Consulting/ Privacy

A world map with privacy regulations pinned to their jurisdictions — CCPA/CPRA in California, GDPR in the European Union, LGPD in Brazil, POPIA in South Africa, PIPL in China, and Australia's Privacy Act — alongside the obligations they share, such as lawful basis, data subject rights, breach reporting, and data minimization

Consulting · Privacy

Records and Information
Management Privacy Evaluations

Which privacy regulations touch which of your activities — and what to do about it. Our team specializes in GDPR, CCPA/CPRA, and the growing patchwork beyond, with a proactive plan to get compliant and stay that way.

Schedule an evaluation

Privacy services

Our consulting team offers several privacy-related services to determine how your organization may be impacted by various privacy regulations, or to assist with a variety of other privacy-related initiatives. Four engagements, and most programs need more than one; they share a premise: privacy obligations land on the retention schedule, so that is where we fix them.

Records management evaluation

Ensuring your organization is compliant with different privacy regulations around the globe is a significant undertaking that requires time and resources. We help determine which of your organization's activities are affected by which regulations and create a proactive plan for you to be compliant — and stay that way. Regulations we specialize in: the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), and more.

Proactive, not reactive — the plan is built before a request or an audit forces the question.

Retention period minimization

Propose opportunities and collaborate with stakeholders to defensibly decrease retention schedule periods, shrinking costs and risks associated with over-retention of records and personal information. We propose the reductions, then work them through the stakeholders who have to live with them.

Over-retention is the quiet liability: every extra year is more to store, more to search in discovery, and more to lose in a breach.

Privacy compliance monitoring

Receive updates on privacy laws and regulations to support ongoing compliance and make informed changes impacting your retention schedule — translated into the specific changes required, not a newsletter you have to interpret yourself.

Privacy law changes faster than any schedule refresh cycle. Monitoring is what keeps the two from drifting apart.

Compelled privacy review

Comply with mandatory privacy laws with defined maximum retention periods for regulated categories of personal data. Some laws do not merely permit deletion — they compel it once the purpose is served.

This is where privacy and recordkeeping genuinely conflict: one rule says keep it, another says destroy it. The schedule has to resolve both.

How an evaluation works

An evaluation is a scoping exercise before it is a compliance exercise. You cannot apply a privacy law to data you have not located, and most organizations hold more personal information, in more systems, than their own inventory shows.

Step 01

Find the personal data

Identify what personal information you collect, where it lives, who touches it, and why you hold it. Purpose is the hinge — nearly every privacy regime measures how long you may keep data against the reason you collected it.

Step 02

Match it to the law

Determine which regimes reach which activities. Jurisdiction rarely follows your org chart: it follows where your customers, employees, and processing sit, so one system can answer to several laws at once.

Step 03

Put it in the schedule

Translate the findings into retention periods, disposition rules, and the documented basis for each. A privacy obligation that never reaches the retention schedule is an opinion, not a control.

The regimes we work in

Our consultants specialize in GDPR and CCPA/CPRA, and work across the wider patchwork. What follows is what each one tends to drive in a retention schedule.

GDPR — European Union

Storage limitation is a principle, not a guideline: personal data may be kept only as long as the stated purpose requires. Drives documented lawful basis, data subject rights, and breach reporting into the schedule.

CCPA / CPRA — California

CPRA added an explicit retention angle: you must disclose how long you keep each category of personal information, or the criteria you use to decide. That is a schedule question before it is a privacy-notice question.

LGPD — Brazil

Closely modeled on GDPR, with its own regulator and its own legal bases for processing. Organizations with Brazilian operations or customers frequently discover it after building a GDPR program.

POPIA — South Africa

Conditions for lawful processing, with retention tied to the purpose for which the record was collected. Records kept beyond that purpose need a specific justification to stay.

PIPL — China

Separate consent for sensitive personal information and real constraints on moving data out of the country. Cross-border transfer is usually the requirement that reshapes an existing program the most.

Privacy Act — Australia

The Australian Privacy Principles require destroying or de-identifying personal information once it is no longer needed for a permitted purpose — an affirmative disposal obligation, not merely permission to delete.

What you get

Deliverables you can hand to counsel, IT, and an auditor. Not a slide deck.

Applicability findings

Which regimes reach which of your activities, and the reasoning behind each call.

Retention recommendations

Proposed periods for each affected category, with the legal basis documented.

Gap analysis

Where current practice diverges from the obligations, ranked by exposure.

A plan you can execute

Sequenced next steps, scoped to what your team can realistically absorb.

Who does this work

Privacy law, read by people who practice it.

Our privacy work is led by licensed attorneys who also hold privacy credentials — CIPP/US, CIPP/E, CIPM, and AIGP — alongside the records credentials the retention side demands. That combination is the point: privacy obligations only become real when they reach the schedule.

Meet the consultants →

Privacy law moved again. Did your schedule?

Schedule an evaluation