Cybersecurity and Infrastructure

Data Protection and Privacy Engineering

Collecting less, holding it properly, and being able to answer what you hold about a person.

How We Work, Step by Step
  1. 1Find the data
  2. 2Classify and map
  3. 3Apply protection
  4. 4Set retention
  5. 5Handle rights requests

What We Do for You

  • Discover and classify what personal and regulated data you hold.
  • Write the retention and deletion schedule and apply it.
  • Run data protection impact assessments on high-risk processing.
  • Build the rights-request procedure and train the people who answer.
  • Configure encryption, tokenisation and loss prevention.

How this is bought: Bought as an assessment first, then a project priced from what the assessment finds. Build an estimate for your case.

Our Approaches Explained

Data classification

Sorting information into levels - public, internal, confidential, regulated - so protection matches sensitivity.

Data minimisation and retention

Collecting only what the purpose requires and deleting it on a written schedule.

Encryption in transit and at rest

TLS 1.2 or above on the wire; AES-256 or equivalent on disk, with keys held separately.

Pseudonymisation and tokenisation

Replacing identifying values with tokens so working copies carry less risk.

Data loss prevention (DLP)

Watching for regulated data leaving by email, upload or removable media.

Privacy by design and default

Privacy decided when the system is designed, with the protective setting as the starting point.

Data protection impact assessment (DPIA)

A written assessment before high-risk processing, recording risks and mitigations.

Data subject rights handling

A working process for access, correction, deletion and portability requests within the legal window.

Consent and lawful basis records

Evidence of why each category of data may be processed, and what the person agreed to.

Cross-border transfer controls

Contractual and technical measures when data moves between jurisdictions.

The Standards We Work To

GDPR and UK GDPRCCPA / CPRAHIPAA (where health data applies)PCI DSS 4.0 (where card data applies)ISO/IEC 27701 privacy information managementNIST Privacy Framework

We follow the structure and controls these standards describe. We do not claim to be certified against them - where you need a formal certificate, we prepare the evidence and an accredited body performs the audit.

What You Get

  • Data classification scheme
  • Retention and deletion schedule
  • DPIA template and first assessments
  • Rights-request procedure
  • Records of processing
Where We Usually Focus
Data stores classified88%
Retention rules written82%
Rights requests inside window94%

These are the areas clients most often ask us to improve. Your project sets its own targets, measured and agreed with you.

Ask AI what ARRIX does for Data Protection and Privacy Engineering - ARRIX

Opens your assistant with the question ready. Gemini has no pre-filled link, so we copy the question to your clipboard first.