Get licensed, appoint your DPO, and show POTRAZ your paperwork when they ask.

From “we should probably do something about this” to licensed, documented and defensible.

A consultant and an administrator working through a binder of records together

What this is

You already look after people’s information carefully. What the Act adds is the duty to prove it: a licence, a named officer, a register of what you hold, notices that say what you do with it, and a plan for the day something goes wrong. That is paperwork with a purpose, and we do it with you rather than to you.

We start with a gap assessment in plain language: where you stand against the Act and SI 155 of 2024, what is missing, and what closing each gap costs. You get the report whether or not you go further.

Then we build what is missing. Where the rules require a Data Protection Officer, we can act as yours on a retainer or prepare the person you nominate. Everything we write is written for your staff to follow, not for a shelf.

Who asks for it

Clinics and medical practicesSchools and collegesLaw and accounting firmsMicrofinance and SACCOsNGOsRetail and property

What you get

  • Gap assessment with a prioritised, costed plan
  • POTRAZ data controller licence application, submitted and tracked
  • Data Protection Officer: outsourced, or your nominee trained and registered
  • A register of what you hold, why, where and who can see it
  • Privacy notices, consent forms and policies people can read
  • Impact assessments before you buy or build a new system
  • A one-page breach plan and the 24-hour notification playbook
  • Cloud, vendor and cross-border transfer review
  • An annual review so it still holds next year

How it runs

Four stages. You see each one before the next starts.

STAGE 1Discover

We walk your systems and paperwork with you. What data, where it lives, who touches it. No policy is written before the map exists.

STAGE 2Assess

Every gap scored against the Act, with an owner, a priority and a fixed price to close it.

STAGE 3Build

Licence, DPO, register, notices, breach plan. Written for your organisation, in your language.

STAGE 4Embed

Staff briefing, DPO handover or retainer, and a review date in the calendar.

Questions

What clients ask about this one.

We are a small practice. Does this really apply to us?

Yes. The Act attaches to anyone who decides why and how personal data is used, regardless of size. A clinic with patient files, a school with pupil records or a shop with a customer database is a data controller and needs a licence and a DPO.

Can our office manager be the DPO?

Often, yes. The DPO must complete accredited training and be registered with POTRAZ, and they need enough time and authority to do the job. We prepare your nominee and support them. Where nobody suitable exists, we act as your DPO.

How long does licensing take?

A focused small organisation can be documented and ready to apply within a few weeks. Larger organisations with many systems take longer, and we phase the work so the highest-risk gaps close first.

Start with a 20-minute call.

Tell us what you hold and what is worrying you. No charge, no obligation, and you leave knowing what data protection & privacy would involve for you.