Privacy Compliance Program (GDPR/CCPA)
Service description
A privacy compliance program is the set of policies and routines that lets a business handle personal data lawfully: mapping what data it holds, publishing accurate privacy notices, and answering consumer requests to access or delete their information. The provider builds it around the laws that apply to the business, which may include the EU's GDPR, California's CCPA and other state privacy laws.
Common industries
Applies to any business that collects personal data, notably e-commerce, software, healthcare and advertising.
ROI
Compliance avoids steep privacy penalties and satisfies enterprise customers' data-handling requirements; recurring as laws expand.
Benefit
Stand up a privacy program — policies, data mapping, consumer-rights handling — to meet GDPR, CCPA, and the growing state patchwork.
Why get it
Whether a privacy law applies turns on where customers live and what data the business handles, not only where the business is located. Enterprise customers also increasingly ask vendors to show a working program.
When you benefit
Built once, then maintained: notices, data maps and request handling are reviewed regularly as the business's data practices and the laws change.
What it costs
Flat setup, then retainer.
When you pay
Providers typically quote a flat fee for the initial build, then a monthly retainer or hourly rate for upkeep. Payment is often split between a deposit at the start and milestones as policies and data maps are delivered.
Other costs
Data-mapping or consent-management software, and training for staff who handle personal data. Help with a regulator's inquiry is usually priced separately.
Risks to know
A business that publishes a privacy notice it doesn't follow can face action for deceptive practices under the FTC Act (15 U.S.C. §45). Collecting data without the required notice, or missing a consumer's rights request, can violate the CCPA or GDPR, and a program that exists only on paper won't answer a regulator's questions.
When risks arise
Exposure starts the day the business begins collecting regulated data, whether or not a policy exists. It typically surfaces when a consumer complains, a regulator inquires, or a customer's security review asks for proof of compliance.
The process
The provider maps the business's data flows and identifies which laws apply. It then drafts the privacy notice, internal policies and a process for consumer requests, with vendor contract terms where needed. The business reviews each deliverable and trains the staff involved, and the provider sets a schedule for periodic review.
Your commitment
The business describes what personal data it collects, where it is stored, and which vendors receive it, and names someone to own the program. It should tell the provider where its customers live and which products collect data, since that determines which laws apply.
Documents to gather
- Current privacy policy and cookie notice
- A list of systems and vendors that hold personal data
- Data processing agreements with vendors
- Records of past consumer requests or privacy complaints
Helpful reading
- Protecting Personal Information: A Guide for Business — Federal Trade Commission
- NIST Privacy Framework — National Institute of Standards and Technology
- Data protection guide for small business — European Data Protection Board
- US State Privacy Legislation Tracker — International Association of Privacy Professionals
Further research
- Regulation (EU) 2016/679 — General Data Protection Regulation (EUR-Lex)
- California Civil Code § 1798.100 — General duties of businesses that collect personal information (California Consumer Privacy Act)
- California Privacy Protection Agency — CCPA law and regulations
- California Attorney General — California Consumer Privacy Act (CCPA)
- Code of Virginia, Title 59.1, Chapter 53 — Consumer Data Protection Act
- 15 U.S. Code § 45 — Unfair methods of competition unlawful (FTC Act § 5)
Not open yet
Privacy Compliance Program (GDPR/CCPA) isn’t taking requests yet. Join the waitlist. It is listed in your requests tray.