
Audit-ready evidence
Every control change ships with audit evidence: a records-of-processing update, before and after risk rating, DPIA notes, and a runbook entry for assessors.
Two recent data privacy engagements. Records of processing, DPIAs, and DLP coverage shared under MNDA on a scoping call.

Cybersecurity and Compliance engagement,
Data privacy and GDPR compliance program
Dcrayon mapped every data flow, built our Article 30 record, and set retention rules our legal team signed off on. DSAR responses now follow one documented process.
DLP coverage and DSAR volumes on scoping call
Data flows mapped and classified
Data protection strategy: data mapping, a DPIA on high-risk processing, DLP policy in Microsoft Purview, and a consent and retention schedule reviewed with counsel.
Read Cybersecurity and Compliance engagement's Case Study
Mid-market cybersecurity and compliance brand,
Privacy program with security review
We had no record of where personal data lived. Dcrayon delivered a full data inventory and a breach notification runbook that maps to the 72-hour rule.
Audit gaps closed, shared on scoping call
Retention and consent controls live
Data protection work alongside a wider cybersecurity review. A gap assessment against GDPR and PCI DSS set the baseline for the privacy roadmap.
Read Mid-market cybersecurity and compliance brand's Case StudyHOW DCRAYON DATA PROTECTION STRATEGY WORKS

What every Dcrayon data protection strategy engagement includes by default
Score, Plan, Compound. A privacy and security diagnostic, a 90-day control roadmap, and the toolkit we run on every data protection strategy engagement.

A data-mapping and gap assessment against GDPR Articles 30 and 32, the DPDP Act, and PCI DSS. We chart where personal and cardholder data lives, who touches it, and which controls are missing. Free on every proposal call.

A 90-day roadmap that sequences data protection work back to one privacy or security metric you pick, so gaps close in priority order inside a quarter.

An internal toolkit that runs data mapping and DLP audits, then generates a prioritized remediation list your CFO and data protection officer can budget.
Three repeatable practices that harden data protection across cycles.
Free Dcrayon Score readout in one business day. We inventory your personal and cardholder data flows, check lawful basis and cross-border transfer paths, and score your data loss prevention coverage, then give one 0-100 number plus the gap list. No follow-on commitment.
Written 90-day data protection plan tied to one control gap you pick, from records of processing to encryption at rest. A CIPP-certified GDPR consultant writes the controls, and either side can close the SoW. No annual lock-in.
Weekly working session with your lead consultant plus a monthly board-ready summary. The programme builds in order: data mapping in cycle one sets the DLP rules in cycle two, which feed audit-ready evidence in cycle three.
Sibling Dcrayon services inside the Cybersecurity and Compliance category. Programs clients often layer alongside Data Protection Strategy.

No trainees practicing on your regulated data. The GDPR consultant who scopes your program stays on it through delivery.

A written diagnostic and a fixed estimate up front, so you see scope and cost before any contract, not after a long discovery phase.

Every engagement includes AI-assisted work by default: anomaly detection on data access, exfiltration alerts, and policy-drift monitoring across endpoints.

A weekly working cadence and a monthly Score tied to one privacy or security metric. A report your CFO and data protection officer can read without translation.
Onboarding begins after a scoping call and access provisioning. Post-incident and breach-response work is prioritized ahead of routine data privacy engagements.
Both. Some clients hand us the whole data protection function, acting as their outsourced DPO and PCI DSS lead. Others keep an internal team and use us as senior GDPR and PCI escalation. We scope per account.
Most data protection strategy engagements start at Rs 4 to 8 lakhs per month in India or USD 6 to 15 thousand per month globally. A one-off GDPR or PCI DSS gap audit starts lower.
Yes. A free five-axis data protection Score on every proposal call, with the top gaps ranked by risk. No follow-on commitment required.