EU · UK · Australia · India
Customers and staff in four countries. One programme, not four.
One set of records, notices, procedures and contracts that meets the data protection laws of every country where you have customers or staff, built once with a country annex for each, and kept current in the platform after we hand over.
One core programme, four annexes, each with written applicability reasoning
- EU core programme
- Records, notices, DPIAs, processor agreements
- Built
- UK annex
- Representative decision, IDTA, ICO fee
- Extended
- Australia annex
- APP applicability, notifiable data breaches, local counsel
- Extended
- India annex
- DPDP consent notices, fiduciary obligations, local counsel
- Extended
Who this is for
Companies with people in more countries than their privacy documents cover.
A fit
- A SaaS company headquartered in one country with customers in the EU and the UK and an engineering team in India.
- A company expanding into Australia that already holds a GDPR programme and needs it extended, not rebuilt.
- A company whose enterprise customers in several countries each send a different privacy questionnaire and expect consistent answers.
Also a fit
- A company preparing for a funding round where privacy due diligence covers every market it sells in.
- A team that received a rights request from a country it had not thought about.
- A company that wants to start with two countries and add the others as it expands.
Not a fit
- Organisations that need a Data Protection Officer, EU or UK representative or Indian consent manager appointed. We help you decide and appoint; we do not take the roles.
- Countries other than the EU, the UK, Australia and India. Ask on the call; other countries are quoted separately with local counsel.
- Companies looking for formal legal opinions only. Local counsel gives the opinion in each country; the implementation is the service.
What you walk away with
Built once on the strictest shared requirement, adapted where the laws diverge.
Every deliverable is editable and yours, inside the platform or exported as DOCX, CSV and PDF.
Multi-country privacy programme
11 deliverables, 8 to 10 weeksGlobal data inventory and data flow map by country
Systems, flows, recipients, with country tags
- CSV
Applicability analysis per country with written reasoning
GDPR, UK GDPR, Australian Privacy Act, DPDP Act
- DOCX
Records of processing with country tags
Purposes, lawful grounds, retention, per jurisdiction
- CSV
Layered privacy notices with country-specific sections
Customers, website visitors, candidates, staff
- DOCX
- HTML
Consent and lawful ground design
Including DPDP consent notices and APP collection notices
- DOCX
Cross-border transfer map and transfer tools per route
SCCs, IDTA or UK Addendum, APP 8 accountability
- CSV
- DOCX
Country annexes for the EU, the UK, Australia and India
Each with regulator, deadlines, roles and local positions
- DOCX
Rights request and breach procedures with per-country deadlines
72 hours, eligible data breaches, Board notification, in one flow
- Procedure
Local counsel opinions for Australia and India where required
From lawyers admitted there, scheduled in parallel
Evidence that each document is in use
Linked to the record it supports
- Platform
Recorded hand-over and readiness sign-off
With whoever owns the programme afterwards
- Video
How it works
Ten weeks to hand-over. Then a country is added, not a programme.
Local counsel opinions run in parallel and are scheduled in the plan.
- GRCTrail
- Hand-over
- Without us
Week 0
Scoping call
Countries where you have customers, users, staff and vendors; what exists. Written fixed price within 3 business days.
Weeks 1 to 2
Assessment
Data inventory by country, applicability analysis for each law, review of any existing programme. Local counsel scoped. Implementation price confirmed.
Weeks 3 to 9
Implementation
Core documents, country annexes, notices, consent design, transfer tools, procedures. Local counsel opinions in parallel. Two review sittings with your team.
Week 10
Hand-over
Notices published, annexes signed off, recorded hand-over, readiness sign-off.
When you expand
A new country
A new annex on the same core, quoted as an extension. The records and notices already carry the structure.
Every year
Reviews and law changes
DPDP rules phased in, UK amendments, APP reforms tracked. Notices reviewed. In GRCTrail or in your export.
How we price
What moves the price
Three things we ask about on the call.
How many countries, and which.
The EU core is the base; each annex adds applicability work, and Australia and India add local counsel.
What already exists.
A GDPR programme means the core is reviewed and extended rather than written.
Your role and your data.
Controllers with staff in several countries need more notices and consent design than processors.
Never in our price, named in the quote so you can budget
- Acting as your Data Protection Officer, EU representative, UK representative or Indian consent manager
- Countries other than the EU, the UK, Australia and India; quoted separately
- Formal legal opinions beyond those listed; local counsel is named in the quote
- Penetration testing
Questions before the call
Why do you engage local counsel for Australia and India?
Because a formal legal opinion on Australian or Indian law has to come from a lawyer admitted there. We build the programme. Local counsel confirms the positions that need confirming, and their cost is named in the quote.
Is India's DPDP Act in force?
The Act was passed in August 2023 and its rules are being brought into force in stages. The assessment records which obligations apply at the time of the engagement, and the programme is built to the full Act so that later stages need no rework.
Does the Australian Privacy Act apply to a company with no office in Australia?
It can. Organisations that carry on business in Australia and collect or hold personal information there have an Australian link. Small business exemptions exist but do not cover every case. The assessment gives you a written answer.
Can we start with two countries and add the others later?
Yes. The core documents are built once, and each country is a separate annex. Adding a country later is quoted as an extension, not a new programme.
How do the four laws differ?
They share the same shape: a lawful ground, transparency, security, rights and breach notification. They differ in the grounds they accept, the role of consent, transfer rules and the regulator. The programme is built on the strictest shared requirement and adapted per country where the laws diverge.
Last reviewed: October 2026
Tell us where your customers, staff and vendors are.
You leave the call with a scope and an indicative range. The written fixed price follows within 3 business days.