Many organisations begin with notices, consent language and policies. Those matter, but they do not answer every practical question. Teams still need to know where data sits, who can access it, how long it should be kept and what happens when something goes wrong.

A simple readiness review should look at how personal data moves through real processes. That includes customer onboarding, marketing lists, HR records, vendor sharing and support workflows.

Where to begin

Start with the data that creates the most exposure. Map the process, check the evidence and confirm who owns each decision. Small habits, repeated well, are usually what make privacy controls work.