PRIVACY & DATA PROTECTION
Protect Personal Data. Prove It to Customers and Regulators.
Privacy programs built on real data flows and real controls, aligned to the regulations that apply to your business.
PRIVACY THAT CAN BE DEMONSTRATED
Build a Defensible Privacy Program Around the Data You Actually Hold.
Privacy obligations now reach almost every organization: patient records, cardholder data, employee files, customer accounts, and the vendors that process them. A patchwork of federal, state, and international rules means the question is no longer whether privacy applies to you, but which rules apply, and whether you can show you meet them.
Rosen Burke Consulting helps organizations move from uncertainty to a documented, defensible privacy program. We start by finding out where personal data actually lives and flows, then align controls, policies, and vendor practices to your obligations. The goal is a program that stands up to customer due diligence, regulatory inquiry, and an incident.
CAPABILITIES
What We Deliver
Privacy governance, technical safeguards, and regulatory readiness built around how personal data actually moves through your organization.
Data discovery and mapping
Inventory of personal and sensitive data, where it is collected, stored, shared, and retained, and who can access it.
Regulatory applicability review
Analysis of which laws and standards apply to you, such as HIPAA, GDPR, CCPA/CPRA, other state privacy laws, and PCI DSS, and what each requires.
Privacy program development
Governance, roles, policies, notices, consent practices, retention schedules, and data subject request procedures.
Privacy and security control assessments
Evaluation of technical and administrative safeguards against frameworks such as the NIST Privacy Framework, NIST SP 800-53, ISO/IEC 27701, and HIPAA Security and Privacy Rules.
Payment data protection
Scoping and safeguards for cardholder data environments, with QSA-level knowledge of PCI DSS v4.0.1.
Third-party and processor oversight
Data processing agreements, vendor privacy reviews, and cross-border transfer considerations.
Incident and breach readiness
Response plans, notification decision trees, and tabletop exercises aligned to applicable notification requirements.
Privacy impact assessments
Structured review of new products, systems, and AI tools before launch.
OUR PROCESS
How We Work
01
Discover
We map data, systems, vendors, and current practices through interviews and document review.
02
Assess
We compare what you do today with what the applicable laws and standards require, and rate each gap by risk.
03
Build
We develop the policies, procedures, and controls needed, and help your team put them into practice.
04
Sustain
We set up monitoring, training, and periodic review so the program keeps pace with your business and the law.
WHO WE SERVE
Privacy Readiness for Regulated and Data-Driven Organizations.
Healthcare practices and their business associates, retailers and service providers that accept card payments, SaaS and technology companies handling customer data, and organizations preparing for enterprise or government due diligence.
WHY ROSEN BURKE CONSULTING
Privacy and Security Managed as One Program.
- Depth in both privacy and security, so policies match the controls that actually exist.
- Direct experience with PCI DSS, HIPAA, HITRUST, SOC 2, and ISO 27001 environments.
- Plain-language guidance that business leaders, legal counsel, and engineers can all use.
- SBA-verified SDVOSB with a track record of supporting enterprise and government clients.
COMMON QUESTIONS
Frequently Asked Questions
Not Sure Which Privacy Requirements Apply to You?
Schedule a free consultation and we will help you map your obligations.