Interviews, documentation review and hands-on inspection to establish what is actually true about how data is currently handled today.
-
02
Analyse
Findings tested against your commercial constraints, so recommendations are affordable as well as correct.
-
03
Recommend
A prioritised plan with sequencing, costs, dependencies and the risks of doing nothing.
-
04
Implement
We deliver the work ourselves or support your team through it, whichever you prefer.
-
05
Review
Measurement against the baseline we agreed at the start, and an honest account of what did not land.
What you receive
- Data map and record of processing activities
- Classification scheme and applied labelling
- Retention schedule with automated enforcement
- Access control review and remediation
- Subject request handling procedures
Tell us about your idea, and we'll make it happen.
Have a problem that needs solving? We would like to hear about it.