How we work

Four phases, twelve steps, twenty deliverables

Every engagement follows the same shape. You always know what is happening now, what is next, and what evidence exists at the end of each phase.
Weeks 0–2
Engage
Confidential discovery, scoping, a registration-threshold assessment, contracting, and formal designation of the Data Protection Officer with the National Privacy Commission.
Weeks 2–8
Plan
A compliance gap assessment against the five NPC pillars, a department-by-department data inventory, Privacy Impact Assessments on your highest-risk systems, and a prioritized treatment plan.
Months 2–6
Implement
Build and land the program: governance, the manual, notices, consent, data subject rights, vendor and sharing contracts, the retention schedule, breach readiness, NPC registration and staff training.
Continuous
Monitor
Run the program: 72-hour breach readiness, data subject request handling, register maintenance, quarterly reporting to management, the annual audit, the Annual Security Incident Report, registration renewal, and tracking every new NPC issuance.

Weeks 0–2

At the end of Engage, you have

  • Signed engagement
  • Board resolution and designation letter
  • NPC filing confirmation
  • Kickoff plan

What you end up holding

Twenty templates, drafted to your operations. Every one of them carries your name and logo, not ours — a Privacy Manual with a consultant's branding on it reads as an off-the-shelf purchase rather than the organization's own policy, which is exactly the wrong impression to give a regulator.

Engage

  • Client discovery questionnaire
  • Proposal and scope of work
  • DPO-as-a-Service agreement
  • Mutual non-disclosure agreement
  • DPO designation pack — board resolution, secretary’s certificate, designation letters
  • Onboarding and kickoff checklist

Plan

  • Client compliance workbook — gap assessment, records of processing, risk register, retention schedule, vendor register, request and incident logs, roadmap, calendar
  • Privacy Impact Assessment template
  • Privacy Management Program and roadmap

Implement

  • Privacy Manual
  • Privacy notices and consent pack
  • Data subject rights procedure and forms
  • Breach response plan and notification templates
  • Data sharing and outsourcing agreements
  • Privacy awareness training pack

Monitor

  • Internal privacy audit checklist
  • Quarterly DPO report to management
  • Sector overlays

The gap assessment

Seventy-two controls, scored across the five NPC pillars, producing a weighted maturity score and a heat map showing where you are weakest. It is the document the whole roadmap is built from, and it is the one that tends to change how seriously an organization takes this.

The audit tests evidence, not intention. An unevidenced yes is a no.

The first two phases are largely free

Discovery, the NDA, the scoping call and the written fixed-fee proposal cost nothing. You only commit once you have the proposal in front of you.

Nexthread Solutions is an information technology solutions provider for both hardware and software needs. Current as of July 27, 2026. Reviewed quarterly, and on each new NPC issuance.