Home ยป Enterprise & Corporate

Enterprise & Corporate

You already have a privacy function. What you’re missing is capacity on a specific programme, an independent view your board will accept, or someone who has seen how this plays out in other organisations at your scale. That’s the work PrivacyIQ does.

Alongside your team, not instead of it

Engagements here are scoped to sit beside an in-house function rather than replace it. The people who know your business are your own; what we add is depth on a defined problem and the ability to say something your team may not be positioned to say internally.

The advice is shaped by three things:

  • Over a decade of privacy-specific work. Not a general risk or legal practice with a privacy line. This is the whole discipline.
  • Experience spanning industries, from healthcare AI to financial services and public sector innovation, which means pattern recognition across sectors rather than one sector’s habits.
  • A close-up view of how regulation actually comes about, which changes what you prioritise and how much weight you give to a given piece of guidance.

Where we’re brought in

Programme and transformation support

Sustained work on large or multi-stage change: a migration, an acquisition, a new product line, a governance framework being rebuilt. Privacy input that arrives before decisions are locked rather than after.

Audit and gap analysis

Independent assessment where an internal view isn’t enough, or won’t be treated as enough. Findings are written to be actionable and to survive being read by a regulator.

Regulatory readiness

Preparation for something specific and dated: a new regime coming into force, a supervisory engagement, an audit, a certification. Scoped backwards from the date.

Training and capability building

Raising the level of an existing team, or reaching the parts of the organisation where the policy and the practice have drifted apart. Built around your actual processes, not generic modules.

The gap between the policy and the practice

At this scale, the framework usually exists. The risk sits in the distance between what it says and what people do on a Tuesday afternoon under deadline pressure. Governance that only lives in documents is documentation, not governance.

Most of the substantial findings in our work are not missing policies. They are working practices that grew up around the policy, in teams doing their best with tools nobody assessed.

How engagements are structured

Scoped against a defined outcome and a date, with a written statement of what’s covered, who’s involved from your side, and what you’ll have at the end. Day rates and fixed-scope pieces both work; which one suits depends on whether the endpoint is known at the start.