GDPR · CCPA/CPRA · U.S. state privacy laws
Manage privacy risk inside your security program — not beside it.
Privacy laws ask the same questions your security framework does: what data you hold, where it goes, who can touch it, and how you’d know if something went wrong. We answer them once, and map the answer to every regulation you’re subject to.
Where we help
- Data mapping and records of processing
- Privacy notices, consent, and cookie practices
- Data subject and consumer rights-request workflow
- DPIAs and CCPA risk assessments
- Vendor DPAs and cross-border transfer safeguards
- Privacy incident and breach response
Regulations we work with
One privacy program, mapped to every law you answer to.
GDPR
EU & UK GDPR
Applies when you offer goods or services to people in the EU or UK, or monitor their behavior — wherever your company is based.
- Records of Processing Activities (Article 30)
- Lawful basis, transparency, and consent
- Data Protection Impact Assessments (Article 35)
- Processor agreements (Article 28) and transfer safeguards
- 72-hour breach notification readiness (Article 33)
CCPA / CPRA
California Consumer Privacy Act
The most demanding U.S. privacy law — and its newest regulations reach directly into your security program.
- Rights to know, delete, correct, and opt out of sale or sharing
- Risk assessments for covered processing, required from January 1, 2026
- Automated decision-making technology (ADMT) rules from January 1, 2027
- Independent cybersecurity audits — first certifications due April 1, 2028, 2029, or 2030 depending on revenue
- Service-provider and contractor terms
U.S. states
State privacy laws
Virginia, Colorado, Connecticut, Texas, Oregon, and a growing list of others — similar in spirit, different in the details.
- Applicability analysis by state and threshold
- One harmonized baseline instead of fifty checklists
- Universal opt-out and browser privacy signals
- Sensitive data and children’s data requirements
- Annual review as new laws take effect
Where privacy and security meet
Implement once, satisfy both.
Most privacy obligations have a security twin. We build the control one time and document how it meets each law.
| Obligation | GDPR | CCPA / CPRA | How we implement it once |
|---|---|---|---|
| Know your data | Records of processing (Art. 30) | Notice at collection; data inventory for rights requests | A single data map tied to your asset inventory |
| Assess risk | DPIAs for high-risk processing (Art. 35) | Risk assessments under CPPA regulations | One assessment method feeding your security risk register |
| Secure the data | Security of processing (Art. 32) | Reasonable security; annual cybersecurity audits | The same controls you use for SOC 2, ISO 27001, or HITRUST |
| Manage vendors | Processor contracts (Art. 28) | Service-provider and contractor terms | Vendor risk tiering with privacy terms built in |
| Honor rights | Access, erasure, portability — one month to respond | Know, delete, correct, opt out — 45 days to respond | One intake and tracking workflow for every request |
| Respond to incidents | Notify the regulator within 72 hours when required | California breach-notification law and statutory damages exposure | One incident response plan with privacy decision points |
The privacy track of the Anchor Path
From data map to managed privacy risk.
Discover
Map
Inventory personal data, systems, vendors, and flows; confirm which laws apply.
Assess
Measure
DPIAs and CCPA risk assessments; privacy risks added to your Risk Ledger.
Treat
Build
Notices, consent, rights-request workflow, vendor terms, retention rules.
Monitor
Watch
Ongoing privacy risk indicators and tracking new laws as they land.
Assure
Prove
Evidence packages, cybersecurity audit readiness, and regulator-ready records.
We’re security and compliance practitioners, not a law firm. We work alongside your legal counsel, who remains responsible for legal interpretation and advice.
Collecting more personal data than you can account for?
Tell us which laws you’re worried about. We’ll show you where you stand and what it will take.