Privacy Public trust
People can see how their information is held and who's answerable.
Notices describe a practice nobody has verified, and requests are handled ad hoc.
Discuss this domainThe notice says one thing; the systems do another.
The privacy notice has not been checked against what systems actually collect.
Rights requests are handled by whoever receives the email.
Retention is theoretical: little is deleted, because nobody owns the decision.
New systems go live without a privacy assessment because none is required.
The privacy offering menu.
Offering 01 is the front door: it produces the evidence-based TruMaturity™ score and this domain’s maturity roadmap, which decides the order of everything below it. A fractional Chief Privacy Officer (vCPO) is available where the roadmap calls for a standing seat.
Related insights
All insights →Who Owns Privacy? Why a DPO Title Doesn't Guarantee Accountability
Twenty US states now have comprehensive privacy laws in effect. See why an independent DPO still isn't the same as owning privacy operationally.
Five Privacy Findings That Show Up Long After the Policy Was Signed
A privacy policy is a snapshot, not a subscription. See the five privacy findings that surface long after the policy was signed and board-approved.
Privacy depends on the data inventory, the controls protecting it, and the AI tools reading it.