Data protection

Bounded advice

Data Protection Impact Assessment: the document a regulator asks for first

An AI feature that processes personal data usually triggers an assessment obligation, and the assessment is also the first document a regulator asks for. Most are written after the fact to paper a decision already taken, which is when they are least useful and most dangerous. This one is done properly, on one operation, in two to three weeks.

Published range
$2,000–4,500 / assessment
Timing after intake
2–3 weeks
Quoted in India
₹1,00,000–2,25,000 / assessment

Fixed scope, not hourly. Quoted before we start, with the exclusions written down. The India figure is a separate price for a separate market, not a conversion.

Bounded advice

How this is actually run

One defined question answered properly - a system, a vendor, a transfer route, a questionnaire - with the reasoning written out and the documents to act on it.

The scope is fixed before the work starts, which is why the price is a published range rather than an hourly estimate. Anything outside it is quoted separately rather than absorbed quietly or billed by surprise.

Why clients instruct us
An AI feature that processes personal data usually triggers an assessment obligation, and the assessment is also the document a regulator asks for first. Most are written after the fact to paper a decision already taken, which is exactly when they are least useful.
What we actually do
One processing operation, properly: what it does and why, whether it is necessary and proportionate to that purpose, what could go wrong for the people affected and how likely it is, the measures that reduce it, and the residual risk that remains. Where the operation cannot be brought within the law as designed, we say so and set out what would have to change.
What sits outside this
The assessment covers the operation it names. Broader privacy remediation across the business, and security testing of the systems involved, are separate pieces of work.
What you can show afterwards
A completed assessment with its reasoning, its consultation record and its sign-off - the document a regulator, a customer or an insurer asks for, dated and ready rather than reconstructed under pressure.

What you receive

A completed assessment for one processing operation: necessity, proportionality, risks to people, and the measures that bring it within the law.

One processing operation. Broader privacy remediation across the business, records of processing for the whole estate, and security testing of the systems involved are separate pieces of work, quoted separately.

  • A description of the processing: what it does, for whom, on what basis
  • A necessity and proportionality analysis against the stated purpose
  • Risks to the people affected, assessed by likelihood and severity rather than asserted
  • The measures that reduce each risk, with owners against them
  • The residual risk that remains, stated plainly
  • A consultation record, including whose views were sought
  • Sign-off, and what to do if the operation cannot be brought within the law as designed

What it costs, and what it replaces

Both figures are published ranges for the same unit of work. Ours is fixed before we start; if our process gets faster, that is our gain and your price does not move.

How engagements are structured →
Per assessment · against every fixed-scope engagement
$750Data Protection Impact Assessment: $2,000–4,500$12,000

Published range for this engagement, against the span of the whole card. In India the same scope is quoted at ₹1,00,000–2,25,000 — a separate price for a separate market, not a conversion. Where in the range a quote lands is set by scope, entities and how much usable evidence already exists.

Midpoint $3,250 per assessment

How the work runs

  1. 01

    Scope the operation

    One processing operation, defined precisely. An assessment covering 'the platform' is an assessment of nothing, and it is the first thing a regulator picks apart.

  2. 02

    Describe and test necessity

    What the processing does and why, then whether it is actually necessary and proportionate to that purpose - which is the question most assessments skip, because the honest answer is sometimes no.

  3. 03

    Assess risk to people

    Not risk to the company. What could go wrong for the people whose data this is, how likely it is, how severe, and how easily they could find out or object.

  4. 04

    Measures and residual risk

    The measures that reduce each risk, who owns them and by when, then the residual risk stated plainly rather than assumed away by the existence of the measures.

  5. 05

    Consultation and sign-off

    Whose views were sought and what they said, then sign-off. Where the residual risk stays high, we advise on what follows from that rather than letting the document end quietly.

What we need from you

  • A walkthrough of the processing, ideally in a staging environment
  • Data categories, sources, retention and who can reach the data
  • The vendors and subprocessors involved, and their terms
  • Any existing assessment, privacy notice or record of processing
  • The product owner, and whoever carries data protection responsibility

What we check before delivery

  • Risk is assessed from the perspective of the people affected, not the company's exposure
  • Necessity is actually tested, including the option of not doing the processing
  • Every factual statement about the system is confirmed by its owner
  • A second qualified reviewer checks the analysis before sign-off

When firms send us this

  • A new AI feature will process personal data at scale
  • A customer or regulator has asked whether an assessment exists
  • Processing involves sensitive categories, children, or monitoring
  • An existing assessment was written to paper a decision and will not survive scrutiny

Questions about data protection impact assessment

  • Do we definitely need one?

    That itself is a question worth answering before you spend money on the assessment. Whether the obligation bites depends on what the processing does and where. We will tell you if the answer is no - it is a short conversation and it costs you nothing.

  • Can you do several at once?

    Yes, priced per operation, and the second is usually cheaper than the first because the architecture work carries over. Most companies start with the one that worries them most.

This engagement

Scope it in fifteen minutes.

Data Protection Impact Assessment at $2,000–4,500 per assessment, delivered in 2–3 weeks after a complete intake. Scoping costs nothing, and we will say if a smaller engagement would serve you better.

Schedule a Call