Security & Compliance
Know What You Hold, Why You Hold It, and What You Owe
GDPR, CCPA and CPRA, the state privacy laws, VCDPA, BIPA. We build privacy programs that answer a regulator, a customer, and a data subject, and that hold up now that AI is reaching data you collected for something else entirely.
The problem
Privacy Exposure Is Usually about Data You Forgot You Had
The regulation that catches organizations out is rarely the one they prepared for. It’s the biometric consent nobody documented, the marketing list that outlived its purpose, the vendor that retained records past termination, the analytics tag collecting more than the notice describes.
AI makes this sharper. A model trained or prompted on data collected for another purpose raises a question, was this compatible with why you collected it, that most privacy notices were never written to answer.
How we help
Program, Assessments, and the Awkward Questions Early
Privacy Program Design
Governance structure, roles, policies, notices, retention schedules, and a records-of-processing approach that stays current.
Data Mapping and Inventory
What you hold, where it came from, what you’re allowed to do with it, and when it should be gone.
Privacy Impact Assessments
PIAs and DPIAs for new products, features, and AI use cases, done early enough to change the design.
Data Subject Rights
A workflow that answers access, deletion, and opt-out requests inside the deadline, repeatably.
AI and Privacy
Purpose limitation, minimization, and transparency for AI use cases, including automated-decision obligations where they apply.
Vendor and Cross-Border Transfers
Processor terms, transfer mechanisms, and the diligence to support them.
privacy program build · data mapping · PIA and DPIA · records of processing · notices and consent design · data subject rights workflow · retention and deletion · vendor privacy diligence · cross-border transfer mechanisms · biometric and sensitive-data review · privacy training
What you get
Defensible Answers, Written Down
- A data inventory and map your legal and engineering teams both trust
- Policies, notices, and a retention schedule that match what actually happens
- PIAs on the record for the decisions that needed them
- A rights-request process with owners and timers
- A privacy position on your AI use cases before a regulator asks for one
GDPR · AI/ML
A manufacturer using AI to interpret ultrasound images needed GDPR compliance before entering the EU and UK markets. We assessed the policies and practices behind the model, revised what the regulation impacted, and prepared them for launch.
The Work Stays Proven after We Hand It Over
Privacy obligations don’t hold still. The CyRisk platform tracks the controls, the assessments, and the evidence, and flags what needs review as the map changes.
CyRisk is 4A’s sister platform. Where our work for CyRisk appears on this site, we disclose the affiliation.
