Watch DemoRead About It
Browse ServicesService Provider InfoSign In / Up
LegalAll statesComing soon

Privacy Compliance Program (GDPR/CCPA)

Service description

A privacy compliance program is the set of policies and routines that lets a business handle personal data lawfully: mapping what data it holds, publishing accurate privacy notices, and answering consumer requests to access or delete their information. The provider builds it around the laws that apply to the business, which may include the EU's GDPR, California's CCPA and other state privacy laws.

Common industries

Applies to any business that collects personal data, notably e-commerce, software, healthcare and advertising.

ROI

Compliance avoids steep privacy penalties and satisfies enterprise customers' data-handling requirements; recurring as laws expand.

Benefit

Stand up a privacy program — policies, data mapping, consumer-rights handling — to meet GDPR, CCPA, and the growing state patchwork.

Why get it

Whether a privacy law applies turns on where customers live and what data the business handles, not only where the business is located. Enterprise customers also increasingly ask vendors to show a working program.

When you benefit

Built once, then maintained: notices, data maps and request handling are reviewed regularly as the business's data practices and the laws change.

What it costs

Flat setup, then retainer.

When you pay

Providers typically quote a flat fee for the initial build, then a monthly retainer or hourly rate for upkeep. Payment is often split between a deposit at the start and milestones as policies and data maps are delivered.

Other costs

Data-mapping or consent-management software, and training for staff who handle personal data. Help with a regulator's inquiry is usually priced separately.

Risks to know

A business that publishes a privacy notice it doesn't follow can face action for deceptive practices under the FTC Act (15 U.S.C. §45). Collecting data without the required notice, or missing a consumer's rights request, can violate the CCPA or GDPR, and a program that exists only on paper won't answer a regulator's questions.

When risks arise

Exposure starts the day the business begins collecting regulated data, whether or not a policy exists. It typically surfaces when a consumer complains, a regulator inquires, or a customer's security review asks for proof of compliance.

The process

The provider maps the business's data flows and identifies which laws apply. It then drafts the privacy notice, internal policies and a process for consumer requests, with vendor contract terms where needed. The business reviews each deliverable and trains the staff involved, and the provider sets a schedule for periodic review.

Your commitment

The business describes what personal data it collects, where it is stored, and which vendors receive it, and names someone to own the program. It should tell the provider where its customers live and which products collect data, since that determines which laws apply.

Documents to gather

Helpful reading

Further research

Suggest an edit to this page →

Not open yet

Privacy Compliance Program (GDPR/CCPA) isn’t taking requests yet. Join the waitlist. It is listed in your requests tray.