Data-Privacy Assessment: What You Collect and What You Do With It
A review of the personal data flowing through your business — what is collected, where it lives, who can see it and how long it stays. GullySystem maps it and recommends practical changes to reduce what is exposed.
What a Data-Privacy Assessment Maps Out
This assessment traces personal data through your business rather than testing a system for technical weaknesses: every form that collects it, every place it ends up stored, every person and system that can see it, and how long it is kept after it is no longer needed.
Where Personal Data Quietly Piles Up
- Copies of customer ID documents sit in individual staff laptops' downloads folders, with no idea how many copies actually exist
- A signup form collects details that were never actually used for anything afterwards
- There is no process for responding when someone asks you to delete their data
- A vendor integration was given a full data export instead of only the fields its integration actually needed
What Gets Assessed
Data Inventory and Mapping
What personal data is collected, from where, and every system it flows into afterwards.
Retention Practice
How long data is kept, and whether anything is retained well past the point it was needed.
Consent and Collection Points
What forms and touchpoints collect personal data, and whether people are told what it is used for.
Internal and External Access
Who inside your business, and which outside vendors, can actually see the data once it is collected.
What the Review Produces
A data map showing what you hold and where, and a practical set of changes — reducing what is collected at the source, restricting who can see it internally, setting retention limits, and tightening what vendors are given access to. This is a stand-alone review; it can feed into a certification effort such as DPDP readiness, but is not itself proof of compliance.
Who Should Run This
- Businesses collecting identity, health or financial details from customers, patients or students
- Companies preparing for a certification or compliance effort that will ask how personal data is handled
- Any business that has been asked directly by a customer how their data is handled and cannot yet answer confidently
Frequently asked questions
How is this different from the ISO 27001, SOC 2 and DPDP readiness work?
This assessment focuses specifically on personal data — what is collected, where it goes, and how long it is kept. Readiness work is broader, covering the wider set of technical controls a certification or audit effort needs across security generally. This assessment often feeds into that effort but stands on its own without one.
Does completing this assessment make us compliant with DPDP or any other law?
No. This is a practical review and set of recommendations, not a certification or a legal determination of compliance. Where legal compliance is the goal, this work is done alongside your legal counsel or compliance consultant, not instead of them.
What drives the cost of a data-privacy assessment?
How many systems and forms collect personal data, and how many distinct types of data — identity documents, health records, financial details — are involved. A business collecting one or two data types through a handful of forms costs less to map than one collecting many types across dozens of systems.
What determines how long the mapping exercise takes?
How well documented your current data flows already are, and how quickly access to review the relevant systems and forms is provided. A business with no existing data inventory takes longer, since building the map from scratch is part of the work.
Does it matter which systems or software we use to store customer data?
No. The assessment adapts to whatever combination of software, spreadsheets and physical storage your business currently uses — the goal is an accurate picture of where data actually is, not a check against one particular platform.
Who owns the data map and recommendations?
You do. The data map, findings and recommended changes belong to your business and can be shared with your own legal counsel, auditor or consultant as needed.
What does GullySystem need from us to begin?
A list of the forms, systems and vendors that collect or receive personal data, and access to review each of them, along with a contact who can explain why a particular piece of data is collected where the reason is not obvious.
Tell us what you need.
Send a short brief and one of our engineers will come back to you — usually the same day.
- No obligation
- We reply the same working day
- Your details stay private