Discipline

Data Protection

Learn what you process and what follows from it, get help building the system, and have it audited

ISO/IEC 277016 modules · 2 tracks

Privacy obligations met in the processes that carry them

Work from the processing you actually do: which role you hold in it, what it creates for the people behind the data, and which controls and rights-handling routines follow. ISO/IEC 27701 is the frame; the obligations come from the law that applies to you.

Overview

Privacy starts with knowing what you process

Privacy work goes wrong at the start, in the mapping. An organisation that cannot say which processing it does, in which role, and on whose behalf, cannot answer a data subject, assess a transfer, or judge whether a new AI feature is lawful. Everything downstream inherits that gap.

Closing that gap is connective tissue rather than a policy set: records that are maintained rather than reconstructed, assessments reopened when a purpose changes, and rights handling that does not depend on one person knowing where things are. In Switzerland the law behind it is rarely only the GDPR, which is one more reason the mapping has to be yours rather than a template's.

Professional tracks

Build role-specific expertise

All tracks →

Halderstone tracks follow a modular structure. They first establish a strong, role-specific foundation across disciplines, which is then applied to the chosen discipline.

Training modules

Deepen your expertise

All modules →

Each module can be taken on its own and trains the calls a practitioner has to make without being prompted. These are the modules that teach this discipline; the cross-discipline core that every track shares is in the catalogue.

Advisory

Build and improve your privacy programme

Learn more →

We help organisations translate data protection requirements into workable governance, roles, processes and controls. This includes privacy management structures, risk-based assessments, operational integration across the data lifecycle, and documentation that supports accountability, regulatory expectations and sustainable compliance in day-to-day practice.

The four phases below are the life of a management system, and an engagement can begin at any one of them.

  1. 01

    Design

    Establishing clear data protection governance and accountability

    Data protection governance framework and policy design

    Definition of roles and responsibilities (e.g. controller, processor, DPO)

    DPIA methodology and risk classification

    Design of data inventories and processing records

    Integration into existing management systems and governance structures

    Design of documentation and evidence structures

  2. 02

    Operate

    Embedding data protection into daily practice

    Execution of Data Protection Impact Assessments (DPIAs) and risk assessments

    Operational processes for data protection lifecycle management

    Handling of data subject requests

    Incident and breach handling processes

    Supplier onboarding and data processing agreements and controls

    Enablement of key roles (management, legal, IT, business)

  3. 03

    Assure

    Providing confidence and audit readiness

    Independent reviews of data protection governance

    Compliance and implementation effectiveness checks

    Review of Data Protection Impact Assessments (DPIAs) and other documentation

    Supplier and third-party data protection reviews

    Preparation for internal and external audits or regulatory reviews

  4. 04

    Evolve

    Keeping data protection effective as requirements and practices change

    Monitoring regulatory developments and guidance

    Maturity assessments and improvement roadmaps

    Integration of new use cases and technologies

    Scenario analysis for cross-border data processing

    Executive sparring on strategic data protection decisions

Audit

Assess your privacy programme

Learn more →

A privacy programme audit follows the risk to people rather than the paperwork: whether that risk drives the controls, whether the controls survive a change of purpose or supplier, and whether the reviews would find a gap before a data subject does.

Supported frameworks

EU GDPR

Swiss Federal Act on Data Protection (FADP)

ISO/IEC 27701

ISO/IEC 27001 and ISO/IEC 27002

NIST Privacy Framework

Organisation-specific privacy and data protection frameworks

Free · no obligation

Thirty minutes to understand your situation and what you are trying to achieve. No preparation needed on your side.

Length
30 minutes
Where
Video call · link sent by email
Afterwards
Possible next steps, in writing

Prefer to write instead?

Pick a timeYour details

Times shown in
Zurich

The calendar cannot be reached just now. Please send a written brief instead.

Nothing suitable?