Privacy, Data Protection & Security
Build security practices around the protection of sensitive and personal information while considering applicable regulatory requirements.
Privacy regulation asks a question most systems were not designed to answer: what personal data do you hold, where is it, who can reach it, and how long does it stay. Answering that is a security and architecture problem long before it is a legal one.
Our role is the security side of that. We help establish where personal data actually lives, what protects it and where the controls do not match the sensitivity of what they are protecting.
Data spreads faster than the map of it
Personal data rarely stays where it was collected. It is copied into an analytics warehouse, exported for a report, synced to a support tool and cached by a third-party integration — each step reasonable, none of them recorded in one place.
By the time a regulation asks where personal data is held, the honest answer often takes weeks to assemble. Building that picture is the practical starting point, because every control decision afterwards depends on it.
How this is put together.
Each stage carries access, security, privacy and control questions. The hard part is usually knowing which stages your data is actually in.
What each one is actually for.
Select a framework to see its focus and the considerations it usually raises.
Not every framework applies to every organization. Which are relevant depends on your sector, your customers and where you operate.
What this covers
SCOPE OF SERVICETMG Security provides cybersecurity and compliance support. We are not an auditor, a certification body or a law firm, and nothing here is legal advice. Organizations should obtain legal advice for legal or regulatory interpretation.
How we approach it
- 01DISCOVEREstablish where personal data is actually held.
- 02CLASSIFYUnderstand sensitivity and which requirements attach.
- 03REVIEWAssess the controls protecting each location.
- 04GAPIdentify where protection does not match sensitivity.
- 05PRIORITISERank by exposure and by what is straightforward to change.
- 06SUPPORTHelp implement and document the improvements.
When Do Privacy Requirements Reach Your Systems?
Output leadership can act on.
Which of these apply depends on engagement scope.
Where current practice differs from the requirements that apply to you.
Which controls address which requirements, and where nothing does.
What the gaps mean in terms of risk, not just non-conformity.
What needs to exist in writing, and what it needs to say.
Whether you could demonstrate a control operates, if asked.
Sequenced work, with dependencies made explicit.
A version of the findings that a board or exec team can act on.
Adjacent parts of the programme.
Questions we get asked before an engagement.
No. We work on the security and technical side — where data lives, what protects it, whether access is appropriate. Interpretation of a regulation, lawful basis and regulatory position are matters for qualified legal counsel, and we would say so rather than guess.
No provider can honestly promise that, and we would treat the claim as a warning sign. Compliance depends on your practices, your legal interpretation and in some cases an external assessment. We can materially improve the security posture that underpins it.
Data discovery, almost always. Every subsequent decision — access, retention, encryption, third-party sharing — depends on knowing where personal data actually is, and that answer is usually broader than expected.
Substantially, on the security side. The safeguards these regulations expect look a lot like the controls those frameworks describe, so work done for one usually carries over. The privacy-specific obligations sit on top.
Discuss Privacy & Data Protection
Tell us what personal data you hold and which regimes you think apply. The first useful step is usually finding out where that data actually is.
