Who this is for
Organizations that are legally required to appoint a DPO (or want one as best practice) but don't have the volume of work, or budget, to justify a full-time role: mid-market companies under GDPR/Amendment 13/CCPA scope, and enterprises supplementing an internal privacy function with specialist bandwidth.
Outcomes & deliverables
- A named, contactable DPO of record for regulators, employees, and customers
- A current, audit-ready data-processing register and record of processing activities
- Documented procedures for data-subject access, deletion, and correction requests
- Breach-notification readiness matched to the specific deadlines your regulator enforces
Scope & methodology
Data-flow mapping, processing register build-out, and gap analysis against applicable privacy law.
Ongoing DPO duties: regulator liaison, staff training, data-subject request handling, and vendor DPA review.
Quarterly re-assessment as processing activities, vendors, or regulations change.
What you receive
A named DPO your organization can list in privacy notices and regulator filings, a maintained processing register, documented request-handling procedures, and direct escalation access when a data-subject request or regulator inquiry lands.
Frameworks & standards mapped
Industries & use cases
Proof
Led by Nitzan Levi, whose title is literally Executive Director of Privacy & GRC, holding CISM, CISSP, CDPSE, CCSK and CSA credentials: this isn't a generalist consultant covering privacy as a side practice.