GDPR and privacy programs
A comprehensive privacy program — data mapping, consent, DSAR handling, breach response — built to satisfy regulators and the procurement teams of the customers you want.
Practitioner-led privacy and security programs for mid-market operating businesses — GDPR compliance, ISO 27001 certification, and the data-governance build that unlocks enterprise contracts and clears diligence. Led by a former Chief Privacy Officer who has stood up the programs that won large corporate deals — not an auditor selling a checklist.
Privacy & Security Compliance is rarely one job. Engagements typically braid two or three sub-offers, led by the partner with the most relevant operating experience.
A comprehensive privacy program — data mapping, consent, DSAR handling, breach response — built to satisfy regulators and the procurement teams of the customers you want.
Stand up the information-security management system and carry it through to certification. The credential that clears enterprise vendor-security reviews.
Who owns what data, where it lives, who can touch it. The governance backbone that makes both privacy and analytics work instead of fighting each other.
Build privacy and security into platform rollouts from day one, instead of retrofitting after an audit finds the gap.
The security and privacy diligence on your vendors — and the answers when your enterprise customers run the same review on you.
Privacy and security posture is a diligence line item. Get it clean before a buyer or partner asks, so it is an asset in the data room, not a discount.
The partner who takes your first call is the partner in the room. We don't sell what we haven't run.
Marcin Samiec, Senior Partner, Tech & AI, and a former VP of Technology and Chief Privacy Officer. He has stood up GDPR and ISO 27001 programs that helped win large corporate contracts.
Because privacy and security posture is increasingly what wins enterprise contracts and what clears diligence in a sale. It is an operating and deal-value issue, and Marcin has run it from the executive seat.
Yes — from gap assessment through the management-system build to the certification audit, with the internal team owning it afterward.
No — any business handling customer or employee data at scale, especially one selling into enterprise or preparing for a sale, needs a defensible privacy and security posture.
It is built into the digital-transformation and AI engagements — privacy-by-design rather than a separate audit — and it surfaces directly in exit-prep and diligence.