Services

1. External Data Protection Officer Services

Receive ongoing privacy guidance from an experienced external professional without needing to create a full-time internal position.

Pricing:

  • Small organisations: $50,000 – $100,000/month
  • Medium organisations: $100,000 – $200,000/month

What it includes:

  • Privacy Compliance Oversight – Monitor and support your organisation’s privacy programme.
  • Privacy Advice & Guidance – Advise management and staff on data protection obligations and best practices.
  • Policy & Procedure Review – Review and recommend updates to privacy-related policies, procedures, and documentation.
  • Privacy Risk & Impact Assessments – Assist with identifying and assessing privacy risks associated with new processes, systems, or projects.
  • Data Subject Rights Support – Guide on handling requests for access, correction, deletion, and other rights under the JDPA.
  • Incident & Breach Guidance – Advise on responding to privacy incidents and personal data breaches.
  • Staff Awareness & Training – Promote privacy awareness through guidance and training sessions.
  • Regulatory Support – Serve as a point of contact for privacy-related matters involving the Office of the Information Commissioner (OIC), where appropriate.
  • Ongoing Reporting – Provide periodic reports and recommendations to management on the organisation’s privacy posture.

Deliverables:

  • Privacy compliance reports
  • Risk assessment reports
  • Privacy policies and procedures
  • Privacy registers and records
  • Privacy guidance and recommendations
  • Staff awareness materials
  • Data breach response guidance
  • Meeting notes and management reports
  • Annual privacy programme reviews

2. Implementation Gap Review (detailed diagnostic)

I find out exactly where you stand before enforcement becomes a problem.

Pricing:

  • Small organisations: $25,000 – $45,000
  • Medium organisations: $45,000 – $100,000

What it includes:

  • Data mapping (what customer data you collect and where it flows)
  • Gap analysis vs JDPA requirements
  • Risk identification (high, medium, low)
  • Plain-English report + action plan
  • Review of:
    • Policies vs actual practice
    • Staff behavior
    • Data handling flows
  • Written report:
    • Gaps
    • Risk level
    • Prioritized fixes

Deliverables:

  • Where your DPO says you should be
  • Where you actually are
  • What’s not being followed
  • What’s creating risk operationally

3. Implementation Execution (core service)

I help take your organisation from non-compliant to structured and defensible.

Pricing:

  • Small organisations: $85,000 – $150,000
  • Medium organisations: $150,000 – $300,000

What I do:

  • Take existing DPO documents
  • Turn them into:
    • Real workflows
    • Staff habits
    • Enforced procedures

Examples:

  • Turn a privacy policy into front-desk scripts
  • Turn a retention policy into actual file handling rules
  • Turn “access control” into:
    • Who can open what
    • When
    • How it’s logged

What it includes:

  • Privacy policy (customer-facing)
  • Internal data protection policy
  • Staff confidentiality agreements
  • Data retention schedule
  • Breach response procedure
  • Consent forms aligned with JDPA
  • Basic staff training session
  • Staff interviews
  • Workflow observation
  • Sample testing (e.g., how records are handled)

Deliverables

  • Detailed operational breakdown
  • Step-by-step remediation roadmap

4. Ongoing Support (retainer)

I help your organisation stay compliant so you can focus on growing your business.

Retainer Pricing:

  • Small organisations: $35,000 – $75,000/month
  • Medium organisations: $75,000 – $180,000/month

What I do:

  • Keep things working
  • Handle issues as they arise

What it includes:

  • Monthly/quarterly check-ins
  • Policy updates
  • Incident handling support
  • Staff refresher training
  • Liaison with your DPO
  • Light audit updates

Optional Add-Ons

  • Breach simulation exercise
  • Staff privacy-sensitisation training
  • Business workflow redesign (privacy-first processes)
  • Vendor/data processor compliance review
  • Website creation and management