Privacy education, consultancy & implementation, in 50+ jurisdictions.enquiry@vedhacon.com
Guidance and examples adapt to your selection.↑↓ to browse, ↵ to apply
Not sure where to start?Check your readiness in 10 minutes

Eighteen questions, eight domains, a prioritised list of gaps. Nothing leaves your browser.

Begin the assessment
Featured jurisdictionIndia, DPDP Act 2023

Notice, consent, Data Fiduciary duties, SDF obligations and breach intimation, explained.

Open the guide
Where most engagements startA readiness assessment, then a plan

We scope against the laws that actually apply to you, then sequence the work by risk.

Start the assessment
Free, no sign-upCheck your readiness in 10 minutes

Answer 18 questions and get a prioritised control roadmap instantly.

Start the assessment
Free, alwaysZero to practitioner

Track 01 assumes no prior knowledge of governance, risk and compliance.

Start Track 01
Careers & practice · 30–60–90 plan

Your first 90 days as a one-person privacy team

Do not try to complete a privacy programme in one quarter. Learn the business, make the worst day survivable, build repeatable intake routes and agree what will—and will not—be done next.

Vedhacon Privacy Operations practice10 min read

You are the privacy team. There may be no complete inventory, no dedicated budget and no agreed intake route—only contracts, product questions, incidents and requests arriving from different directions. The temptation is to begin by writing policies. Resist it until you understand which processes, people and decisions those policies need to govern.

The first-quarter goal is not completeness. It is a defensible view of risk, a survivable incident process and a repeatable way for work to reach you.

Before day one: define the mandate

Clarify who sponsors the role, what authority it has, whether it is acting as a statutory or formal DPO, which entities and jurisdictions are in scope, and what independence or reporting arrangements apply. Do not accept personal accountability for controls owned by the business, security, HR, product or procurement.

Agree three things with the sponsor
  • Which decisions you advise on, approve, escalate or only monitor.
  • How material risks and overdue actions reach leadership.
  • What capacity, budget and specialist support are available for incidents or high-risk matters.

Days 1–30: listen, map and triage

Meet the leaders and operators who touch personal data. Ask each what the function does, which systems and vendors it relies on, where data comes from and goes, what causes complaints, which deadlines worry them and what changes are planned.

Days 1–30: establish the baseline
WorkstreamActionOutput by day 30
Mandate and governanceConfirm scope, sponsor, reporting line, decision rights and escalation.One-page charter and sponsor cadence
StakeholdersMeet security, legal, HR, product, marketing, procurement, IT, audit and customer operations.Stakeholder map with owners and concerns
ApplicabilityMap entities, people, locations, sectors and services to likely regimes.Applicability register with assumptions
ProcessingBuild a minimum RoPA from real process walkthroughs and existing evidence.Initial activity inventory with known gaps
Existing controlsCollect notices, contracts, request logs, incidents, training and assessments.Control and document inventory
RiskCapture urgent exposures, deadlines and upcoming change.Prioritised privacy risk register

Use evidence, not interviews alone

Compare conversations with vendor spend, SSO applications, cloud inventories, website tags, contracts, incident records and rights-request history. Mark uncertainty openly. An incomplete record labelled as incomplete is more useful than a polished register built on guesses.

Triage by consequence and urgency

A simple prioritisation model
PriorityTypical triggerResponse
ImmediateLive incident, regulator deadline, rights request nearing expiry, unlawful collection or active high-risk launch.Escalate, assign owner, record decision and work to the deadline.
HighSensitive or large-scale processing, children, monitoring, weak vendor terms, missing transfer route or no incident capability.Assess within the quarter and agree treatment dates.
MediumControl exists but is inconsistent, manual or weakly evidenced.Standardise through the operating plan.
FoundationalPolicy refresh, taxonomy cleanup or optimisation with no immediate exposure.Schedule after urgent and high-risk gaps.

Record why an item received its priority, who owns the underlying process and what would change the rating. Privacy should coordinate and challenge; the business owner should own the treatment.

Days 31–60: make the worst day survivable

Prioritise minimum viable controls for events that become complaints, losses or missed deadlines quickly. Three commonly deserve early attention: incidents, individual rights and high-risk vendors or changes.

Days 31–60: minimum viable controls
ControlMinimum viable stateEvidence
Incident responseNamed team and deputies, clocks matrix, decision log and notification templates.Approved playbook and tabletop action log
Rights requestsOne intake route, identity checks, tracker, search owners, response templates and escalation.Case register and tested workflow
Vendor intakeRisk questions, processing roles, data, countries, security, sub-processors and contract route.Completed assessments for highest-risk vendors
High-risk changeDPIA screening embedded in product, procurement and architecture intake.Screening decisions and linked assessments
Transparency and consentCurrent notices mapped to processing; optional consent controls tested.Versioned notice and interface evidence
RetentionPriority rules mapped to systems, owners, holds and deletion mechanisms.Rule specifications and first execution sample

Run a realistic exercise

Do not declare a process operational because a document exists. Run one incident tabletop and one rights-request simulation using the people, systems and clock that would apply. Record failures and assign fixes.

Days 61–90: build the operating rhythm

Move from individual heroics to predictable routes and recurring decisions. Privacy questions should enter through procurement, change, incident and request processes rather than depending on colleagues remembering to contact you.

Days 61–90: establish governance
CadencePurposeParticipants or output
Weekly intake reviewTriage new requests, changes, vendors, incidents and deadlines.Privacy, legal, security and relevant owners
Monthly risk reviewReview high risks, overdue actions, exceptions and decisions required.Sponsor and accountable business owners
Monthly champions callShare changes, surface issues and reinforce local ownership.Named privacy contacts in major functions
Quarterly programme reviewAssess metrics, capacity, roadmap and material changes.Leadership report and approved priorities
Annual planSequence assessments, training, assurance and control improvements.Funded roadmap with explicit exclusions

What good looks like at day 90

  • A written mandate, sponsor cadence and escalation route.
  • An applicability map and minimum RoPA with owners and known gaps.
  • A risk register separating urgent, high, medium and foundational work.
  • Incident and rights-request workflows tested at least once.
  • A risk-based vendor and change intake process.
  • A small set of agreed metrics and an executive report.
  • A 12-month roadmap showing priorities, dependencies, capacity and deferred work.
  • A decision log recording advice, approvals, exceptions and risk acceptance.

Measure control, not activity volume

Useful early programme measures
MeasureWhat it reveals
Requests by type, age and deadline statusDemand, bottlenecks and missed-service risk
High risks without owner or due dateGovernance and accountability gaps
New vendors or changes screened before approvalWhether privacy is embedded upstream
Overdue DPIA, contract and remediation actionsWhere advice is not converting into control
Processing activities with owner and review dateInventory quality and accountability
Exercise findings closed on timeWhether testing produces improvement

Avoid celebrating the number of policies written, assessments opened or training invitations sent. Measure whether high-risk work is identified early, owned, completed and evidenced.

Protect capacity and independence

A team of one cannot attend every meeting or personally operate every control. Publish intake criteria, standard response times and escalation rules. Use templates for repeatable advice, office hours for lower-risk questions and external support for incidents, complex transfers, investigations or specialist assessments.

Workload safeguards
  • Keep one visible backlog with priority, owner and deadline.
  • Separate advisory responsibility from business control ownership.
  • Record decisions so settled questions are not repeatedly reopened.
  • Escalate when capacity creates a material compliance risk.
  • Build a peer network and identify trusted specialist support before an emergency.
  • Schedule focused work and recovery time after incidents or intense deadlines.

Common first-quarter mistakes

  • Writing a complete policy suite before understanding the business.
  • Accepting ownership for security, HR, product or vendor controls.
  • Building a perfect RoPA from interviews without reconciling systems and spend.
  • Trying to fix every gap rather than documenting prioritisation.
  • Reporting activity counts without explaining risk or decisions required.
  • Allowing urgent work to erase the roadmap every week.
  • Waiting for a real incident to test escalation and notification.

References and scope

  • Regulation (EU) 2016/679 (GDPR), including Articles 30, 33 and 37–39 where applicable.
  • Digital Personal Data Protection Act, 2023 (India), including duties, rights and Significant Data Fiduciary requirements where applicable.

General information for practitioners, not legal advice or a universal role description. Responsibilities depend on applicable law, formal appointment, organisational structure, sector and risk. Confirm the mandate and obtain qualified advice where required.