Four phases, twelve steps, twenty deliverables
Weeks 0–2
At the end of Engage, you have
- Signed engagement
- Board resolution and designation letter
- NPC filing confirmation
- Kickoff plan
What you end up holding
Twenty templates, drafted to your operations. Every one of them carries your name and logo, not ours — a Privacy Manual with a consultant's branding on it reads as an off-the-shelf purchase rather than the organization's own policy, which is exactly the wrong impression to give a regulator.
Engage
- Client discovery questionnaire
- Proposal and scope of work
- DPO-as-a-Service agreement
- Mutual non-disclosure agreement
- DPO designation pack — board resolution, secretary’s certificate, designation letters
- Onboarding and kickoff checklist
Plan
- Client compliance workbook — gap assessment, records of processing, risk register, retention schedule, vendor register, request and incident logs, roadmap, calendar
- Privacy Impact Assessment template
- Privacy Management Program and roadmap
Implement
- Privacy Manual
- Privacy notices and consent pack
- Data subject rights procedure and forms
- Breach response plan and notification templates
- Data sharing and outsourcing agreements
- Privacy awareness training pack
Monitor
- Internal privacy audit checklist
- Quarterly DPO report to management
- Sector overlays
The gap assessment
Seventy-two controls, scored across the five NPC pillars, producing a weighted maturity score and a heat map showing where you are weakest. It is the document the whole roadmap is built from, and it is the one that tends to change how seriously an organization takes this.
The audit tests evidence, not intention. An unevidenced yes is a no.
The first two phases are largely free
Nexthread Solutions is an information technology solutions provider for both hardware and software needs. Current as of July 27, 2026. Reviewed quarterly, and on each new NPC issuance.