Privacy compliance: what it actually consists of for a company with no privacy team

Privacy compliance is a phrase that covers everything from a one-page notice to a certified programme, and for a company without a privacy team the useful version is short. Five things, in the order that makes each one cheaper than it would be alone.

Know what you hold

Systems, not fields. What personal data is in each, why it is there, who else sees it, how long it stays. This is a morning with a spreadsheet and it makes the other four faster, which is why it is first and why doing it last is the most common expensive mistake.

Publish notices that are true

A privacy policy and, if you set cookies, a cookie table. True matters more than complete: a short accurate policy is a better position than a long one that describes a business you no longer are. Version them so you can say what they said last year.

Have a request route that works

Published, monitored, and walked end to end at least once before a real request arrives. The walk-through is what finds the systems the map missed, which is why it belongs here rather than at the end, and it converts an untested claim on a policy page into a process somebody has actually rehearsed.

Contract your vendors

An agreement with every company that processes personal data on your instructions. This is the item most often sitting at zero, and it is discovered during a customer's security review rather than by anybody internal, which makes it a commercial problem before it is ever a regulatory one.

Keep the record

Requests, decisions and changes, each with a date. Compliance you cannot evidence is a claim, and the record is the only one of these five artefacts whose value increases with age: a two-year-old request log answers questions that nothing else in the business can answer at all.

Questions people ask about privacy compliance

Where do most small companies actually stand?

Notices published, nothing else. The notice is the visible obligation, so it gets done, and the four invisible ones are the ones an enquiry tests.

Do we need a certification?

Almost never for privacy specifically, and a certification is not compliance. Customers asking for one are usually asking for security assurance, which is a different question with a different answer.

What does this cost?

At this size, mostly time: a day for the map, a day for the notices, a day for the vendor list, and then an hour a month. The tooling decision comes after that, and it is much easier once the four artefacts exist.

Sources

Related answers

Keep the request record: $10 a monthStart the request record