Blog › ICP guides
Data privacy consultant on retainer: GDPR compliance advisory, CCPA/CPRA advisory, and data breach response advisory on monthly retainer
August 1, 2026 · ~22 min read
A B2B SaaS company processing personal data of EU data subjects receives a letter from the Irish Data Protection Commission (DPC) in February initiating a formal inquiry under Article 77 GDPR following a data subject complaint. The complaint alleges that the company’s privacy notice failed to identify the legal basis for processing employee performance data shared with the company’s HR analytics platform, and that a data subject access request submitted in October received no response within the 30-day window required by GDPR Article 12(3). The DPC inquiry requests the company’s Article 30 Records of Processing Activities and all data subject requests received in the preceding 12 months along with their response dates.
The company’s legal team reviews the ROPA. The ROPA was last updated in 2023 and does not include the HR analytics platform onboarded in March 2024. The privacy notice does not identify the legal basis for the HR analytics processing and does not specify the categories of data subjects whose data is shared. The October DSAR was received via the company’s website contact form — not through the dedicated privacy inbox established for DSARs — and was never routed to the privacy team. The DPC inquiry has identified three distinct GDPR compliance gaps that, if identified and addressed in an ongoing advisory relationship, would each have been resolved before the complaint was filed.
Between the company’s previous DPA engagement three years earlier and the February inquiry were the advisory hours that could have kept the GDPR compliance program current: the quarterly ROPA review that would have added the HR analytics platform to the processing register when it was onboarded in March 2024; the annual privacy notice adequacy review that would have identified the missing legal basis specification for the HR analytics processing; and the DSAR intake process review that would have confirmed that all channels through which data subjects contact the company are monitored and routed to the privacy team. Those advisory hours are invisible in a privacy advisory relationship that bills only for discrete project deliverables — the initial GDPR gap assessment three years earlier, the privacy notice that was drafted and never updated, the processor agreement template that was approved and then applied to new processors without individual review.
Data privacy consultants on monthly retainer — CIPP/E- and CIPP/US-credentialed privacy professionals, external DPOs, and privacy attorneys who provide ongoing compliance advisory to organizations processing personal data in the EU, California, and other regulated jurisdictions — do a substantial share of their highest-value work between the visible regulatory milestones of DPA investigations and data breach notifications. This guide covers GDPR compliance advisory, CCPA/CPRA compliance advisory, and data breach response advisory: the regulatory frameworks behind each service area, the specific legal standards and procedural requirements that govern the advisory, and how to structure a retainer agreement that makes the ongoing privacy advisory work visible to the client’s privacy and legal teams between enforcement events.
GDPR compliance advisory
GDPR compliance advisory is the retainer function that evaluates the client’s ongoing data processing activities against the General Data Protection Regulation’s lawfulness, transparency, and accountability requirements, advising on privacy notice adequacy, processor agreement compliance, records of processing activities maintenance, and DPIA requirements before data protection authority inquiries or data subject complaints trigger formal investigation.
Privacy notice adequacy: GDPR Articles 13 and 14
GDPR Articles 13 and 14 require controllers to provide data subjects with specific information about the processing of their personal data at the time the data is collected (Article 13, for data obtained directly from the data subject) or within a reasonable period after collection (Article 14, for data obtained from sources other than the data subject). The information required includes the identity and contact details of the controller; the contact details of the DPO if appointed; the purposes and legal basis for the processing; where the processing is based on legitimate interests, the specific legitimate interests pursued; the categories of recipients or specific recipients of the data; the intent to transfer data to third countries and the safeguards applied; the retention period or the criteria used to determine it; the data subject’s rights (access, rectification, erasure, restriction, portability, objection); and, where the processing is based on consent, the right to withdraw consent at any time.
Lawful basis identification is the most commonly deficient element in privacy notices. GDPR Article 6 provides six lawful bases for processing personal data of non-special-category data subjects: consent (Article 6(1)(a)), contract (Article 6(1)(b)), legal obligation (Article 6(1)(c)), vital interests (Article 6(1)(d)), public task (Article 6(1)(e)), and legitimate interests (Article 6(1)(f)). The privacy notice must identify the specific lawful basis for each processing purpose, not merely list all six as potential bases. A privacy notice that states “we process your data on the basis of consent, contract, legal obligation, or legitimate interests as appropriate” does not satisfy the Article 13(1)(c) requirement because it does not allow the data subject to identify which basis applies to which purpose. The retained data privacy consultant reviewing a privacy notice evaluates whether each processing purpose stated in the notice has a specifically identified lawful basis, and whether the lawful basis is plausibly applicable to the stated purpose.
Purpose limitation under GDPR Article 5(1)(b) requires that personal data be collected for specified, explicit, and legitimate purposes, and not further processed in a manner incompatible with those purposes. A privacy notice that states a purpose of “providing our services and improving our products” as a single undifferentiated purpose conflates data processing for service delivery (a purpose closely related to the original collection purpose) with data processing for product analytics and improvement (a purpose that may or may not be compatible with the original collection purpose depending on whether behavioral analytics data is identifiable or aggregated). The retained consultant evaluates whether the privacy notice’s stated purposes are specific enough to allow the controller to evaluate compatibility if the data is subsequently used for a new purpose, and whether the “compatible purposes” analysis under GDPR Article 6(4) has been documented for any secondary uses of the data.
Retention period specificity is the element of Article 13/14 compliance most frequently addressed with inadequate language. A privacy notice that states “we retain your data for as long as necessary to provide our services or as required by law” does not meet the Article 13(2)(a) requirement because it does not specify the retention period or the criteria used to determine the retention period. The retained consultant reviewing a privacy notice evaluates whether the retention language for each data category is specific enough to allow a data subject to anticipate when their data will be deleted or anonymized, and whether the client’s actual data retention practices are consistent with the stated retention periods — a common gap when the privacy notice specifies retention periods that the underlying data systems do not enforce through automated deletion or anonymization.
Data processor agreements: GDPR Article 28
GDPR Article 28 requires controllers to use only processors that provide sufficient guarantees to implement appropriate technical and organizational measures (TOMs) such that processing meets the GDPR’s requirements and protects data subjects’ rights. Processing by a processor must be governed by a contract (or other binding legal act) that sets out the subject matter, duration, nature and purpose of the processing, the type of personal data and categories of data subjects, and the obligations and rights of the controller. Article 28(3) specifies the mandatory provisions that must appear in every data processing agreement (DPA): the processor shall process personal data only on documented instructions from the controller; the processor shall ensure confidentiality obligations on authorized personnel; the processor shall implement appropriate security measures under Article 32; the processor shall respect the conditions for engaging sub-processors; the processor shall assist the controller in fulfilling its obligations under Articles 32 to 36 (security, breach notification, DPIA, prior consultation); the processor shall assist the controller in responding to data subject rights requests; the processor shall delete or return all personal data after the end of services; and the processor shall make available all information necessary to demonstrate compliance with Article 28.
Sub-processor management under Article 28(2) is the most operationally challenging element of processor agreement compliance for controllers using SaaS platforms and cloud infrastructure. The processor must obtain prior specific or general written authorization from the controller before engaging sub-processors. General authorization (the most common approach in commercial DPAs) allows the processor to engage any sub-processor subject to: notifying the controller of intended additions or replacements, and giving the controller the opportunity to object. The retained data privacy consultant advising on processor agreement management evaluates whether the controller’s DPAs contain an objection mechanism with a defined notice period (typically 14 to 30 days) and a defined escalation path if the controller objects but the processor proceeds with the sub-processor engagement.
Technical and organizational measures (TOMs) descriptions in Article 28 processor agreements range from a single sentence (“the Processor will implement industry-standard security measures”) to detailed technical annexes specifying encryption standards, access control mechanisms, penetration testing schedules, and incident response procedures. The EDPB’s Guidelines on Article 28 indicate that TOM descriptions should be sufficiently specific to allow the controller to evaluate whether the processor’s security measures are appropriate to the risk level of the processing. The retained consultant evaluating a processor agreement’s TOM annex reviews whether the description covers the three dimensions of appropriate TOMs under Article 32: pseudonymization and encryption of personal data; the ability to ensure ongoing confidentiality, integrity, availability, and resilience; the ability to restore availability and access to personal data in a timely manner following an incident; and a process for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures.
Cross-border transfer mechanisms apply when a controller uses a processor or sub-processor located outside the European Economic Area (EEA). Following the Court of Justice of the EU ruling in Schrems II (Case C-311/18, 2020), the primary mechanism for transfers to non-adequate countries is the European Commission’s Standard Contractual Clauses (SCCs), issued in updated form in June 2021. The 2021 SCCs introduce a modular structure covering four transfer scenarios: controller-to-controller (Module 1), controller-to-processor (Module 2), processor-to-controller (Module 3), and processor-to-processor (Module 4). For transfers to processors in the United States, the EU-U.S. Data Privacy Framework (DPF, adopted July 2023) provides an adequacy decision allowing transfers to DPF-certified recipients without SCCs. The retained consultant evaluating cross-border transfers reviews whether transfers to U.S. processors are covered by DPF certification of the recipient, whether SCCs are in place for transfers to processors in non-adequate, non-DPF-certified recipients, and whether the transfer impact assessment (TIA) required by Schrems II has been completed for transfers to jurisdictions where government access to personal data creates meaningful risk to EU data subjects.
Records of processing activities and DPIA advisory
GDPR Article 30 requires controllers with 250 or more employees (or controllers whose processing is likely to result in a risk to data subjects, processing of special category data, or non-occasional processing) to maintain Records of Processing Activities (ROPA). The ROPA must contain: the name and contact details of the controller and DPO; the purposes of the processing; a description of the categories of data subjects and categories of personal data; the categories of recipients to whom the personal data has been or will be disclosed (including recipients in third countries); transfers to third countries and the safeguards; envisaged time limits for erasure; and, where possible, a general description of the technical and organizational security measures.
The retained data privacy consultant maintaining or advising on the ROPA treats it as a living compliance document rather than a one-time project output. The ROPA requires updating when: new processing activities are introduced (new SaaS tools onboarded, new marketing analytics platforms, new HR systems); existing processing activities change in material ways (new data categories collected, retention periods changed, new third-country transfers introduced); processing activities are discontinued (data deleted or transferred to a different system, contracts terminated); and the basis for cross-border transfers changes (processor DPF certification expires, SCC modules updated). The retained consultant evaluates the client’s change management process to ensure that procurement, IT, and marketing teams notify the privacy function when new data processing activities are introduced, rather than relying on annual ROPA audits that may miss changes made during the year.
Data Protection Impact Assessment (DPIA) is required by GDPR Article 35 before processing that is likely to result in a high risk to the rights and freedoms of natural persons, given the nature, scope, context, and purposes of the processing. Article 35(3) specifies three mandatory DPIA triggers: systematic and extensive profiling with significant effects on individuals; large-scale processing of special category data or criminal conviction data; and systematic monitoring of publicly accessible areas on a large scale. The EDPB Guidelines 9/2022 on records of processing activities extend the analysis using nine criteria established by the Working Party 29: evaluation or scoring; automated decision-making with legal or similar significant effects; systematic monitoring; sensitive data or data of a highly personal nature; data processed on a large scale; matching or combining datasets from separate controllers; data concerning vulnerable data subjects; innovative use or applying new technological solutions; and data transfers outside the EEA. A processing activity that meets two or more of these criteria is generally considered likely to result in high risk requiring a DPIA. The retained consultant advising on DPIA requirements evaluates each new processing activity against the applicable DPA’s published list of processing types requiring DPIAs (required under Article 35(4)) and the nine EDPB criteria, and issues a written pre-screening memo documenting whether a DPIA is required and, if so, the scope of the required assessment.
Case study: A global HR technology company providing talent management software to enterprise clients in the EU retained a data privacy consultant to conduct a quarterly compliance review. At the Q3 review, the consultant identified that the company had onboarded a workforce analytics product in May that used predictive scoring to rank candidates for promotion by analyzing performance review data, sales data, and communication pattern metadata from email and calendar systems. The consultant applied the EDPB Article 35(4) pre-screening checklist: the processing involved evaluation or scoring (candidate ranking, criterion 1), automated decision-making with significant effects (promotion recommendations used by HR managers, criterion 2), systematic monitoring of communication patterns (email metadata analysis, criterion 3), and large-scale processing of a sensitive data subcategory (health-related absence data was included in the performance review data, criterion 4). Four criteria met — DPIA required. The consultant also identified that the processing activity had not been added to the ROPA because the product onboarding had been handled by the company’s product team without notifying the privacy function. The consultant issued a written advisory identifying: (1) DPIA required before the processing could lawfully continue for EU data subjects; (2) ROPA update required to add the workforce analytics processing activity; (3) privacy notice update required to add the workforce analytics purpose and the legal basis (legitimate interests, requiring a legitimate interests assessment); (4) Article 28 DPA review required for the workforce analytics vendor, whose sub-processor list had not been reviewed for the four months since onboarding. The advisory prevented a situation where an EU DPA audit would have found an undisclosed high-risk processing activity operating without a DPIA for four months.
CCPA/CPRA compliance advisory
CCPA/CPRA compliance advisory is the retainer function that evaluates the client’s compliance with the California Consumer Privacy Act (Cal. Civ. Code §1798.100 et seq.) as amended by the California Privacy Rights Act, advising on consumer rights program structure, opt-out mechanism adequacy, GPC signal compliance, and CPPA regulatory developments between CPPA enforcement inquiries.
Consumer rights program: CCPA Section 1798.100 to 1798.125
The CCPA grants California consumers six primary rights with respect to personal information collected by covered businesses: the right to know (Section 1798.100 — the right to know what personal information is collected, used, disclosed, and sold, and to receive specific pieces of personal information upon request); the right to delete (Section 1798.105); the right to correct (Section 1798.106, added by CPRA); the right to opt-out of sale or sharing (Section 1798.120); the right to limit use of sensitive personal information (Section 1798.121, added by CPRA); and the right to non-discrimination (Section 1798.125). The CCPA applies to for-profit businesses that do business in California and meet one of three thresholds: annual gross revenue above $25 million; buying, selling, or sharing the personal information of 100,000 or more consumers or households; or deriving 50% or more of annual revenue from selling or sharing consumers’ personal information.
Sale vs. sharing is the CPRA-introduced distinction that most significantly expands the opt-out right. Under the original CCPA, only the “sale” of personal information (exchange for monetary or other valuable consideration) triggered the opt-out right. CPRA added “sharing,” defined as disclosing personal information to a third party for cross-context behavioral advertising, whether or not money changes hands. The practical effect is that a business that allows third-party advertising pixels (Google Ads, Meta Pixel) to collect personal information from its website visitors for behavioral advertising purposes is “sharing” personal information under CCPA/CPRA, even if no direct payment is made to the business for the disclosure. The retained consultant evaluates whether the client’s privacy notice uses the combined “Do Not Sell or Share My Personal Information” designation (required by CPRA for businesses that sell or share), whether the opt-out mechanism on the business’s website actually prevents third-party pixel data collection upon opt-out (a technical compliance requirement, not just a disclosure obligation), and whether the client’s vendor management program treats advertising technology vendors as “third parties” for sharing purposes or incorrectly classifies them as “service providers.”
Sensitive personal information is a CPRA-added category under Section 1798.121 that includes Social Security numbers, driver’s license numbers, precise geolocation, racial or ethnic origin, religious beliefs, union membership, genetic data, biometric data, health information, sex life or sexual orientation, and account credentials. Consumers have the right to direct a business to limit the use and disclosure of sensitive personal information to purposes reasonably necessary to provide the requested goods or services. A business that uses sensitive personal information for purposes beyond service delivery — including inferring consumer characteristics, profiling, or advertising — must provide a “Limit the Use of My Sensitive Personal Information” link on its homepage. The retained consultant evaluates whether the client’s data inventory has identified all sensitive personal information categories collected or processed, whether the “Limit” link is required and if so is implemented correctly, and whether the client’s data use practices for sensitive categories are limited to CPPA-approved purposes under 11 CCR §7027(m).
Global Privacy Control signal compliance
The Global Privacy Control (GPC) is a browser-based signal that users can enable to communicate their opt-out of sale or sharing preference to websites automatically, without the user having to click a “Do Not Sell or Share” link on each site. Under CPPA regulations 11 CCR §7025(b)(3), a business must treat a GPC signal from a California consumer as a valid opt-out of sale or sharing of personal information. The CPPA has made GPC signal compliance an active enforcement priority: in 2023, the CPPA issued enforcement notices against several companies for failing to honor GPC signals, and the CPPA’s 2024 Annual Report identified GPC non-compliance as among the most common sources of enforcement inquiries.
The retained consultant advising on GPC compliance evaluates the technical implementation on the client’s website: whether the client’s consent management platform (CMP) or tag management system is configured to detect the GPC signal (typically implemented in the browser as navigator.globalPrivacyControl === true), whether detection of the signal triggers suppression of all third-party advertising technology pixels and cookies, and whether the opt-out is persistent across sessions for authenticated users. Common GPC compliance failures include: CMP platforms that detect the GPC signal but apply it only to “targeting cookies” categories and not to analytics or measurement pixels that also constitute “sharing” under the broad CPRA definition; tag management configurations where the GPC detection fires after advertising pixels have already loaded on the page (requiring the pixel to fire before suppression takes effect); and mobile app implementations where the GPC signal is not honored because the app does not implement a GPC detection mechanism equivalent to the browser signal.
Consumer rights request handling and timing
CCPA Section 1798.130(a)(2) requires a business to respond to a verified consumer request within 45 days of receipt. The business may take an additional 45 days when reasonably necessary, provided the consumer is notified within the first 45-day period. The response must confirm the categories and specific pieces of personal information the business has collected about the consumer (for right to know requests), confirm deletion of the personal information or explain the applicable exception (for right to delete requests), correct the inaccurate personal information or explain why correction is not required (for right to correct requests), and confirm that the business has opted the consumer out of sale or sharing (for right to opt-out requests).
Verification requirements under CCPA Section 1798.130(a)(2) require the business to verify the consumer’s identity before responding to right to know or right to delete requests (not required for right to opt-out requests). The verification method must match the sensitivity of the information requested: for requests to know specific pieces of personal information, the CPPA regulations at 11 CCR §7060 require a higher level of verification (three or more pieces of verifying information matching the business’s records, or a signed declaration under penalty of perjury) than for requests to know categories only. The retained consultant evaluating the client’s consumer rights request handling procedure reviews the verification method used for each request type, confirming that the verification level applied matches the CPPA regulation requirements for the specific information requested.
Authorized agent requests under CCPA Section 1798.130(a) allow a consumer to designate an authorized agent to submit requests on their behalf. The business may require the authorized agent to provide written permission signed by the consumer, or may require the consumer to directly verify their identity with the business, even where the agent submits the request. The retained consultant evaluates whether the client’s consumer rights intake procedure has a documented process for authorized agent requests and whether the verification requirements applied to agent-submitted requests are consistent with CPPA guidance.
Data breach response advisory
Data breach response advisory is the retainer function that evaluates the client’s incident response plan against GDPR and US state breach notification requirements, advises on the risk assessment and notification timeline analysis when a potential breach occurs, and reviews the breach notification content against applicable legal requirements.
GDPR Article 33 breach notification advisory
GDPR Article 33 requires a controller to notify the competent supervisory authority (the DPA of the controller’s lead establishment under the one-stop shop mechanism, or the DPA of each affected member state for purely local controllers) without undue delay and, where feasible, not later than 72 hours after becoming aware of a personal data breach — unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Article 34 separately requires notification to affected data subjects without undue delay when the breach is likely to result in a high risk to their rights and freedoms.
Becoming aware is the trigger for the 72-hour clock, and its determination is the most time-sensitive element of GDPR breach response. A controller is considered to have become aware when it has a sufficient degree of certainty that a security incident has occurred that has led to the compromise of personal data. The EDPB guidelines on personal data breach notification (WP 250, adopted 2017, revised 2022) indicate that a controller should not wait until it has complete certainty about a breach before beginning the notification assessment — the 72-hour clock begins when the controller has reasonable grounds to believe that a personal data breach has occurred, even if the full scope is not yet known. The retained consultant advising on a potential breach evaluates the evidence available at the time of the assessment against the EDPB’s “sufficient degree of certainty” standard, issues a written awareness determination with a timestamp for the start of the 72-hour clock, and advises on whether the available evidence supports a conclusion that the breach is unlikely to result in risk to data subjects (the threshold that would exempt the controller from Article 33 notification).
Risk assessment under Article 33(1) and the EDPB’s four-factor risk framework evaluates: the nature of the personal data and the categories and approximate number of data subjects affected; the likely consequences of the breach for the data subjects; and the severity of the consequences. The four factors in the EDPB’s risk matrix are: type of breach (confidentiality breach, integrity breach, or availability breach); nature, sensitivity, and volume of personal data (special category data, financial data, or less sensitive data, combined with the volume of records affected); ease of identification of individuals (whether the data allows direct or indirect identification); and severity of consequences (financial harm, physical harm, reputational harm, or discrimination risk). The retained consultant applies the EDPB’s risk assessment framework to each specific breach scenario and produces a written risk assessment memo documenting the analysis and the notification threshold determination.
US state breach notification law advisory
The United States does not have a federal data breach notification law for non-healthcare, non-financial personal information. Instead, 50 states and several territories have enacted individual breach notification laws with varying definitions of covered data, triggering thresholds, notification timelines, and notification content requirements. The retained consultant advising on a multi-state breach evaluates the applicable laws based on the states of residence of affected individuals and identifies the most stringent notification obligations that will govern the breach response.
California AB 1130 (2019) expanded California’s breach notification law (Cal. Civ. Code §1798.82) to cover passport numbers, tax identification numbers, unique biometric data, and health insurance information as categories of personal information whose unauthorized acquisition triggers notification. California’s breach notification law requires notification to affected California residents “in the most expedient time possible and without unreasonable delay,” which the California Attorney General has interpreted as within 30 days in most cases. California law also requires notification to the California Attorney General if the breach affects more than 500 California residents.
New York SHIELD Act (2020) extended New York’s breach notification law to cover businesses that own or license computerized data including private information of New York residents, regardless of whether the business is located in New York. The SHIELD Act also requires businesses to implement a data security program with reasonable administrative, technical, and physical safeguards. New York’s definition of private information includes biometric data, email addresses combined with passwords or security questions, and account credentials — categories not covered under the original New York breach notification law.
Texas HB 4390 (2023) requires covered entities to notify the Texas Attorney General of a breach affecting 250 or more Texas residents within 30 days of discovery (reduced from 60 days under prior law). Texas law requires notification to the Texas AG in addition to individual notification to affected residents. The retained consultant tracking multi-state breach notification obligations maintains a current reference for the notification timelines, triggering thresholds (some states require notification only when the breach affects more than a minimum number of residents, others require notification for any breach regardless of scale), and regulator notification requirements for all 50 states, and applies that reference to each specific breach to produce a multi-state notification obligation matrix.
Case study: A mid-market financial services company retained a data privacy consultant after experiencing a ransomware incident in which the attacker accessed a file server containing customer account data for approximately 8,200 customers, including names, addresses, and account numbers. The incident occurred on a Thursday at 11:45 PM when the security monitoring system generated an alert about unusual file access on the server. The security team confirmed by 9:00 AM Friday that unauthorized access to the file server had occurred and that customer data files had been accessed and exfiltrated. The retained consultant was notified at 9:15 AM Friday. The 72-hour GDPR clock started at 9:00 AM Friday (the moment the controller became aware of the breach), meaning the Article 33 notification to the competent DPA was due by 9:00 AM Monday. The consultant’s Friday advisory covered four parallel tracks: (1) GDPR risk assessment — the breach involved financial account data (higher sensitivity category), approximately 8,200 data subjects, direct identification from the data, and meaningful risk of financial harm from fraudulent account access; the consultant determined that Article 33 notification was required (not exempted by the “unlikely to result in risk” exception) and that Article 34 data subject notification was required based on the likelihood of high risk from financial harm. (2) US state notification matrix — customer address data identified residents in 14 states; the consultant produced a notification matrix covering timelines, AG notification obligations, and content requirements for all 14 states, identifying California (30 days, AG notification required for 8,200 affected residents), New York (expedient notification, no minimum threshold), and Texas (30 days, AG notification required) as the three states with the most specific regulatory requirements. (3) Article 33 notification content — the consultant drafted the supervisory authority notification under Article 33(3): the nature of the breach (unauthorized access and exfiltration), categories and approximate number of affected data subjects (approximately 8,200), categories and approximate number of records concerned (name, address, account number), name and contact details of the DPO, description of likely consequences, and description of measures taken and proposed to address the breach. (4) Breach documentation — documented all available evidence for the internal Article 33(5) breach register (required for all personal data breaches regardless of whether notification is required). The consultant submitted the Article 33 notification to the DPA Sunday evening, within the 72-hour window, and coordinated the multi-state notification schedule across the 14 states with varying deadlines.
Why data privacy consultant retainer hours are invisible between DPA audits and breach notifications
DPA investigations and data breach notification events are visible regulatory milestones with formal inquiry letters, notification deadlines, and enforcement outcomes. What is invisible to the company’s privacy team, legal counsel, or CFO between those events are the advisory hours that maintain the compliance program: the quarterly ROPA review that added the HR analytics platform to the processing register when it was onboarded, three months before the DPA inquiry requested the ROPA; the annual privacy notice adequacy review that identified the missing legal basis specification for the workforce analytics processing before the data subject complaint was filed; the processor agreement review that caught a sub-processor addition without prior notice within the 30-day objection window rather than after the window expired; the DPIA pre-screening that identified a high-risk processing activity requiring a DPIA before the activity went live; and the CCPA consumer rights request procedure review that identified two overdue right-to-know requests before the CPPA enforcement inquiry arrived.
The invisibility problem in data privacy advisory retainer relationships is structural: the highest-value advisory work occurs before the regulatory events that generate visible compliance outcomes. A ROPA update that adds a new processing activity within the month it is onboarded produces a revised ROPA spreadsheet that is filed in the privacy program documentation. Its value — avoiding a finding that the ROPA was incomplete when the DPA audit requested it — is only visible in retrospect when the audit produces no adverse finding on ROPA completeness. A processor agreement review that catches a sub-processor notification gap within the 30-day objection window produces a written review memo and a client directive to the processor. Its value is the absence of a processor agreement non-compliance finding in a DPA investigation that would have found the unauthorized sub-processor engagement.
The billing problem is compounded by the regulatory density of data privacy advisory deliverables. A privacy notice adequacy review references specific GDPR article numbers, EDPB guidelines, and DPA guidance documents from the ICO, CNIL, and other national authorities. A DPIA pre-screening memo references Article 35(4) DPA lists for the applicable jurisdiction, EDPB Guidelines 9/2022, and the nine-criterion analysis with documentation of each criterion’s applicability. A multi-state breach notification matrix references specific statutory citations for all 14 applicable state laws, notification timelines, content requirements, and AG notification thresholds. None of that technical work appears on an invoice as anything other than “data privacy advisory — 6 hours” without a structured work log that captures which regulatory framework was applied, which specific article or statute was analyzed, what was found, and what advisory was issued.
HourTab is a retainer hours dashboard designed for advisory relationships like data privacy consulting retainers where client value is created between the visible milestones of DPA investigations and breach notifications. The retained data privacy consultant logs hours against specific tasks — ROPA update for a specific new processing activity, privacy notice adequacy review for the Q3 update cycle, processor agreement review for a specific new vendor, DPIA pre-screening for the workforce analytics product, CCPA consumer rights request handling review for Q2 — with technical notes identifying the regulatory framework applied, the specific article or statute analyzed, the finding, and the advisory direction. The consultant shares a public URL that gives the company’s privacy officer or general counsel a running view of hours balance and work log between audit cycles and enforcement events, without requiring a client login or portal account. The ROPA update that added the HR analytics platform becomes a work log entry: the processing activity description, the data categories added, the legal basis identified, and the retention period specified. The advisory hour is no longer invisible.
Setting up a data privacy consultant retainer agreement
A data privacy consultant retainer agreement should define the scope with enough specificity to distinguish routine advisory tasks included in the monthly retainer — privacy notice adequacy review, processor agreement review, ROPA maintenance advisory, DPIA pre-screening, consumer rights request handling review, GPC compliance review — from activities that require separate scoping: full DPIA preparation (not just pre-screening), regulatory enforcement response (DPA investigation response preparation, regulatory correspondence, hearing representation), litigation support and expert testimony, privacy program implementation projects (consent management platform deployment, data mapping campaigns), and cross-border transfer impact assessments for high-risk third-country transfers.
A well-structured data privacy consultant retainer specifies:
Services covered: GDPR compliance advisory including privacy notice Article 13/14 adequacy review (quarterly or triggered by material changes), Article 28 processor agreement review (for new or renewed agreements), Article 30 ROPA maintenance advisory (monthly or triggered by new processing activities), Article 35 DPIA pre-screening for new high-risk processing activities; CCPA/CPRA compliance advisory including consumer rights request handling procedure review (quarterly), opt-out mechanism and GPC signal compliance review (quarterly), sensitive personal information use review, and CPPA regulatory development monitoring; data breach response advisory including annual incident response plan review against GDPR Article 33 and applicable US state notification law requirements, and advisory support during actual breach assessment events.
Applicable regulatory frameworks: GDPR (EU) 2016/679, Articles 5 (principles), 6 (lawful basis), 9 (special categories), 13-14 (transparency), 17 (erasure), 25 (data protection by design and default), 26 (joint controllers), 28 (processors), 30 (records), 32 (security), 33-34 (breach notification), 35 (DPIA), 37-39 (DPO); EDPB Guidelines 07/2020 (consent), 05/2020 (consent mechanisms), 09/2022 (data subject rights), WP 250 (breach notification); Cal. Civ. Code §§1798.100–1798.199.100 (CCPA/CPRA); 11 CCR §§7000–7306 (CPPA regulations); applicable US state breach notification statutes for all 50 states and territories.
Deliverables: quarterly privacy notice adequacy memo (GDPR Articles 13/14 analysis against published processing activities and EDPB lawful basis guidance); processor agreement review memo (Article 28 mandatory provisions checklist, TOM adequacy evaluation, sub-processor management mechanism review, cross-border transfer mechanism identification); monthly ROPA update record (new or changed processing activities documented with legal basis, data categories, retention period, and transfer mechanism); DPIA pre-screening memo (nine-criterion analysis per EDPB Guidelines 09/2022, DPA list check, DPIA requirement determination); quarterly CCPA/CPRA consumer rights request handling review (timeline compliance audit, verification procedure review, opt-out mechanism technical check, GPC signal compliance review); annual incident response plan review (GDPR 72-hour clock analysis, US state notification matrix, notification content template review).
Rates: Privacy professionals with CIPP/US or CIPP/E certification and 3 to 7 years of experience typically bill at $120 to $190 per hour. Senior privacy attorneys and CIPP/E-credentialed consultants with 8 or more years of GDPR and CCPA specialty experience typically bill at $200 to $350 per hour. External DPOs serving as the designated Article 37 DPO of record typically bill at $250 to $400 per hour or at a fixed monthly DPO retainer rate.
Monthly retainer: $3,000 to $12,000 per month depending on the number of jurisdictions covered (GDPR only, CCPA only, or multi-jurisdiction), the volume of processor agreements requiring review, the number of new processing activities introduced each quarter, and whether the DPO designation service is included. A single-jurisdiction SaaS company with EU data subjects only, a manageable processor ecosystem of 20 to 30 vendors, and no DPO designation service may structure a $3,000 to $5,000 monthly advisory retainer. A global B2B company with GDPR obligations, CCPA obligations, 80 or more active vendor agreements, regular product launches introducing new processing activities, and an external DPO designation requirement will typically structure a $7,000 to $12,000 monthly retainer covering all three advisory tracks with monthly and quarterly deliverables.
HourTab turns a time-tracker CSV into a public retainer-hours URL your client can bookmark. No client login. No portal setup. Start free →