Who this is for

The obligation is real. The capacity to run it isn't.

Privacy obligations are usually understood. The work cannot keep pace because it sits with one person carrying it alongside another full-time role. This practice is built for the companies that gap creates.

Where large firms fall short

Large firms answer the capacity gap with a template, limited time understanding the business, and a policy pack the client then has to operationalize alone — which is precisely the thing they lack capacity to do.

What I build instead are privacy programs that actually run inside the business, built by someone who understands how the business works rather than applied from a template. The work is operational rather than theoretical, so the fit depends on your wanting a program that is built to run.

The companies this is built for

Size
More than 100 employees or more than $15 million in revenue At that size the privacy obligation is genuine and the work is steady.
Regulatory exposure
Several US state laws and often GDPR or UK GDPR The regulatory map usually spans multiple jurisdictions at this scale.
Internal situation
Privacy sits with a general counsel, IT lead, or compliance generalist who already has a full-time job A full-time privacy hire is hard to justify; a fractional owner with depth provides better coverage than a junior hire who needs supervision they cannot provide internally.

Three situations that fit

  • No program exists and you know you need one.
  • A program exists but has quietly stopped keeping pace with the business.
  • You want an independent read on whether it holds up before a regulator, a customer, or an acquirer tests it.

Sectors where this work lands

  • Multifamily and proptech
  • Consumer services
  • Healthcare-adjacent businesses
  • Financial services
  • Any company deploying AI against customer or employee data

Where I am not the right resource

  • Technical integration work. I will advise on what a privacy management platform is required to do and how it ought to be configured against your obligations, but I am not the resource implementing it within your environment.
  • Cookie remediation or breach management. Breach response properly sits with outside counsel and a forensics team, where the protection of privilege carries more weight than the convenience of a single provider.
  • Document sets that sit unused. The work is operational rather than theoretical.

Recognize the situation?

Get in touch

The usual path is an audit or gap assessment first as a defined project, then a retainer to run what the assessment recommends.

Write to us

Prefer email? Start here.

A short note about your situation is plenty. Replies come from rasha.hisham@appliedprivacyconsulting.com.