When this work helps
For organisations needing recurring privacy advice, coordination across teams or support for an internal privacy owner.
Scope and practical outputs
Agree retainer capacity for questions, selected reviews, governance meetings and follow-up on priorities. Define any additional compliance services separately.
- An advisory mandate and responsibility map.
- A review calendar and record of advice on agreed matters.
- A progress brief covering decisions, open actions and responsible owners.
What your team contributes
Name a decision-maker and operational contacts. Give them time to answer questions, implement agreed changes and escalate new issues. Agree access and confidentiality before sharing records.
An example to discuss
A business introducing new suppliers every month may need recurring review capacity; a business with one unfinished notice may need a small project.
Agree the boundaries
Advisory support does not itself appoint a statutory DPO. Any formal appointment, reporting relationship, public contact role, response commitment and specialist involvement must be explicitly agreed after checking the relevant basis.
Common questions
What is included in the retainer?
The agreement specifies advisory capacity, review activities, reporting cadence and response arrangements. Additional work needs an agreed scope and fee.
Does the retainer appoint a statutory DPO?
A formal appointment requires its own reviewed basis and written mandate. Advisory support and appointment responsibilities must be made explicit.
Which support model fits your team?
Answer eight short questions about the work and capacity. The result explains the reasoning and includes an internal-capacity option.
Explore support optionsDiscuss the work you need
Agree the service, deliverables, responsibilities and fees before committing to an engagement.
Related reading
This page explains topics to scope and discuss. It does not establish applicability, certify compliance or confirm a paid engagement.
← Services