Privacy
We trace personal data through collection, use, sharing, and deletion, and compare what we find with the requirements you pick, such as DPDPA or ISO/IEC 27701. Notices, consent records, processor contracts, and the rights request process each get a finding. The plan puts gaps with legal exposure at the top.
Engagement brief
Fixed scope
AccountableYour named owner
ResponsibleA Truvara practitioner
Drafts and citesCASK
Phases
We confirm scope and timing after a first call.
When teams call us
The DPDP Rules are in force and you need to know what changes for you
A customer's data processing agreement asks for records you do not have
Rights requests arrive by email and nobody tracks the deadline
You plan to extend an ISO/IEC 27001 system with ISO/IEC 27701
What you receive
Drag the divider. On the left, where the work usually starts. On the right, the files you receive.
What you receive
The files from this engagement
Gap assessment
Implementation
Before the engagement
What we usually find on day one
A gap list that is really a folder of unanswered questions.
What it works against
CASK maps every requirement to evidence in the workspace, so scoping starts from what already exists and what is missing.
Key areas covered
How it runs
One sequence, from the records you already have to the outcome in your hands.
Agree the requirements
Confirms which laws and standards apply, such as DPDPA, GDPR, or ISO/IEC 27701, and which business units are in scope.
Trace the data
Interviews the teams that collect and use personal data and confirms purposes and retention with them.
Review notices, consent, and rights
Walks a sample rights request through your process and reviews each notice against the law.
Rank the gaps
Sets priorities with your privacy owner and counsel, then presents the plan.
What we need from you
Questions