Privacy services, from first principle to audit evidence
Vedhacon works at the point where privacy law meets the systems that process personal data. Every engagement begins with what applies to the organisation, and ends with evidence that a regulator, an auditor or a customer can verify.
Privacy education & training
Compliance fails most often because the people who make daily decisions were never told what the law expects of them. Training is written for the audience in the room, the board hears risk and accountability, engineers hear design decisions, and recruiters hear what they may and may not collect.
Separate tracks per function, so nobody sits through material that does not apply to their work.
Ninety minutes on exposure, personal liability, and the decisions only leadership can make.
Minimisation, retention, logging, pseudonymisation and consent, expressed as build requirements.
Structured preparation for recognised privacy and information security qualifications.
Consultancy & DPO as a service
The first question is never "how do we comply", it is "which laws actually reach us, and for which processing". Applicability is established first, then the gap is measured against it, then the work is sequenced by risk rather than by whichever obligation is easiest to close. We scope in writing and deliver in phases, so you always know what is being done and what it will cost.
Which regimes apply, to which entities, for which processing activities, and on what basis.
Current state against obligations, scored by risk and effort, with a defensible rationale.
A named contact for regulators and data principals, with independence preserved by contract.
Responses to security and privacy questionnaires that hold up to follow-up questions.
Implementation & engineering
A policy that no system enforces is not a control. This is the work of turning obligations into configuration, records, and repeatable process, carried out alongside the teams who will own it once the engagement ends.
What is held, where it sits, why it was collected, who it reaches, and when it is deleted.
Layered notices, granular consent capture, withdrawal that propagates, and an auditable log.
Assessments that are actually completed, records that stay current, and enforced deletion.
Mechanism selection, transfer impact assessments, and processor obligations that flow down.
Intake, identity verification, fulfilment and response, inside statutory timelines.
Roles, escalation paths, committee cadence, and the decisions each forum owns.
Certification readiness
Certification is won or lost at scoping. Define the boundary carefully, build a management system the organisation can genuinely sustain, and the assessment becomes a confirmation rather than an examination.
A defensible boundary and a Statement of Applicability with reasoned inclusions and exclusions.
Policies, procedures and records proportionate to the organisation, not a generic template pack.
Methodology, assessment, treatment plan, and residual risk accepted at the right level.
Management review, internal audit, and attendance alongside you through the certification audit.
Audit & assurance
An audit is useful only when it tests whether a control operated, not whether a document exists. Sampling is evidence-led, findings are written so the reader can reproduce them, and every observation carries a corrective action with an owner and a date.
Programme audits against the standard, the law, or your own control set.
Assessment of processors and sub-processors, including on-site and remote review.
Artefacts organised by control, so the next reviewer does not start from nothing.
Findings followed through to verified closure, with re-testing where it matters.
AI governance
Most organisations moved from AI experiments to AI in production without the control model catching up. The work here is inventory first, then lawful basis and data provenance, then the assessments and human oversight the newer regimes now expect.
Every model and AI-enabled feature, including those procured inside third-party tools.
Tiering against the EU AI Act and internal thresholds, with the obligations each tier attracts.
Where training and prompt data came from, and whether that use was lawful and disclosed.
Human review points, drift and performance monitoring, and a route to challenge a decision.
Breach & incident response
Notification windows are short and they begin at awareness, not at certainty. The decisions that matter, who assesses, who notifies, and what the threshold is, have to be settled before an incident, because they cannot be settled during one.
Roles, decision thresholds, and the clock that starts at each stage of an incident.
Scenario drills that test the plan against real timelines, with findings written up afterwards.
Regulator and data principal notification drafted against the requirements of each regime.
Root cause, control failure analysis, and changes carried back into the programme.
Six steps, and you own the outcome at each one
Scoping call
Forty-five minutes on what you process, where you operate, and what is driving the deadline.
Assessment
Applicability and gap analysis, producing a risk-ranked view of what is actually outstanding.
Implement
Controls implemented with your teams, so capability stays in the organisation afterwards.
Prove
Audit, evidence packs, and certification support, so the programme withstands scrutiny.
Sustain
Training, regulatory monitoring and periodic reassessment, so the programme does not drift.
Handover
Documentation your own team can maintain. No dependency by design, that is the point.
Tell us where you are, and where you need to be
Share a little context and the right specialist, legal, technical, or certification, will come back to you. There is no obligation and no sales script.