Auditing & Consulting
Privacy Laws & Business has been advising clients on their data protection policies and procedures since its first year in business, in 1987.
Many of these clients are Financial Times UK Top 50 and Fortune USA Top 50 companies, as well as many public sector organisations.
Consulting
Clients typically want to know what the law says; what the law means for them; what they should do to implement an effective data protection compliance system; and how to build privacy into their corporate or marketing strategies.
In many cases, there is a specific issue which leads to the consultancy project. The Privacy Laws & Business team will address that issue but also explain to the client the other privacy areas which demand attention.
One of the essential themes of Privacy Laws & Business’s approach is the consultants’ ability to think laterally about the issues which the clients present to them. The solution may lie in the application of both legal analysis and advice and more appropriate management techniques.
Auditing
Privacy Laws & Business’s work on auditing began with a series of workshops in 1997 on how to apply ISO 9000 quality assurance principles to auditing for data protection law compliance. This experience led to the company winning the contract to prepare the Data Protection Auditing Manual for the UK’s Information Commissioner.
The Data Protection Auditing Manual, published in July 2001, develops auditing procedures aimed at assessing organisations’ compliance with the UK Data Protection Act 1998. The aim of the project was to prepare an Audit Manual which will be used by the Commissioner when carrying out his audit functions, and also by organisations wishing to check their own data protection compliance.
This contract has direct relevance to many consulting projects, as techniques developed and lessons learned are applied to a client’s business. Although the questionnaires and audit checklists are based on the UK law, the methodology will work successfully with any country’s law and clients’ processing of personal data within this legal framework.