Skip to content

Data & Privacy Advisory

Independent data and privacy advisory for one platform

Data and privacy advisory is an independent review for Australian organisations with a bespoke platform or CRM where no one has recently asked the hard questions about hosting, access, backups or breach response. We sit with the platform developer, document the answers and produce a risk rated plan leadership can hand to its MSP.

Describe the problem in a sentence or two. Please do not send credentials or sensitive records.

Best fit
One bespoke platform, CRM or line of business system
Main deliverable
Evidence based advisory report and action plan
Client effort
One sponsor plus developer or platform owner sessions
Commercial model
Fixed price for one nominated platform
Delivery ownership
  1. Scope
  2. Review
  3. Findings
  4. Walkthrough

The accountable team stays involved from scoping through the final walkthrough. Specialist capability is added where the evidence needs it, with responsibilities agreed before work starts.

Deliverable status

A written review your delivery partners can use

A fixed price quote for one nominated platform is agreed before work starts. The Pricing page explains how fixed scope advisory and follow on delivery are handled.

Advisory, not certification

Written advisory report

Plain language findings based on the evidence available during the engagement.
  • Findings by area
  • Low, medium or high risk ratings
  • Recommendations
  • Suggested owners
Evidence map

Supply chain map

A documented view of the services behind the platform and the status of each assessment.
  • Service providers
  • Where each sits
  • Assessment status
  • Concentration risk
Decision session

Leadership walkthrough

A session to agree priorities and route actions to the right delivery partner.
  • Leadership walkthrough
  • Stakeholder questions
  • Priority agreement
  • Action ready output
The nominated platform, evidence boundary and fixed price are agreed before work starts.

Scope

The four areas we cover

Platform review

Where the platform is hosted, whether data stays in Australia, how it is encrypted, how recovery is tested, what audit evidence and certifications exist, and which parties in the supply chain can reach it.

Data lifecycle and retention

The personal and sensitive data held, how long each type remains, how it is destroyed or archived and where copies exist.

Access and permissions

Roles, joiner mover leaver processes, privileged access, developer access and the cadence of access reviews.

Incident response readiness

Escalation paths, evidence available from the platform, contractual notification commitments and practical response gaps.

Recent work

Independent review of a platform holding sensitive client data

Working sessions and vendor evidence produced a thirty one page report and a prioritised action list for leadership.

Method

How the engagement runs

One nominated platform is reviewed per engagement. Multiple platforms are sequenced during scoping.
  1. Kick off

    Confirm scope and platform

    The sponsor confirms the platform, priorities, stakeholders and timing.
  2. Discovery

    Working sessions with the developer

    We interview the platform owner and review available policies, service provider lists and assurance reports.
  3. Draft

    Draft advisory report

    We rate findings low, medium or high and pair them with practical recommendations and suggested owners.
  4. Walkthrough

    Final report and plan

    Leadership reviews the findings and receives an action ready report for the MSP or another delivery partner.

The gap The platform grew without a clear owner

A custom CRM was built years ago. The MSP runs the network and devices. Someone still needs to look at the software itself as well. The bespoke platform's developer may be the only person who fully understands it. Leadership sits between them.

The OAIC's Notifiable Data Breaches reports regularly identify compromised credentials, human error and access control failures among breach causes.

The answer is not a two hundred page audit. It is an independent review of hosting, encryption, access, backups, supply chain and incident response, with the answers and next steps written down.

Choose the right starting point

Readiness, usage, DLP or privacy advisory

Whole organisation

AI Readiness Audit

Use this when leadership needs to understand opportunities, operating gaps and the order of work.
Read about AI Readiness Audit
Staff behaviour

AI Usage Review

Use this when the immediate question is which tools and data practices staff report using now.
Read about AI Usage Review
One platformCurrent service

Data and Privacy Advisory

Use this when a nominated CRM or platform needs an independent review of hosting, access, retention and response.

Boundaries

What this engagement is not

Advisory boundary

Certification or legal advice

We do not certify against ISO 27001, SOC 2 or IRAP, and we do not provide legal opinions. We document evidence and flag where privacy counsel is needed.
Separate evidence

A penetration test

We do not run vulnerability scans and will say when technical testing is the right next step.
Separate scope

An implementation project

Actions remain with the MSP, internal team or an agreed third party.
Decision support

Vendor management

We provide questions and evidence gaps rather than negotiating contracts on the client's behalf.

Triggers

When to call us in

Funder question

Asked about data handling

A board or funder expects answers the executive cannot yet provide confidently.
Privacy reform

New obligations on the horizon

A changing privacy obligation requires a current picture of the platform and data flows.
Tender requirement

Evidence required

A grant, tender or contract requires written evidence about a bespoke or third party platform.
Stale platform

No one has looked in years

A line of business system has operated for years without independent review.
MSP scope gap

Application layer is unowned

Infrastructure is managed, but no one is reviewing the application and data layer.
Sensitive sector

Personal and sensitive data

The organisation handles sensitive information in disability, aged care, health, education or not for profit services.

Practical details

Questions about Data & Privacy Advisory

What is assessed, what you receive and where advisory responsibility stops.

No. We are not your MSP and we do not want to be. The MSP runs the network, devices and infrastructure. We sit at the application and data layer, often the bit no one is reviewing right now. The report is written so your MSP can pick up the actions that are theirs to do.

Scoping call

Get an independent view of one platform

We will confirm whether one platform review is enough before writing a scope. Read the data, privacy and AI review case study for how this work runs.Enquiries get a reply within one business day.