Skip to content

Data & Privacy Advisory · Independent

Data & privacy advisory, independent

Data and privacy advisory is an independent review for Australian organisations with a bespoke platform or CRM where no one has recently asked the hard questions about hosting, access, backups or breach response. The OAIC's Notifiable Data Breaches reports regularly identify compromised credentials, human error and access control failures among breach causes. We sit with the platform developer, document the answers and produce a risk rated plan leadership can hand to its MSP.

The gap

You grew into your systems, now no one knows how it works

A custom CRM was built years ago. The MSP runs the network and devices. Someone still needs to look at the software itself, not just the network. The bespoke platform's developer may be the only person who fully understands it. Leadership sits between them.

The answer is not a two hundred page audit. It is an independent person asking the right questions about hosting, encryption, access, backups, supply chain and incident response, then recording the answers and what to do next.

Scope

The four areas we cover

Platform review

This covers where the platform is hosted, whether your data stays in Australia, and how it is encrypted and secured. It also covers how well the platform recovers from a failure, what records exist for an audit, which certifications it holds, and who else in the supply chain can reach your data.

Data lifecycle and retention

The personal and sensitive data held, how long each type remains, how it is destroyed or archived and where copies exist.

Access and permissions

Roles, joiner mover leaver processes, privileged access, developer access and the cadence of access reviews.

Method

How the engagement runs

One nominated platform is reviewed per engagement. Multiple platforms are sequenced during scoping.
  1. Kick-off

    Confirm scope and platform

    The sponsor confirms the platform, priorities, stakeholders and timing.
  2. Discovery

    Working sessions with the developer

    We interview the platform owner and review available policies, sub-processor lists and assurance reports.
  3. Draft

    Draft advisory report

    Findings are rated low, medium or high and paired with practical recommendations and suggested owners.
  4. Walkthrough

    Final report and plan

    Leadership reviews the findings and receives an action ready report for the MSP or another delivery partner.

Deliverable status

What you walk away with

A fixed price quote is agreed before work starts.
Advisory, not certification

Written advisory report

Plain language findings based on the evidence available during the engagement.
  • Findings by area
  • Low, medium or high risk ratings
  • Recommendations
  • Suggested owners
Evidence map

Supply chain map

A documented view of the services behind the platform and the status of each assessment.
  • Sub-processors
  • Where each sits
  • Assessment status
  • Concentration risk
Decision session

Leadership walkthrough

A session to agree priorities and route actions to the right delivery partner.
  • Leadership walkthrough
  • Stakeholder questions
  • Priority agreement
  • Action ready output

Boundaries

What this engagement is not

No certification

A formal compliance audit

We do not certify against ISO 27001, SOC 2 or IRAP; we document evidence and gaps.
Separate evidence

A penetration test

We do not run vulnerability scans and will say when technical testing is the right next step.
Separate scope

An implementation project

Actions remain with the MSP, internal team or an agreed third party.
Not legal advice

Legal advice

We identify when a privacy lawyer should review a finding or obligation.
Decision support

Vendor management

We provide questions and evidence gaps rather than negotiating contracts on the client's behalf.

Triggers

When to call us in

Funder question

Asked about data handling

A board or funder expects answers the executive cannot yet provide confidently.
Privacy reform

New obligations on the horizon

A changing privacy obligation requires a current picture of the platform and data flows.
Tender requirement

Evidence required

A grant, tender or contract requires written evidence about a bespoke or third party platform.
Stale platform

No one has looked in years

A line of business system has operated for years without independent review.
MSP scope gap

Application layer is unowned

Infrastructure is managed, but no one is reviewing the application and data layer.
Sensitive sector

Personal and sensitive data

The organisation handles sensitive information in disability, aged care, health, education or not for profit services.

Recent work

Independent review of a platform holding sensitive client data

Working sessions and vendor evidence produced a thirty one page report and a prioritised action list for leadership.

Practical details

Questions about Data & Privacy Advisory

What is assessed, what you receive and where advisory responsibility stops.

Scoping call

Need answers about a platform you can't fully see? Start with a 30 minute scoping call

We will tell you whether this engagement is the right fit. No pitch deck.