Devensa Advisory
Get started
Six domains / Privacy

Privacy Public trust

People can see how their information is held and who's answerable.

Without it

Notices describe a practice nobody has verified, and requests are handled ad hoc.

Discuss this domain
Signs you need help here

The notice says one thing; the systems do another.

01

The privacy notice has not been checked against what systems actually collect.

02

Rights requests are handled by whoever receives the email.

03

Retention is theoretical: little is deleted, because nobody owns the decision.

04

New systems go live without a privacy assessment because none is required.

What Devensa does here

The privacy offering menu.

Offering 01 is the front door: it produces the evidence-based TruMaturity™ score and this domain’s maturity roadmap, which decides the order of everything below it. A fractional Chief Privacy Officer (vCPO) is available where the roadmap calls for a standing seat.

01
Current State Assessment
Privacy readiness against the NIST Privacy Framework
02
Privacy Governance Framework & Charter
Structure, decision rights, accountability (Govern-P)
03
Privacy Policy Framework
Notices, consent, data handling, processor standards
04
Data Mapping & Records of Processing
Inventory and mapping of processing (Identify-P)
05
Privacy Impact & DPIA Program
High-risk processing evaluation (Control-P)
06
Data Subject Rights & DSAR Program
Rights fulfillment process and tooling
07
Cross-Border Transfer & Processor Risk
Transfer mechanisms, DPAs, third-party privacy risk
08
Privacy Incident Response & Breach Notification
Detection, response, regulatory notification
09
AI & Automated Decision-Making Privacy Risk
Profiling, automated decisions, opt-out rights
10
Privacy Organizational Impact Assessment
Workflow change from privacy-by-design
11
Privacy Workforce Training & Culture Change
Role-based training and awareness (Communicate-P)
See the complete services menu →

Related insights

All insights →
Privacy

Who Owns Privacy? Why a DPO Title Doesn't Guarantee Accountability

Twenty US states now have comprehensive privacy laws in effect. See why an independent DPO still isn't the same as owning privacy operationally.

Privacy

Five Privacy Findings That Show Up Long After the Policy Was Signed

A privacy policy is a snapshot, not a subscription. See the five privacy findings that surface long after the policy was signed and board-approved.

The other five

Privacy depends on the data inventory, the controls protecting it, and the AI tools reading it.

Cybersecurity
Continuity
Open →
AI Governance
Permission to move
Open →
Risk Management
One narrative
Open →
Compliance
Defensibility
Open →
Data Governance
Capacity
Open →