Privacy education, consultancy & implementation, in 50+ jurisdictions.enquiry@vedhacon.com
Guidance and examples adapt to your selection.↑↓ to browse, ↵ to apply
Featured jurisdictionIndia, DPDP Act 2023

Notice, consent, Data Fiduciary duties, SDF obligations and breach intimation, explained.

Open the guide
Where most engagements startA readiness assessment, then a plan

We scope against the laws that actually apply to you, then sequence the work by risk.

Start the assessment
Featured whitepaperThe DPDP implementation clock

What must be operational before the substantive obligations commence in 2027.

Read the briefing
Free, no sign-upCheck your readiness in 10 minutes

Answer 18 questions and get a prioritised control roadmap instantly.

Start the assessment
Free, alwaysZero to practitioner

Track 01 assumes no prior knowledge of governance, risk and compliance.

Start Track 01
Seven disciplines, one accountable team

Privacy services, from first principle to audit evidence

Vedhacon works at the point where privacy law meets the systems that process personal data. Every engagement begins with what applies to the organisation, and ends with evidence that a regulator, an auditor or a customer can verify.

01

Privacy education & training

Compliance fails most often because the people who make daily decisions were never told what the law expects of them. Training is written for the audience in the room, the board hears risk and accountability, engineers hear design decisions, and recruiters hear what they may and may not collect.

Built forBoards and executive teams, engineering and product, HR and recruitment, procurement, marketing, legal, and customer support.
Attendance records, assessment scores and refresher schedules, retained as training evidence.
Role-based curricula

Separate tracks per function, so nobody sits through material that does not apply to their work.

Board & leadership briefings

Ninety minutes on exposure, personal liability, and the decisions only leadership can make.

Privacy by design for engineers

Minimisation, retention, logging, pseudonymisation and consent, expressed as build requirements.

Certification preparation

Structured preparation for recognised privacy and information security qualifications.

02

Consultancy & DPO as a service

The first question is never "how do we comply", it is "which laws actually reach us, and for which processing". Applicability is established first, then the gap is measured against it, then the work is sequenced by risk rather than by whichever obligation is easiest to close. We scope in writing and deliver in phases, so you always know what is being done and what it will cost.

Built forOrganisations entering a new market, responding to customer due diligence, or operating without a dedicated privacy function.
A prioritised roadmap with owners, effort estimates and target dates, not a list of findings.
Applicability analysis

Which regimes apply, to which entities, for which processing activities, and on what basis.

Gap assessment

Current state against obligations, scored by risk and effort, with a defensible rationale.

DPO as a service

A named contact for regulators and data principals, with independence preserved by contract.

Customer due diligence support

Responses to security and privacy questionnaires that hold up to follow-up questions.

03

Implementation & engineering

A policy that no system enforces is not a control. This is the work of turning obligations into configuration, records, and repeatable process, carried out alongside the teams who will own it once the engagement ends.

Built forTeams that have completed an assessment and now need the controls to exist in the products, platforms and processes themselves.
Working controls with a maintained record of processing, retention schedules and transfer documentation.
Data discovery & mapping

What is held, where it sits, why it was collected, who it reaches, and when it is deleted.

Notices & consent

Layered notices, granular consent capture, withdrawal that propagates, and an auditable log.

DPIA, RoPA & retention

Assessments that are actually completed, records that stay current, and enforced deletion.

Transfers & vendors

Mechanism selection, transfer impact assessments, and processor obligations that flow down.

Rights request handling

Intake, identity verification, fulfilment and response, inside statutory timelines.

Governance structure

Roles, escalation paths, committee cadence, and the decisions each forum owns.

04

Certification readiness

Certification is won or lost at scoping. Define the boundary carefully, build a management system the organisation can genuinely sustain, and the assessment becomes a confirmation rather than an examination.

Standards supportedISO/IEC 27001 information security, ISO/IEC 27701 privacy information management, and ISO/IEC 42001 AI management systems.
A complete evidence set, closed internal audit findings, and support through Stage 1 and Stage 2.
Scoping & applicability

A defensible boundary and a Statement of Applicability with reasoned inclusions and exclusions.

Documentation set

Policies, procedures and records proportionate to the organisation, not a generic template pack.

Risk & treatment

Methodology, assessment, treatment plan, and residual risk accepted at the right level.

Assessment support

Management review, internal audit, and attendance alongside you through the certification audit.

05

Audit & assurance

An audit is useful only when it tests whether a control operated, not whether a document exists. Sampling is evidence-led, findings are written so the reader can reproduce them, and every observation carries a corrective action with an owner and a date.

Built forOrganisations with an established programme that must now demonstrate it works, to a customer, a certification body, or their own board.
An audit report, evidence pack and corrective action plan, tracked through to closure.
Internal audit

Programme audits against the standard, the law, or your own control set.

Third-party audit

Assessment of processors and sub-processors, including on-site and remote review.

Evidence packs

Artefacts organised by control, so the next reviewer does not start from nothing.

Remediation tracking

Findings followed through to verified closure, with re-testing where it matters.

06

AI governance

Most organisations moved from AI experiments to AI in production without the control model catching up. The work here is inventory first, then lawful basis and data provenance, then the assessments and human oversight the newer regimes now expect.

Frameworks referencedISO/IEC 42001, the EU AI Act, and the privacy obligations that continue to apply to training data and model outputs.
A model inventory, risk classification, and documented oversight for every system in production.
Model inventory

Every model and AI-enabled feature, including those procured inside third-party tools.

Risk classification

Tiering against the EU AI Act and internal thresholds, with the obligations each tier attracts.

Data provenance

Where training and prompt data came from, and whether that use was lawful and disclosed.

Oversight & monitoring

Human review points, drift and performance monitoring, and a route to challenge a decision.

07

Breach & incident response

Notification windows are short and they begin at awareness, not at certainty. The decisions that matter, who assesses, who notifies, and what the threshold is, have to be settled before an incident, because they cannot be settled during one.

Built forOrganisations that hold personal data at scale, operate across multiple regimes, or have never tested their response plan under time pressure.
A tested playbook, a maintained breach register, and notification templates per jurisdiction.
Response playbooks

Roles, decision thresholds, and the clock that starts at each stage of an incident.

Tabletop exercises

Scenario drills that test the plan against real timelines, with findings written up afterwards.

Notification support

Regulator and data principal notification drafted against the requirements of each regime.

Post-incident review

Root cause, control failure analysis, and changes carried back into the programme.

How we engage

Six steps, and you own the outcome at each one

Start a conversation
01

Scoping call

Forty-five minutes on what you process, where you operate, and what is driving the deadline.

02

Assessment

Applicability and gap analysis, producing a risk-ranked view of what is actually outstanding.

03

Implement

Controls implemented with your teams, so capability stays in the organisation afterwards.

04

Prove

Audit, evidence packs, and certification support, so the programme withstands scrutiny.

05

Sustain

Training, regulatory monitoring and periodic reassessment, so the programme does not drift.

06

Handover

Documentation your own team can maintain. No dependency by design, that is the point.

50+Jurisdictions
3ISO standards
Legal + TechDual-discipline
End-to-endScope to certificate
Start a conversation

Tell us where you are, and where you need to be

Share a little context and the right specialist, legal, technical, or certification, will come back to you. There is no obligation and no sales script.

Contact Vedhacon Check your readiness