Data Privacy

Manage privacy risk under GDPR, CCPA/CPRA, and U.S. state laws on the same foundation as your security program.

GDPR · CCPA/CPRA · U.S. state privacy laws

Manage privacy risk inside your security program — not beside it.

Privacy laws ask the same questions your security framework does: what data you hold, where it goes, who can touch it, and how you’d know if something went wrong. We answer them once, and map the answer to every regulation you’re subject to.

Where we help

  • Data mapping and records of processing
  • Privacy notices, consent, and cookie practices
  • Data subject and consumer rights-request workflow
  • DPIAs and CCPA risk assessments
  • Vendor DPAs and cross-border transfer safeguards
  • Privacy incident and breach response

Regulations we work with

One privacy program, mapped to every law you answer to.

GDPR

EU & UK GDPR

Applies when you offer goods or services to people in the EU or UK, or monitor their behavior — wherever your company is based.

  • Records of Processing Activities (Article 30)
  • Lawful basis, transparency, and consent
  • Data Protection Impact Assessments (Article 35)
  • Processor agreements (Article 28) and transfer safeguards
  • 72-hour breach notification readiness (Article 33)

CCPA / CPRA

California Consumer Privacy Act

The most demanding U.S. privacy law — and its newest regulations reach directly into your security program.

  • Rights to know, delete, correct, and opt out of sale or sharing
  • Risk assessments for covered processing, required from January 1, 2026
  • Automated decision-making technology (ADMT) rules from January 1, 2027
  • Independent cybersecurity audits — first certifications due April 1, 2028, 2029, or 2030 depending on revenue
  • Service-provider and contractor terms

U.S. states

State privacy laws

Virginia, Colorado, Connecticut, Texas, Oregon, and a growing list of others — similar in spirit, different in the details.

  • Applicability analysis by state and threshold
  • One harmonized baseline instead of fifty checklists
  • Universal opt-out and browser privacy signals
  • Sensitive data and children’s data requirements
  • Annual review as new laws take effect

Where privacy and security meet

Implement once, satisfy both.

Most privacy obligations have a security twin. We build the control one time and document how it meets each law.

ObligationGDPRCCPA / CPRAHow we implement it once
Know your dataRecords of processing (Art. 30)Notice at collection; data inventory for rights requestsA single data map tied to your asset inventory
Assess riskDPIAs for high-risk processing (Art. 35)Risk assessments under CPPA regulationsOne assessment method feeding your security risk register
Secure the dataSecurity of processing (Art. 32)Reasonable security; annual cybersecurity auditsThe same controls you use for SOC 2, ISO 27001, or HITRUST
Manage vendorsProcessor contracts (Art. 28)Service-provider and contractor termsVendor risk tiering with privacy terms built in
Honor rightsAccess, erasure, portability — one month to respondKnow, delete, correct, opt out — 45 days to respondOne intake and tracking workflow for every request
Respond to incidentsNotify the regulator within 72 hours when requiredCalifornia breach-notification law and statutory damages exposureOne incident response plan with privacy decision points

The privacy track of the Anchor Path

From data map to managed privacy risk.

Discover

Map

Inventory personal data, systems, vendors, and flows; confirm which laws apply.

Assess

Measure

DPIAs and CCPA risk assessments; privacy risks added to your Risk Ledger.

Treat

Build

Notices, consent, rights-request workflow, vendor terms, retention rules.

Monitor

Watch

Ongoing privacy risk indicators and tracking new laws as they land.

Assure

Prove

Evidence packages, cybersecurity audit readiness, and regulator-ready records.

We’re security and compliance practitioners, not a law firm. We work alongside your legal counsel, who remains responsible for legal interpretation and advice.

Collecting more personal data than you can account for?

Tell us which laws you’re worried about. We’ll show you where you stand and what it will take.