Skip to content

07 · Compliance

Privacy & Data Protection

The obligations you have whether or not anyone asks.

ISO 27001 and SOC 2 are chosen. GDPR, HIPAA, COPPA and PCI DSS are not. They apply by law the moment you handle certain data or certain users. We work out which actually bind you, then build the evidence to show it.

The context

Why this matters

Certification frameworks are commercial decisions: a customer asks, you comply, a deal unblocks. Privacy regulation is different. It applies because of the data you hold and the people you hold it about, and it applied from the day you started, whether or not anyone has raised it.

That asymmetry is why we see the same pattern repeatedly, a company gets ISO 27001 certified, then discovers during an enterprise data protection review that it has no Record of Processing Activities, no lawful basis analysis, and no tested process for a data subject request. Certified, and still exposed.

We start by working out which regulations actually bind you, because the honest answer is often fewer than a vendor questionnaire implies. Then we build the specific artefacts each one demands, and map them onto your ISMS so the same evidence serves both.

Regulations we cover

7 regulations. We’ll tell you which actually bind you.

And which don’t. That answer usually saves more money than any control we implement.

GDPR

By law

EU & UK

Applies ifYou have any users, customers or staff in the EU or UK.

Full guide

HIPAA

By law

United States

Applies ifYou touch protected health information for a US covered entity.

Full guide

COPPA

By law

United States

Applies ifYour service is directed at under-13s, or you know they use it.

Full guide

CCPA / CPRA

By law

California, US

Applies ifYou do business with California residents above the revenue or data thresholds.

Full guide

PCI DSS

By law

Global

Applies ifYou store, process or transmit cardholder data, including via an embedded payment form.

Full guide

FERPA

By law

United States

Applies ifYou handle student education records for US schools or districts.

Full guide

NIS2

By law

European Union

Applies ifYou are an EU cloud, managed service or other in-scope essential entity.

Full guide

What is covered

Scope of the engagement

  1. 01

    Applicability assessment

    Which regulations genuinely apply, based on your users, data, markets and contracts. We will tell you when something does not apply. That answer saves more money than any control we implement.

  2. 02

    Data mapping & records of processing

    What personal data you hold, where it came from, why you hold it, who you share it with, where it goes, and how long you keep it. This underpins nearly every regulation on the list.

  3. 03

    Rights and consent workflows

    Data subject access, deletion, correction and opt-out, built as a process your team can actually run inside the statutory deadline, then tested with a live request.

  4. 04

    Contracts and third parties

    Processor agreements, Business Associate Agreements, Standard Contractual Clauses, sub-processor registers, and a vendor review process proportionate to risk.

  5. 05

    Breach and incident obligations

    Each regulation has its own clock, 24 hours for NIS2, 72 for GDPR, 60 days for HIPAA. One runbook that satisfies all of the ones that bind you.

  6. 06

    Framework crosswalk

    Mapping every obligation onto your ISO 27001 or SOC 2 control set so one body of evidence serves the certification and the regulator.

What you receive

Deliverables

Everything below is included in the fixed price. Nothing here is an upsell discovered halfway through.

  • Applicability report, which regulations bind you, and which do not
  • Data map and Record of Processing Activities
  • Gap assessment against each applicable regulation
  • Policy and notice set: privacy notice, retention schedule, consent records
  • Rights request and breach notification runbooks, tested
  • DPIAs or risk analyses where the regulation requires them
  • Crosswalk onto your existing ISMS control set

Questions

Privacy & Data Protection FAQ

If you process personal data of people in the EU or UK while offering them goods or services, yes, the regulation is extraterritorial and your own location is irrelevant. That said, scope is often narrower than teams fear. The applicability assessment exists precisely to establish what genuinely binds you rather than defaulting to everything.

You can, but understand what you are signing. A Business Associate Agreement makes you directly liable under HIPAA, including for the Security Rule's documented risk analysis. Sign it after you can meet it, not before. We regularly help teams get there in weeks rather than turn the deal down.

Your scope is dramatically reduced, but not eliminated. Which Self-Assessment Questionnaire applies depends on exactly how the payment form interacts with your page, a fully hosted redirect, an iframe, and a JavaScript element that touches your DOM are three different answers. Getting this wrong invalidates the assessment.

No. We are security and compliance consultants, not a law firm, and we do not give legal advice. We build the technical and organisational measures, the evidence and the processes these regulations require, and we work alongside your counsel on the legal interpretation. Where a statutory DPO is required, we help you appoint one.

It should. The overlap is substantial, data mapping, vendor review, access control, incident response and retention all serve both. Running them together typically adds 3 to 5 weeks rather than doubling the work.

Know exactly what an auditor, and an attacker, would find.

Tell us what you need certified or tested. We will scope it properly, quote a fixed price, and tell you honestly if the timeline you have in mind is realistic.

Book a scoping callsecurity@innsecs.com

No sales sequence. A scoping call and a written proposal cost nothing.