How the work runs

Privacy programs built to run inside the business

Privacy obligations are usually understood. The work cannot keep pace because it sits with one person carrying it alongside another full-time role. Large firms answer that gap with a template and a policy pack the business then has to operationalize alone — which is precisely the thing they lack capacity to do.

Operational rather than theoretical

Engagements take three forms: fixed-scope project work with a defined end point, ongoing fractional ownership of the privacy function, and hourly or day-rate work for everything that does not need a standing commitment. There is also supervised delivery capacity for high-volume operational work that does not need principal-level time.

The work I do is operational rather than theoretical, so the fit depends on your wanting a program that is built to run. I do not produce document sets that sit unused.

AI GovernanceAI inventory, risk classification, impact assessments, and governance framework build for companies deploying AI against customer or employee data. Fixed-fee project work covering EU AI Act, GDPR automated decision-making, and US state privacy obligations. Data Mapping and RoPAFixed-fee data mapping and Records of Processing Activities (RoPA) for organizations subject to GDPR and UK GDPR, or building a functioning privacy program. Stakeholder interviews, data flow and transfer detail, and a maintenance SOP included. DSAR HandlingEnd-to-end design and operation of data subject access request workflows for organizations subject to GDPR, UK GDPR, and US state privacy laws. Fixed-fee process build in four to eight weeks, with ongoing handling available. Fractional DPOExternal, named DPO appointment on a monthly retainer. Statutory and functional arrangements for organizations operating under GDPR and UK GDPR. Fixed tiers, twelve-month terms, built to run. PIAs and DPIAsStructured privacy and data protection impact assessments for new products, AI deployments, and vendor processing. Risk framework, assessment policy, completed PIAs and DPIAs, and training — fixed fee, four to eight weeks. Privacy TrainingRole-specific privacy training built from the personal data your employees actually handle. SCORM packages, quizzes, and three rounds of edits. Fixed fee, three weeks to one month. Regulatory Horizon ScanningOngoing monitoring of privacy and AI regulation across your jurisdictions, mapped to your business and converted into dated actions with assigned owners. Not a newsletter.

Engagement models

Project — fixed scope, fixed fee
4 to 12 weeks Audits and gap assessments, program design and build, data mapping, PIAs and DPIAs, policy drafting and RCSA, AI governance program development, and training. You know the number before anything starts.
Fractional retainer — Advisory
From $4,500 / month ~2 days (16 hours) a month. Suits a company with a functioning program that needs a named owner and judgment on live questions.
Fractional retainer — Standard DPO
From $9,000 / month ~4 days (32 hours) a month. Fits a mid-sized operator with real cross-border exposure.
Fractional retainer — Embedded
From $18,000 / month ~8 days (64 hours) a month. Built for companies building or remediating at pace. Retainers are written for 12 months with a review at 6; the tier moves up or down at that review.
Hourly / day rate
$275 / hr or $2,000 / day Ad hoc questions, document reviews, standing office hours, and short defined sprints.
Supervised delivery capacity
From $1,500 / month Trained junior privacy staff working under my supervision at 10, 20, or 40 hours a week — for DSAR throughput, records maintenance, and day-to-day program operations that does not need principal-level time.

Indicative fees

Audit or gap assessment
$10,000 – $18,000 Depending on footprint and complexity. Fixed fee; scoped before work begins.
Policy work
Below audit range Fixed fee; varies by scope.
AI governance program build
Scoped to the engagement Fixed fee agreed before work begins.

The right shape is usually obvious once we have scoped the work on a call.

Book a scoping call

The usual path is an audit or gap assessment first as a defined project, then a retainer to run what the assessment recommends.

Write to us

Prefer email? Start here.

A short note about your situation is plenty. Replies come from rasha.hisham@appliedprivacyconsulting.com.