Data processing policy, privacy notice and consent wording
A data processing policy is only useful when it describes what the company actually does with the information, not what a downloaded template says. So the work starts by walking through the operation —what is collected, where it ends up, who looks at it and who it is shared with— and ends with the policy, the privacy notice and the consent wording drafted on that reality and placed at every point where data enters the business.
The diagnosis comes before the document
A policy copied from another company describes an operation that is not yours, and that is exactly what gets examined when a complaint arrives: whether what the company says it does matches what it actually does. So the work starts by walking through the real operation: what data is collected at each point of contact, under what authorisation it came in, which system it sits in, who inside the company looks at it, which third parties receive it and how long it is kept.
That walk-through almost always surfaces the same findings: inherited databases whose origin nobody knows, forms asking for more information than the business needs, tools contracted by one department without legal review, sensitive data collected without flagging it, and CVs kept indefinitely. We deliver the findings ranked by exposure and by effort, so the company can decide what to fix first.
Three documents that are not the same thing
- Data processing policy. Where the company states what data it handles, for what purposes, who is accountable for it, what rights the data subject has and through which channel those rights are exercised.
- Privacy notice. The short version shown at the moment of collection, where putting the full policy in front of the person is not workable.
- Authorisation. The proof that the data subject agreed. Both its wording and the way it is recorded matter, because proving it falls on the company and not on the individual.
All three are drafted around the real purposes of the business. A purpose that was never announced cannot be relied on later, and a purpose written so broadly that it covers anything ends up reading as though it were not there at all.
Taking it down to the points of contact
The most common problem is not the policy itself but the distance between the document and the operation. That is why the engagement includes carrying the content to the places where collection actually happens.
- Checkboxes and wording on website forms, e-commerce checkout and marketing campaigns.
- The clause in the employment contract and in the recruitment process, including the CVs of candidates who were not hired.
- Commercial email, prospect lists and automated messaging, with a visible route to stop receiving them.
- Notices in areas under camera surveillance, plus a written rule on who views the footage and how long it is kept.
- Call centre scripts and instant messaging channels.
- Paper forms at the point of sale, the gate and the front desk, usually the last ones to be updated.
Sensitive data, children's data and biometrics
When health data, fingerprints or facial images, union membership, religious or political beliefs, or data of children and adolescents come into play, the standard rises. The person must be told they are not obliged to provide them, the business need has to be justified, and that processing has to be kept separate from the rest. Those cases are drafted separately: the general consent wording does not solve them, and burying them inside a long list of purposes is not an answer.
What the client receives
- The processing map: data, purposes, systems, third parties and retention periods, in a format the responsible team can maintain without outside help.
- The processing policy and the privacy notice, drafted on the real operation and ready to publish.
- Consent wording for each collection point, with instructions on how acceptance must be recorded and what is kept as proof.
- Personal data clauses for employment, commercial and service contracts.
- A prioritised list of corrections for what the diagnosis found that no document alone can fix.
Typical situations we handle
- A company about to launch an online store or an app that needs the wording in place before going live.
- A business that never formalised anything and wants to catch up before the first complaint arrives.
- An HR team handling employee, candidate and dependant data without clear authorisations.
- A company that opened a new channel, changed its operation or acquired a database and needs to check whether its policy is still accurate.
Let's solve your legal matter
Every case starts with an honest conversation. Book 30 minutes, no commitment.
Request a diagnostic →