What breaks between ten clients and forty
Nothing goes wrong on any single engagement. What fails, somewhere in the teens, is the ability to answer questions that span the portfolio — which clients use this vendor, which files rest on a fact that has changed, what is left to do on each. Memory was doing that job, and memory does not scale.
These are operating notes rather than legal ones: which parts of the work are the same every time, which are the judgement a client pays for, and how to keep the difference visible in the file.
Guides
Long-form, written for a practitioner.
- How to scale a privacy practice past 20 clients
What breaks between 10 and 40 clients, and the operating habits that keep documentation current without hiring for every new engagement.
- White-labelling compliance documentation for clients
How to deliver documentation under your brand without hiding who is responsible for the content, and what to keep out of file metadata.
- Subprocessor lists: what changes when a vendor updates its DPA
Which vendor changes require a client update, which only need a note on file, and how to track them across a portfolio.
Notes
Shorter pieces on one thing that changed.
- An answer needs a state: confirmed, to check, or gap
A bare "yes, it's encrypted" cannot be defended a year later. A fact with a state, an owner and an expiry date can.
- When a vendor has no public data processing agreement
What to ask for, what a customer-specific DPA changes about the annex, and how to record "asked, no response" so the file stays honest.
Doing this work
What the product does with it.
- Records of processing
Build an Article 30 record of processing for each client from facts you confirmed once: purposes, categories, recipients, transfers and retention, with the vendor rows filled from a verified registry.
- Data processing agreements
Draft an Article 28 data processing agreement for each client from the facts you confirmed once: the processing described, the sub-processors named, transfers and their mechanisms, in your firm's wording.
- Trust pages
Publish a client's security and privacy information as a page on their own domain, under your brand: sub-processors, measures and documents, updated from the same confirmed facts as their pack.
- Vendor changes
Vendor pages are checked daily and every change is read by a person before it reaches you, with the clients affected and the documents to regenerate.
Reference
The pages the facts come from.
See what changed since your clients' policies were written
Enter up to ten client websites. Free, no sign-up, the first report in about a minute.