Common questions

What you probably want to know before a call

Straightforward answers about how engagements work, what is included, and where the boundaries sit. If your question is not here, the scope pages go deeper.

The questions that come up most

These are the things people ask before we scope the work — about engagement shape, pricing, fit, and what falls outside the scope of what I do. Where a question belongs to a specific service, the service page goes further.

Questions and answers

What does the typical engagement path look like?

The usual path is an audit or gap assessment first as a defined project, then a retainer to run what the assessment recommends. The assessment produces a plan prioritized by risk rather than by ease — the exposures that could actually cost you something come first, and the housekeeping follows. From there, execution runs with regular touchpoints so you can see progress and reprioritise as the business shifts.

How is pricing structured?

Pricing follows the shape of the work. Defined pieces of work are fixed fee — you know the number before anything starts. An audit or gap assessment typically lands between ten and eighteen thousand depending on footprint and complexity. Ongoing ownership runs from around four and a half thousand a month for roughly two days up to eighteen for an embedded arrangement at around eight days. Work that does not need a standing commitment is billed at two hundred and seventy five an hour or two thousand a day for defined sprints.

Who is this work a good fit for?

The fit is strongest for customer-facing companies with more than 100 employees or more than fifteen million in revenue — businesses that hold real volumes of personal information or operate where that information is specifically regulated. Multifamily and proptech, consumer services, healthcare-adjacent businesses, financial services, and anyone deploying AI against customer or employee data all fit. They tend to sit in one of three situations: no program and a recognized need for one, a program that has quietly stopped keeping pace with the business, or a need for an independent read before a regulator, a customer, or an acquirer tests it.

What work falls outside the scope of what you do?

I do not undertake technical integration work. I will advise on what a privacy management platform is required to do and how it ought to be configured against your obligations, but I am not the resource implementing it within your environment. Cookie remediation and breach management are also out of scope — breach response properly sits with outside counsel and a forensics team, where the protection of privilege carries more weight than the convenience of a single provider. I also do not produce document sets that sit unused; the work is operational rather than theoretical.

What happens in the first thirty days?

The first thirty days are about understanding the business before changing anything in it. I start by learning what you actually need and how the business runs, because privacy obligations sit on top of commercial reality rather than beside it. From there I map how personal data moves through the organization — what you collect, where it comes from, where it sits, who touches it, who you share it with, and which regulatory regimes attach to it. That picture is what everything else depends on, and in most companies it has never been written down in one place.

What are the most common mistakes when a DSAR arrives for the first time?

The week-one mistakes are consistent: not recognising the request because it arrived by email to a support inbox or a member of staff; searching only the obvious systems and missing backups, archives, and anything held by processors; disclosing third-party personal data without redaction; and letting the deadline run while the business decides who owns it. The clock starts when the request is received, not when it reaches the right person — so the right response is to acknowledge, log, and start the search immediately, even if the position on scope is unresolved.

What should we push back on in a data processing agreement?

Standard controller-favorable positions on most DPA terms are safe to accept. What warrants a push is anything you cannot actually deliver — most commonly a breach notification window shorter than your internal detection capability, unrestricted on-site audit rights, blanket sub-processor veto, and liability that sits uncapped or outside the main agreement. The test is not whether a clause is unusual; it is whether you can operationally comply with it. A proper review takes two to five business days.

What typically triggers a fractional DPO engagement?

Typically one of three situations. The company has a statutory DPO requirement and no one appointed. Privacy responsibility has been sitting informally with a general counsel, IT lead, or compliance generalist who has a full-time job of their own and cannot carry it any further. Or a customer, investor, or acquirer has asked who owns privacy and the answer has proved uncomfortable. Audit findings and regulatory correspondence are also common triggers.

Why does the fractional model work better than a junior hire at this stage?

At the size where the privacy obligation is genuine but steady, a full-time privacy hire is hard to justify. Those companies get better coverage from a fractional owner with depth than from a junior hire who needs supervision they cannot provide internally. The underlying obligations are also continuous rather than one-time, so fractional DPO relationships are built to run rather than to end.

Is the fractional DPO service the right fit if we need a full program built from scratch?

A full program build is scoped separately as a project rather than carried within the retainer. The fractional DPO service covers program development and maintenance, policy and SOP ownership, regulatory tracking, oversight of assessments and data mapping, vendor and contract review, and training delivery — but where the starting point is no program at all, the practical path is usually a scoped build first, then a retainer to run what is built.

Ready to scope the work?

Get in touch

The right engagement shape is usually obvious once we have talked through what the business actually needs.

Write to us

Prefer email? Start here.

A short note about your situation is plenty. Replies come from rasha.hisham@appliedprivacyconsulting.com.