Data protection
Bounded adviceData Protection Impact Assessment: the document a regulator asks for first
An AI feature that processes personal data usually triggers an assessment obligation, and the assessment is also the first document a regulator asks for. Most are written after the fact to paper a decision already taken, which is when they are least useful and most dangerous. This one is done properly, on one operation, in two to three weeks.
- Published range
- $2,000–4,500 / assessment
- Timing after intake
- 2–3 weeks
- Quoted in India
- ₹1,00,000–2,25,000 / assessment
Fixed scope, not hourly. Quoted before we start, with the exclusions written down. The India figure is a separate price for a separate market, not a conversion.
How this is actually run
One defined question answered properly - a system, a vendor, a transfer route, a questionnaire - with the reasoning written out and the documents to act on it.
The scope is fixed before the work starts, which is why the price is a published range rather than an hourly estimate. Anything outside it is quoted separately rather than absorbed quietly or billed by surprise.
- Why clients instruct us
- An AI feature that processes personal data usually triggers an assessment obligation, and the assessment is also the document a regulator asks for first. Most are written after the fact to paper a decision already taken, which is exactly when they are least useful.
- What we actually do
- One processing operation, properly: what it does and why, whether it is necessary and proportionate to that purpose, what could go wrong for the people affected and how likely it is, the measures that reduce it, and the residual risk that remains. Where the operation cannot be brought within the law as designed, we say so and set out what would have to change.
- What sits outside this
- The assessment covers the operation it names. Broader privacy remediation across the business, and security testing of the systems involved, are separate pieces of work.
- What you can show afterwards
- A completed assessment with its reasoning, its consultation record and its sign-off - the document a regulator, a customer or an insurer asks for, dated and ready rather than reconstructed under pressure.
What you receive
A completed assessment for one processing operation: necessity, proportionality, risks to people, and the measures that bring it within the law.
One processing operation. Broader privacy remediation across the business, records of processing for the whole estate, and security testing of the systems involved are separate pieces of work, quoted separately.
- A description of the processing: what it does, for whom, on what basis
- A necessity and proportionality analysis against the stated purpose
- Risks to the people affected, assessed by likelihood and severity rather than asserted
- The measures that reduce each risk, with owners against them
- The residual risk that remains, stated plainly
- A consultation record, including whose views were sought
- Sign-off, and what to do if the operation cannot be brought within the law as designed
What it costs, and what it replaces
Both figures are published ranges for the same unit of work. Ours is fixed before we start; if our process gets faster, that is our gain and your price does not move.
How engagements are structured →Published range for this engagement, against the span of the whole card. In India the same scope is quoted at ₹1,00,000–2,25,000 — a separate price for a separate market, not a conversion. Where in the range a quote lands is set by scope, entities and how much usable evidence already exists.
Midpoint $3,250 per assessment
How the work runs
01
Scope the operation
One processing operation, defined precisely. An assessment covering 'the platform' is an assessment of nothing, and it is the first thing a regulator picks apart.
02
Describe and test necessity
What the processing does and why, then whether it is actually necessary and proportionate to that purpose - which is the question most assessments skip, because the honest answer is sometimes no.
03
Assess risk to people
Not risk to the company. What could go wrong for the people whose data this is, how likely it is, how severe, and how easily they could find out or object.
04
Measures and residual risk
The measures that reduce each risk, who owns them and by when, then the residual risk stated plainly rather than assumed away by the existence of the measures.
05
Consultation and sign-off
Whose views were sought and what they said, then sign-off. Where the residual risk stays high, we advise on what follows from that rather than letting the document end quietly.
What we need from you
- A walkthrough of the processing, ideally in a staging environment
- Data categories, sources, retention and who can reach the data
- The vendors and subprocessors involved, and their terms
- Any existing assessment, privacy notice or record of processing
- The product owner, and whoever carries data protection responsibility
What we check before delivery
- Risk is assessed from the perspective of the people affected, not the company's exposure
- Necessity is actually tested, including the option of not doing the processing
- Every factual statement about the system is confirmed by its owner
- A second qualified reviewer checks the analysis before sign-off
When firms send us this
- A new AI feature will process personal data at scale
- A customer or regulator has asked whether an assessment exists
- Processing involves sensitive categories, children, or monitoring
- An existing assessment was written to paper a decision and will not survive scrutiny
Questions about data protection impact assessment
Do we definitely need one?
That itself is a question worth answering before you spend money on the assessment. Whether the obligation bites depends on what the processing does and where. We will tell you if the answer is no - it is a short conversation and it costs you nothing.
Can you do several at once?
Yes, priced per operation, and the second is usually cheaper than the first because the architecture work carries over. Most companies start with the one that worries them most.
Firms who send us this usually also send
This engagement
Scope it in fifteen minutes.
Data Protection Impact Assessment at $2,000–4,500 per assessment, delivered in 2–3 weeks after a complete intake. Scoping costs nothing, and we will say if a smaller engagement would serve you better.

