Privacy by Design implementation
GDPR Article 25 requires technical and organisational measures, not just a policy. We work with your product and engineering teams to embed privacy into how the system is actually built: from planning and technical design through deployment, so data protection is baked into the product.
Data minimisation & retention by default
We help you implement minimisation as an engineering default (collect only what the purpose needs), build retention enforcement into your systems (delete when the clock runs out, including across replicas and backups), and turn “minimise and delete” into automated behaviour.
Privacy-Enhancing Technologies (PETs)
We help you select and deploy the right PETs for your use case: pseudonymisation, anonymisation, differential privacy, encryption approaches, etc. We match the technique to the actual risk and data flow.
Data flow mapping & discovery
You can’t protect or delete what you can’t locate. We map how personal data actually moves through your systems, databases, APIs, logs, third-party tools, backups; and help you deploy discovery tooling so the map stays current.
Consent & preferences enforcement
We help you enforce consent and preferences where it counts (e.g., at the API gateway or service-mesh level) so that consent status is actually checked before data is used, and preference changes propagate through the system.
DSR & data subject request automation
When a request comes in, the system has to find every copy of a person’s data, including in third-party tools. We help you build the technical side of data subject requests: discovery across structured and unstructured stores, custom wrappers around third-party APIs that hold your users’ data, and evidence that deletion actually happened.
Reusable privacy patterns & control catalogue
We build a catalogue of tested engineering patterns: minimisation defaults, anonymsation, retention enforcement, logging that your teams reuse across products, plus intake gates and decision logs for high-risk trade-offs, so privacy scales with your engineering rather than blocking it.
IoT & device privacy review
We assess devices with cameras, microphones or sensors for privacy-by-design: what the device captures, where it’s processed, what reaches the cloud versus stays on-device, and the recording indicators and defaults that actually protect users. You get a report with device- and app-level privacy controls mapped to GDPR and ETSI EN 303 645.
Consent & CMP engineering
We review your consent mechanism (OneTrust, Cookiebot or a custom banner) for both EDPB/GPC guideline validity and technical correctness, then help your team implement it properly: that “reject” truly blocks tracking, that Consent Mode v2 signals fire with the right states, and that preference changes propagate through the pipeline.
Anonymisation & pseudonymisation review
We assess whether your de-identification is truly anonymous under EDPB/CCPA guidelines and regulations or merely pseudonymisation that stays personal information. We design the anonymisation pipeline, support your team through implementation, and back the result with a sufficiency memo against EDPB tests and re-identification risk (singling out, linkability, inference).