Data & Privacy Advisory · Independent
Data & privacy advisory, independent
Data and privacy advisory is an independent review for Australian organisations with a bespoke platform or CRM where no one has recently asked the hard questions about hosting, access, backups or breach response. The OAIC's Notifiable Data Breaches reports regularly identify compromised credentials, human error and access control failures among breach causes. We sit with the platform developer, document the answers and produce a risk rated plan leadership can hand to its MSP.
The gap
You grew into your systems, now no one knows how it works
A custom CRM was built years ago. The MSP runs the network and devices. Someone still needs to look at the software itself, not just the network. The bespoke platform's developer may be the only person who fully understands it. Leadership sits between them.
The answer is not a two hundred page audit. It is an independent person asking the right questions about hosting, encryption, access, backups, supply chain and incident response, then recording the answers and what to do next.
Scope
The four areas we cover
Data lifecycle and retention
Access and permissions
Incident response readiness
Escalation paths, notification commitments and practical gaps, supported by our automated decision disclosure template, known as ADM.
Method
How the engagement runs
Kick-off
Confirm scope and platform
The sponsor confirms the platform, priorities, stakeholders and timing.Discovery
Working sessions with the developer
We interview the platform owner and review available policies, sub-processor lists and assurance reports.Draft
Draft advisory report
Findings are rated low, medium or high and paired with practical recommendations and suggested owners.Walkthrough
Final report and plan
Leadership reviews the findings and receives an action ready report for the MSP or another delivery partner.
Deliverable status
What you walk away with
Written advisory report
- Findings by area
- Low, medium or high risk ratings
- Recommendations
- Suggested owners
Supply chain map
- Sub-processors
- Where each sits
- Assessment status
- Concentration risk
Leadership walkthrough
- Leadership walkthrough
- Stakeholder questions
- Priority agreement
- Action ready output
Boundaries
What this engagement is not
A formal compliance audit
A penetration test
An implementation project
Legal advice
Vendor management
Triggers
When to call us in
Asked about data handling
New obligations on the horizon
Evidence required
No one has looked in years
Application layer is unowned
Personal and sensitive data
Recent work
Independent review of a platform holding sensitive client data
Related work
What tends to sit beside Data & Privacy Advisory
Practical details
Questions about Data & Privacy Advisory
Scoping call