Compliance Operations:

Build privacy into the way you work.

Policies, processes, and training that last beyond an audit.

What we deliver

A practical privacy program that connects policy to daily work: data inventory and mapping, notices and consent, DSARs and appeals, DPIAs, vendor reviews, records of processing, and role‑based training, and a compact evidence pack that sales can use.

Operational building blocks

  • Data Inventory & Mapping

    • Where personal data lives, why it’s used, and who touches it

    • Data classifications that drive proportionate controls

  • Notices & Consent

    • Clear, scannable notices and a workable consent model

    • Cookie consent with geo‑aware banners and preference center

  • DSARs & Appeals

    • Intake, identity checks, response templates, and SLA tracking

    • Appeal routes and escalation paths

  • DPIAs & Risk

    • Proportionate assessments for higher‑risk use

    • Practical mitigations documented for reviewers

  • Vendor Reviews

    • Privacy questions, red‑flag checks, and records

    • Contract levers captured for reference

  • Records of Processing Activities (RoPAs)

    • Concise entries that reflect reality

    • Ownership and review cadence

  • Training & Accountability

    • Role‑based modules and simple job aids

    • Refresher cadence that isn’t boring and that people can actually finish

Featured add-ons

  • Privacy Operations

    Get your two most visible privacy touchpoints running cleanly, with proof your buyers can verify.

    What you get
    • DSR workflow with ownership and SLA tracking
    • Identity & authorization checks sized to risk
    • Response templates and internal playbook
    • CMP setup with scans, classification, and tag governance
    • Geo‑aware banners, preference center, and GPC handling
    • Evidence pack: logs and change history

    How it runs
    1. Assess
    2. Align owners and SLAs
    3. Implement in your tools & trainings
    4. Assure via periodic checks and evidence refresh

  • External DPO (EU/UK GDPR)

    Aetos serves as your independent DPO of record.

    Includes
    • Appointment & independence check
    • Oversight of DPIAs, training, policy
    • Regulator liaison
    • Annual DPO report

    We designate a specific individual within Aetos to serve as DPO who will avoid operating day‑to‑day controls to preserve independence.

  • DPO Advisor

    Hands‑on guidance and support for your internal DPO.

    Includes
    • Monthly coaching & reviews
    • Refreshed DSAR/DPIA templates
    • Quarterly leadership summary

Artifacts buyers ask for

  • Privacy and cookie policies with last‑updated dates

  • DSAR logs and sample responses

  • DPIA template and a filled example

  • RoPA excerpts

  • Vendor privacy reviews

  • Consent scans and CMP configuration

  • Training schedule and completions

  • One‑page privacy controls overview

Not sure what your business may need?