Home / Engagement
How the work runs, from first call to handover.
The engagement moves through a sequence of named steps. Each one closes with documents your team keeps and a decision your leadership has signed off. Which steps apply, and how far each goes, depends on your business. We agree all of that in writing before the work starts.
Every step produces documents
Nothing closes on a conversation. Each step ends with written output your team reviews, adopts and keeps.
Scope is agreed before the start
You know which steps apply, what each produces and what we need from your team before any invoice exists.
Decisions stay with you
Where a choice is genuinely open, we write up the options and the risks. Your leadership decides and we record it.
Steps can run in parallel
Drafting often begins while discovery finishes in a quieter corner of the business. The sequence guides the work, it does not block it.
Intake and engagement
Before any assessment work, we establish that we can act for you, write down what we are doing, and name the people on your side who will own each part of it. Engagements that skip this step stall halfway through because nobody is clear who decides.
This is also where we flag anything that would change the shape of the work, such as a group structure, a parent company abroad, or an existing adviser already handling part of the picture.
Discovery and mapping
This is the step that does the real work. We interview the people who actually use each system, not only the people who own them, because the gap between the two is where unrecorded data usually lives. Sales keeps a personal spreadsheet. Support runs a WhatsApp group. Someone built a form in 2022 that still collects responses.
By the end of it you have a written record of every activity in the business that touches personal data, which almost no small or medium business has before starting.
Gap Assessment
Discovery tells us what you do. This step tells you what your current arrangements actually achieve. We take each activity from the map and work out whether the way you collect, use and share that data is genuinely supported by what customers were told and what they agreed to.
Most of the uncomfortable findings surface here. A consent box that covers three unrelated things. A notice that does not mention the vendor who receives the data. A marketing list whose origin nobody can explain. We write down what is actually true, with the reasoning, so the fixes that follow are aimed at something real.
Compliance Support
This is the largest step, and it is where most of the value sits. We write the documents your business needs, built from your own data map rather than from a template.
Not every item below applies to every client. A business with no customers under eighteen does not need the children's package. A business with no app does not need in product consent screens. The scope agreed at the start decides what gets drafted.
Implementation support
Documents on their own change nothing. Someone has to build the consent screen, configure the deletion job, close the old access and update the website. This step turns the drafted material into a list of tasks your developers or vendors can actually pick up.
We stay available while that happens, reviewing each item as it goes live rather than discovering at the end that the consent screen records the wrong thing.
Training, assurance and close out
The last step tests whether any of it holds. We train the people who touch personal data, then run the new processes against realistic situations. A dummy deletion request. A withdrawal of consent. A simulated lost laptop on a Friday evening.
What fails gets fixed or recorded as an open item with a date. You finish with a pack that shows what you assessed, what you decided and what you built, which is the thing that matters if anyone ever asks.
Breach response
Something goes wrong eventually. A laptop is left in a cab, a vendor emails a spreadsheet to the wrong address, or an old server turns out to have been reachable for a month. Most of the damage comes from the hours afterwards, when nobody is certain who decides, what to write down, or whether the clock has already started.
We build the plan before you need it, as part of Compliance Support. It names the people who act in the first hours, sets the order they act in, and fixes what gets recorded at each point. We draft the notification letter templates specific to your business, so nobody is writing them under pressure, and we run one practice exercise with your team against a scenario drawn from your own systems.
Requests from customers and staff
People can ask to see the data you hold about them, have it corrected, have it erased, or withdraw a consent they gave you earlier. Your own staff can ask, and so can a parent on behalf of a child. Every request starts a clock, and a request that sits unread in a shared inbox for three weeks has already failed.
We build the route that receives them. It is drafted during Compliance Support and tested during Implementation support, so that by handover a request arriving at your published address reaches a named owner, gets checked against identity, gets actioned across every system holding a copy, and gets answered inside the timeline.
More than one framework
If you sell to customers in the European Union, hold records on staff based abroad, process data on behalf of a client who answers to another country's rules, or take card payments, a second set of obligations lands on the same systems you already run. Handled separately they produce two registers, two sets of notices and two sets of training that quietly disagree with each other.
We settle which frameworks reach you during Applicability and roles, then build once. One set of controls, one record of what you hold and why, and a mapping that shows how each control answers each framework. Where two frameworks genuinely ask for different things, we write up both positions with the risk attached and your leadership decides which one governs.
Modules that attach to the engagement.
Some businesses need more than the core sequence. These attach to the relevant step rather than running separately, and each is agreed before it starts.
Full impact assessments
A detailed assessment for a high risk activity, covering why it is necessary, what alternatives exist, who could be harmed and what reduces that.
Extended assurance testing
Unannounced test requests submitted as a member of the public, sampling of your consent records, and a test of whether a vendor can actually return your data.
Training your own trainers
A facilitator guide and two sessions with your internal trainers, so you can run induction for new staff without bringing us back each time.
Data sharing programme
Where you share data with partners, sponsors or group companies, a sharing agreement, a due diligence checklist and rules on what may be shared.
Plain language explainers
A short notice and script written for the people whose data you hold, including customers, parents or members, rather than for your lawyers.
Periodic review
A set number of hours each month for escalations, new tools, new activities and a scheduled check that what we built is still being followed.
End to end or modular, your choice. Every step listed above can run as a single engagement or stand alone as a module. The first conversation establishes what you need, and the engagement letter records exactly that.
Find out which of these steps your business needs.
A thirty minute call is enough to tell. You leave knowing the three gaps that matter most, whether or not you engage us.