First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Privacy Data Mapping and Impact Assessment (DPIA)
ConsultingCompliance

Privacy Data Mapping and Impact Assessment (DPIA)

Privacy Data Mapping and Impact Assessment (DPIA) is a fixed-price, three-week engagement that builds the two privacy documents regulators, auditors and enterprise customers actually ask for: a record of processing activities — the data map — for an agreed set of your processing activities, and up to two defensible impact assessments. The map records, per activity, the purpose, the data subjects and data categories, the systems, the internal owner, the processors and sub-processors, the international transfers, the retention rule and the lawful basis, in the form GDPR Article 30 and the US state privacy laws expect. Each impact assessment is a GDPR or UK GDPR Article 35 DPIA, a California CCPA risk assessment under the CPPA regulations in force since 1 January 2026, or a DPIA for a Microsoft 365 Copilot or other AI rollout — the document your DPO or general counsel has been asking for. IT Partner builds both from evidence in your own Microsoft estate rather than from questionnaires alone: Microsoft Purview classification, sensitivity labels, retention and data loss prevention policies, the Purview Data Map and Unified Catalog where you run them, and Microsoft Priva Privacy Risk Management where you have licensed it — optional tooling, never a prerequisite. $4,950 per project, fixed, for one data map covering an agreed set of processing activities plus up to two impact assessments; further assessments and further business functions are quoted in writing. We are engineers and privacy practitioners, not a law firm: the documents are yours for counsel and the DPO to review, sign and file, and nothing in this engagement is legal advice or a DPO service.

Timeline 3 weeksService owner Dan ApplebyMicrosoft PurviewMicrosoft PrivaMicrosoft 365 Copilot

What this engagement is

Three deadlines put privacy documentation on the 2026 agenda. California's CCPA regulations on risk assessments, automated decision-making technology and cybersecurity audits took effect on 1 January 2026, per the California Privacy Protection Agency's announcement of 23 September 2025: a business that sells or shares personal information, processes sensitive personal information, uses automated decision-making technology for a significant decision, or trains such technology on personal information must complete a risk assessment before it starts that processing, must assess processing that predates 2026 by 31 December 2027, and must submit its first attestation and summary to the agency by 1 April 2028 — with the automated-decision-making rules applying from 1 January 2027 and cybersecurity-audit certifications phased in from 1 April 2028 by revenue band. In the EU and the UK, Article 30 has required a record of processing activities since 2018 and Article 35 requires a data protection impact assessment wherever processing is likely to be high-risk — and supervisory authorities ask for both in the first letter of an inquiry. Across the United States, twenty comprehensive state privacy laws were in force at the start of 2026, with more enacted since, most of them requiring a data protection assessment for targeted advertising, the sale of personal data, sensitive data and profiling. Underneath all three sits the same problem: nobody can produce a current, accurate answer to 'what personal data do we process, why, where, with whom and for how long.' This is not a discovery scan, and it is worth being precise about the difference. Discovery — our GDPR Data Discovery Service — is tool-driven: it finds where personal data physically sits across SharePoint, OneDrive, Exchange, Teams and file shares and how much of it there is. A data map, or record of processing activities, is organized by activity rather than by location: recruiting, payroll, customer support, marketing analytics, Copilot-assisted drafting. For each activity it records the purpose, the categories of data subjects and data, the systems involved, the internal owner, the processors and sub-processors, any transfer outside the EEA, the UK or the United States, the retention rule and the lawful basis or, under the CCPA, the disclosed purpose and whether the activity sells, shares or touches sensitive personal information. Regulators, auditors and enterprise vendor-review teams ask for the map; discovery is how you check the map is telling the truth. If you have never run discovery, we say so at scoping and the two can be sequenced. What makes the map defensible rather than aspirational is evidence. We take the processing activities your owners describe in workshops and check each against what your Microsoft estate shows: Microsoft Purview's sensitive information types, trainable classifiers and Content Explorer for what the data actually contains, sensitivity labels for how it is classified, retention policies and labels for how long it is really kept, data loss prevention for what leaves, the unified audit log for who touches it, and — for organizations that run them — the Purview Data Map and Unified Catalog for the Azure, Fabric and SQL sources that also hold personal data. Where you have licensed Microsoft Priva Privacy Risk Management, its personal-data insights and policies become another evidence source and a place to keep the map's findings alive; it is optional tooling, never a prerequisite, and we do not require you to buy it. The gaps this exposes — a 'deleted after 90 days' claim contradicted by a seven-year retention policy, a processor nobody listed, a mailbox full of national ID numbers in a team that swore it held none — are the findings that change the map, and they are why a questionnaire-only exercise is not worth paying for. Each impact assessment follows the structure the regulator will read it against. A GDPR or UK GDPR DPIA carries the four elements Article 35(7) names — a systematic description of the processing and its purposes, an assessment of necessity and proportionality, an assessment of the risks to individuals' rights and freedoms, and the measures that address them — and is screened against the Article 35(3) triggers and the European Data Protection Board's criteria for likely high risk, so the file shows why a DPIA was or was not required. A CCPA risk assessment carries the content the CPPA regulations prescribe: the purpose, the categories of personal information, the operational elements of the processing, the benefits weighed against the negative impacts, the safeguards, and the decision whether to proceed — kept in the form the agency can request in full and summarized for the annual submission. Every assessment ends in a risk register with owners and dates and a mitigation plan that names the Microsoft control that closes each item — a DLP policy, a retention label, a Conditional Access rule, a sharing setting — so the plan can be executed by your team or through our DLP and retention engagements. The most common request in 2026 is a DPIA for Microsoft 365 Copilot, and it is a real assessment, not a formality. The facts on Microsoft's side are documented and we cite them: per Microsoft's published Copilot data-handling documentation, prompts, responses and the Microsoft Graph data Copilot reads stay inside the Microsoft 365 service boundary, are not used to train Microsoft's foundation models, are covered by the Microsoft Products and Services Data Protection Addendum, and honor the EU Data Boundary for European tenants; Copilot interactions are stored in the user's mailbox where your retention, eDiscovery and audit controls apply; and Copilot reads only what the user already has permission to read. That last point is where the risk lives. Copilot does not create access — it surfaces every over-shared site, every 'Everyone except external users' link and every mislabeled HR file the user could already open, at the speed of a chat prompt. A Copilot DPIA therefore assesses oversharing, labeling coverage, web-grounded queries that leave the boundary for Bing under separate terms, agents and plug-ins that reach non-Microsoft data, employee-monitoring implications, and the transparency owed to staff — and its mitigation plan is mostly Purview work, which is why it pairs with Purview data governance for Copilot. The UK Information Commissioner's Office has released a redacted DPIA for its own Copilot use, NHS England publishes a template, and Microsoft publishes a build-your-own DPIA for public-sector customers; we use them as reference points and write yours against your tenant. You finish with a data map you can hand to a regulator, an auditor or an enterprise customer's vendor-review team, one or two impact assessments ready for counsel and the DPO to sign, a risk register that IT can execute, and drafted input for your privacy notice wherever the map changed what it should say. The map lives in your own tenant — a SharePoint list and library by default, or the GRC or Priva tooling you already run — with a maintenance procedure your privacy lead can keep up without us. What we are not is a law firm or your data protection officer. We do not decide your lawful basis, interpret a statute for you, sign the assessment as DPO, or promise that any document makes you compliant; we build the evidence-based documents that let the people who carry those roles do so on solid ground.

Success criteria

01The agreed set of processing activities is documented in one data map, each activity carrying purpose, data subjects, data categories, systems, owner, processors and sub-processors, transfers, retention rule and lawful basis or disclosed purpose — with no field left 'unknown' without a named owner and a date to resolve it.
02Every map entry was checked against evidence from the tenant — Purview classification, labels, retention, DLP and the audit log, plus the Purview Data Map or Priva where present — and the discrepancies between what owners believed and what the estate shows are listed as rated findings.
03Each in-scope impact assessment (up to two) is screened and, where required, completed in the structure its regime prescribes — GDPR/UK GDPR Article 35(7), the CPPA risk-assessment content requirements, or the Copilot/AI DPIA structure — with the screening decision recorded either way.
04Each assessment ends in a risk register with a severity, an owner, a date and a mitigation that names the specific control — Microsoft or procedural — that closes it, plus a residual-risk statement counsel can act on, including whether prior consultation with a supervisory authority is indicated.
05The processor and sub-processor inventory reconciles to your contracts: each named processor has a data processing agreement or Microsoft's Data Protection Addendum on file, or is listed as a gap with an owner.
06Privacy-notice input is drafted for every place the map showed the current notice is silent or wrong, marked for counsel to finalize.
07The map and assessments are stored in your own tenant with a written maintenance procedure — who updates what, on what trigger, on what cadence — aligned to the CCPA's three-year review and 45-day material-change rule and the GDPR expectation that the record stays current.
08Your privacy lead can explain, defend and update every entry without us — the handover walkthrough is the test.

What you receive

Privacy data map / record of processing activities — one structured register (a SharePoint list with an evidence library in your tenant by default; Priva or your GRC tool where you prefer) for the agreed set of processing activities, with the GDPR Article 30 fields, the CCPA-relevant fields (sale or sharing, sensitive personal information, automated decision-making) and an evidence reference per entry.
Processing-activity workshop records — the scoped list of activities, the owners interviewed, the questions asked and the answers given, so every map entry has a provenance trail.
Evidence pack from the Microsoft estate — Purview Content Explorer and classification exports, sensitivity-label and retention coverage per workload, the DLP policy inventory, audit-log samples and, where present, Purview Data Map / Unified Catalog and Priva findings, each tied to the map entries it supports or contradicts.
Discrepancy findings — where the estate contradicts what the business believed (retention, location, classification, unlisted processors), rated and assigned to an owner.
Processor and sub-processor inventory — every processor per activity, the contract or data processing agreement that covers it, Microsoft's Data Protection Addendum and sub-processor list where Microsoft is the processor, and the transfer mechanism where data leaves the jurisdiction.
Up to two impact assessments — GDPR/UK GDPR Article 35 DPIA, CCPA risk assessment, or Microsoft 365 Copilot / AI DPIA — each with its screening decision, the regime's required content, the consultation record and a signature block for the DPO or accountable executive.
Risk register and mitigation plan — every identified risk with severity, owner, date, the named control that closes it and the residual risk after mitigation, formatted so IT can execute it and counsel can accept it.
Privacy-notice and transparency input — drafted paragraphs for the external privacy notice, the employee privacy notice and, for Copilot rollouts, the staff communication, marked for counsel's review.
Maintenance procedure and handover — a one-page procedure for keeping the map and assessments current (triggers, cadence, owners, the CCPA submission calendar where it applies), a recorded walkthrough for your privacy lead, and the editable source files for everything above.

How the work unfolds

Days 1–2 — Scope and intake

We agree in writing which processing activities the map covers, which one or two assessments are in scope and under which regime, who owns each activity and who signs. You grant read-only access to Purview, the unified audit log and, where present, the Purview Data Map and Priva. We collect what exists today: any earlier inventory or DPIA, privacy notices, data processing agreements, vendor lists and the tenant's classification and retention configuration.

Days 2–6 — Processing-activity workshops

Short structured sessions with each activity owner — HR, finance, sales and marketing, support, IT, and the Copilot or AI program owner where an AI assessment is in scope. Each session fills the map's fields for that activity and records what the owner believes about retention, sharing and processors, so the evidence step has something to test.

Days 4–9 — Evidence and map build

Purview classification, label and retention coverage, DLP, audit-log samples and the Data Map or Priva findings are pulled for each activity and reconciled against the workshop answers. The map is built in your tenant entry by entry, discrepancies are logged as findings, and the processor inventory is reconciled to your contracts and to Microsoft's Data Protection Addendum.

Days 8–13 — Impact assessments

Each in-scope assessment is screened, then written in its regime's structure: the systematic description, necessity and proportionality, risk analysis and measures for a GDPR or UK GDPR DPIA; the prescribed content for a CCPA risk assessment; the Copilot-specific analysis — data flows, oversharing, labeling, interaction retention, web grounding, agents, monitoring, transparency — for an AI rollout. Drafts go to your privacy lead and counsel for a first read.

Days 12–14 — Risk register, mitigation plan and notice input

Risks from both assessments are consolidated into one register with owners, dates and named controls; the mitigation plan is sequenced; privacy-notice paragraphs are drafted where the map changed what the notice should say. Counsel's comments are incorporated.

Day 15 — Handover

A recorded walkthrough of the map, the assessments and the register for your privacy lead, the DPO and IT; the maintenance procedure and the CCPA submission calendar where it applies; the editable sources. Our access is removed unless you ask us to keep it for a follow-on engagement.

Prerequisites

A named privacy lead — DPO, privacy manager, general counsel's delegate, or the IT director wearing that hat — who can convene the activity owners and make scoping decisions within days.
Activity owners available for one workshop each in the first week; the three-week plan assumes answers in days, not weeks.
Read-only access to Microsoft Purview (classification, Content Explorer, labels, retention, DLP), the unified audit log and, where present, the Purview Data Map / Unified Catalog and Microsoft Priva — granted through a scoped role, never Global Administrator.
Microsoft 365 licensing that exposes the evidence we rely on: Microsoft 365 E5, E5 Compliance or the Purview add-ons give the richest classification and retention data; Business Premium and E3 still work with less depth, and we state at scoping what we can and cannot see.
Your existing privacy artefacts, whatever their state: privacy notices, prior inventories or DPIAs, vendor and processor lists, data processing agreements, and the GDPR or CCPA applicability analysis counsel has already made.
For a Copilot or AI DPIA: the deployment plan (who gets Copilot, which agents and plug-ins, whether web grounding is enabled) and a Copilot administrator to confirm settings.
Counsel or a DPO to review and sign — we draft to their standard, and an assessment is not finished until someone in that role has read it.

Who does what

IT Partner

  • Run the scoping, the workshops and the evidence collection to a written plan, with read-only access only.
  • Build the data map in your tenant with every field evidenced or flagged, never left silently blank.
  • Write each impact assessment to its regime's prescribed structure, citing Microsoft's published documentation and the regulation's current text at the time of writing, with the source and date recorded.
  • Produce the risk register and mitigation plan naming the specific control for every item, including items that earn us nothing to fix.
  • Draft privacy-notice input marked clearly for counsel's review, and say plainly where a question is a legal judgment we will not make.
  • Hand over editable sources, a maintenance procedure and a recorded walkthrough, and remove our access at the end.
  • Treat everything we see as confidential and act under your data processing terms for the duration of the engagement.

Your team

  • Provide the named privacy lead, the activity owners and the read-only access on the agreed dates.
  • Supply existing notices, contracts, data processing agreements and any prior inventory, however incomplete.
  • Make the lawful-basis, applicability and risk-acceptance decisions — with counsel where you choose — that only the controller can make.
  • Confirm scope in writing before the workshops start: which activities, which assessments, which regime.
  • Review the drafts within the plan's windows and route them to counsel or the DPO for signature.
  • Own the map afterwards: run the maintenance procedure, or ask us for the retainer that does.

What's not included

Legal advice of any kind — determining whether the GDPR, UK GDPR, the CCPA or another state law applies to you, choosing a lawful basis, interpreting a statute, negotiating a data processing agreement, or advising on a breach. We draft the documents; your counsel gives the advice. We are not a law firm, a certified public accountant, a QSA, a C3PAO or a certification body.
Data protection officer services — we do not act as your DPO, sign as your DPO, or represent you to a supervisory authority or the California Privacy Protection Agency. The CPPA submission is yours to make; we prepare the calendar and the summary content.
Data discovery at scale — locating and quantifying personal data across the whole estate is the GDPR Data Discovery Service; this engagement samples the estate for evidence and uses discovery output where you already have it.
Remediation — implementing the mitigation plan is separate, quoted work: DLP policy configuration, retention and data lifecycle management, Purview data governance for Copilot, Copilot oversharing clean-up, sensitivity-label rollout, or Conditional Access changes are each quoted from the register in writing.
Consent management, cookie banners and website tracker work — unless scoped and quoted separately. Microsoft removed its Priva Consent Management and Tracker Scanning previews from the Priva portal in December 2025, so this is tooling from another vendor or your web team.
Subject rights request handling — building or operating the DSAR process, which in Microsoft 365 now runs through Purview eDiscovery (Premium) following Microsoft's 2026 transition of Priva Subject Rights Requests, is quoted separately.
Microsoft licensing — Microsoft 365, the Purview add-ons and Microsoft Priva Privacy Risk Management are your subscriptions, bought through us or any other channel at Microsoft's price; nothing in this engagement requires Priva.
Certification or attestation — no deliverable will state that you are 'GDPR compliant' or 'CCPA compliant', and there is no certificate anyone can issue for either. ISO/IEC 27701 or ISO/IEC 42001 readiness is a separate engagement: AI governance and ISO/IEC 42001 readiness assessment. EU AI Act conformity or fundamental-rights impact assessments are likewise out of scope.
Non-Microsoft systems beyond the map — the map records every system an activity uses, but the evidence pull is from your Microsoft estate; ERP, HRIS, CRM and other SaaS platforms are documented from their owners' answers and your contracts, not scanned.
Further impact assessments beyond two, additional business functions beyond the agreed set, and assessments for other jurisdictions' regimes (LGPD, PIPEDA, PDPA and the like) — each quoted in writing from the map.
Ongoing maintenance — keeping the map current, running the three-year and material-change reviews and refreshing the evidence is the Compliance Evidence and Audit Readiness Retainer, or your privacy lead following the handover procedure.

Limitations & technical notes

!Regulatory dates and thresholds are the regulators': the CPPA regulations took effect 1 January 2026, with pre-2026 processing to be assessed by 31 December 2027, the first risk-assessment attestation due 1 April 2028, automated decision-making requirements from 1 January 2027 and cybersecurity-audit certifications phased from 1 April 2028 to 2030 by annual revenue, per the agency's 23 September 2025 announcement and the final regulation text at the time of writing. The assessments cite the current text on their delivery date; confirm against it before filing.
!The count of US state privacy laws changes every legislative session — twenty comprehensive laws were in force at the start of 2026 and more have been enacted since. The map is built to the common Virginia-model assessment fields so it serves the states you name at scoping, not every state forever.
!Microsoft Priva's product line moved in 2025–2026: Microsoft removed the Privacy Assessments, Consent Management, Tracker Scanning and beyond-Microsoft-365 Subject Rights Requests previews from the Priva portal in December 2025 and transitioned Subject Rights Requests to Purview eDiscovery (Premium) from 9 May 2026, while Privacy Risk Management remains a licensed add-on, per Microsoft's Priva 'What's new' notices as reported at the time of writing. We verify Priva's current state in your tenant at scoping and do not build the engagement on it.
!Evidence depth follows licensing. Purview classification, Content Explorer, retention labels and DLP reporting are richest on Microsoft 365 E5 or E5 Compliance; on Business Premium or E3 some evidence is unavailable and the map entry says 'per owner statement' rather than 'per tenant evidence'. We state the difference at scoping.
!A DPIA screening can conclude that no DPIA is required; that conclusion is itself a deliverable and is recorded, and it consumes one of the two included assessments only if the full assessment is then written.
!Statements about Copilot's data handling are Microsoft's published commitments at the time of writing — service-boundary processing, no foundation-model training on your data, the EU Data Boundary, existing-permission enforcement — and are cited with the source and date in the assessment. Web-grounded queries, third-party agents and plug-ins operate under their own terms and are assessed as such.
!Lawful basis, applicability, risk acceptance and any decision to consult a supervisory authority under GDPR Article 36 are the controller's decisions. The assessment lays out the analysis and the residual risk; it does not make the call.
!The map is a snapshot with a maintenance procedure. Processing activities change with every new system and every AI feature Microsoft ships; a map nobody updates is stale within a quarter.

Frequently asked questions

What is the difference between a data map, a record of processing activities and a data inventory?

In practice the first two are the same document: GDPR Article 30 calls it a record of processing activities, the US state laws and most privacy programs call it a data map, and both are organized by processing activity — recruiting, payroll, support — with purpose, subjects, categories, systems, owners, processors, transfers, retention and lawful basis per activity. A data inventory is organized by location: which repositories hold personal data and how much. The inventory is what discovery produces; the map is what regulators ask for. This engagement builds the map and uses inventory evidence to test it.

Do we need a record of processing activities if we have fewer than 250 employees?

Under GDPR Article 30(5) the derogation for organizations with fewer than 250 employees falls away if the processing is likely to result in a risk to individuals, is not occasional, or includes special categories of data or criminal-conviction data — and payroll, HR and customer records alone are 'not occasional', so almost every organization ends up keeping one anyway. The UK GDPR carries the same rule. Whether the derogation applies to you is a legal question for counsel; we will tell you what the regulation says and build the map either way, because the CCPA risk assessment and the US state assessments need the same fields.

When exactly does the CCPA risk-assessment obligation bite, and what has to be sent to the CPPA?

Per the California Privacy Protection Agency's 23 September 2025 announcement and the final regulations, the rules took effect on 1 January 2026. From that date a business must complete a risk assessment before starting any processing that presents significant risk — selling or sharing personal information, processing sensitive personal information, using automated decision-making technology for a significant decision, or training such technology on personal information. Processing already under way before 2026 must be assessed by 31 December 2027. The first submission to the agency — an executive attestation plus summary information about the assessments conducted in 2026 and 2027 — is due by 1 April 2028 and annually after that; the agency or the Attorney General can request the full assessment. Assessments are reviewed at least every three years and updated within 45 days of a material change. Whether your business meets the CCPA's thresholds is counsel's call; we build the assessment to the regulation's content requirements and the submission calendar.

Our DPO has asked for a DPIA before we roll out Microsoft 365 Copilot. Is that really necessary?

Very often, yes — and the DPO is right to ask. Copilot processes personal data across email, chat, documents and meetings at a scale and speed that supervisory authorities tend to treat as likely high-risk under the Article 35 screening criteria, especially where employee data and profiling are involved; the UK Information Commissioner's Office has released a redacted DPIA for its own Copilot use and NHS England publishes a template, which tells you how regulators see it. The good news is that Microsoft's side is documented: it states that prompts, responses and Graph data stay inside the Microsoft 365 service boundary, are not used to train its foundation models, honor the EU Data Boundary and are covered by its Data Protection Addendum. The assessment's real work is your side of the boundary — oversharing, labeling, retention of Copilot interactions, web grounding, agents and transparency to staff — and its mitigation plan is mostly Purview configuration.

Do we have to buy Microsoft Priva for this?

No. Priva Privacy Risk Management is optional tooling we can use as an evidence source and as a home for the map's personal-data findings if you already license it, and we can walk you through it in a Microsoft partner demo tenant before you decide. Nothing in the engagement depends on it. Be aware that Microsoft removed the Priva Privacy Assessments, Consent Management, Tracker Scanning and beyond-Microsoft-365 Subject Rights Requests previews in December 2025 and moved Subject Rights Requests to Purview eDiscovery (Premium) from 9 May 2026 — so if a vendor is selling you Priva as a complete privacy platform, ask which parts still exist. Licensing, if you choose it, is your Microsoft subscription at Microsoft's price.

Where does the data map live afterwards?

In your tenant — by default as a SharePoint list with a document library for the evidence and assessments, permissioned to the privacy team, which gives you version history, an audit trail and no new tool to buy. If you run a GRC platform or Priva, we build it there instead. Either way you get the editable sources and a one-page maintenance procedure.

How is this different from the GDPR Data Discovery Service?

Discovery answers 'where is the personal data and how much' by scanning the estate with Purview tooling over two to six weeks. This engagement answers 'what do we do with personal data, why, with whom and for how long' by building the activity-based record and the impact assessments, sampling the estate for evidence rather than scanning all of it. If you have never run discovery and have no idea where your data sits, discovery first is usually the honest sequence; if you already have an inventory or a scan, this engagement uses it.

What does 'an agreed set of processing activities' mean in practice?

One coherent slice you can finish in three weeks — a business function such as HR or marketing, or a platform such as the Microsoft 365 estate itself — listed activity by activity in the scope letter before we start. Most first engagements map one function end to end and use the Copilot or CCPA assessment to cover the horizontal risk. A second function or the rest of the enterprise is a further quoted engagement on the same register, so the map grows rather than restarts.

Can you decide our lawful basis or tell us whether the CCPA applies to us?

No, and be wary of anyone who will for $4,950. We record the lawful basis your owners and counsel state, flag where it looks unsupported — consent claimed for processing nobody can withdraw from, legitimate interests with no balancing test on file — and lay out the analysis. The decision, and the applicability analysis, belong to your counsel.

What happens if the DPIA finds high residual risk?

It says so, plainly. Under GDPR Article 36 a controller must consult the supervisory authority before processing when residual risk stays high after mitigation; the assessment identifies that situation and the mitigation plan shows what would bring the risk down first, which is almost always what a controller prefers to do. Whether to consult is your decision with counsel; we prepare the material either way.

Which Microsoft evidence do you actually use, and what if we are not on E5?

Purview sensitive information types, trainable classifiers and Content Explorer for what the data contains; sensitivity labels for classification; retention policies and labels for real retention; DLP for what leaves; the unified audit log for access; Purview Data Security Posture Management for AI for Copilot interactions involving sensitive data; and, where you run them, the Purview Data Map and Unified Catalog for Azure, Fabric and SQL sources. On Microsoft 365 E5 or E5 Compliance all of that is available; on Business Premium or E3 some is not, and the map marks those entries as owner statements rather than tenant evidence. We tell you the difference at scoping, not at handover.

Does the CCPA risk assessment double as our GDPR DPIA?

Not automatically — the two prescribe different content and apply different tests — but they share most of the description and much of the risk analysis, and we write them from one evidence base so the second is largely a restructuring of the first. If both regimes apply to one activity, that is a sensible use of the two included assessments.

Can you also handle our privacy notices, subject access requests and the CPPA filing?

We draft privacy-notice input for every place the map changed what the notice should say, marked for counsel to finalize. Subject rights requests are a separate process — in Microsoft 365 they now run through Purview eDiscovery (Premium) — and building or operating it is quoted separately. The CPPA submission is the business's own attestation; we prepare the calendar and the summary content, and you file it.

How do we keep the map current after handover?

The handover procedure names the triggers — a new system, a new vendor, a new AI feature, a change of purpose — the owners and the cadence, aligned to the CCPA's three-year review and 45-day material-change rule and the GDPR expectation that the record stays accurate. Your privacy lead can run it in a few hours a quarter. If you would rather we did, the Compliance Evidence and Audit Readiness Retainer keeps the map, the evidence and the assessments refreshed monthly.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$4,950 per project
3 weeks
Scope the data map and DPIA