top of page

When a Privacy Assessment Starts Becoming Privacy Implementation

Anuuj Medirattaa
3 days ago
3 min read

A recent fintech privacy assessment reminded me that the best outcome of an assessment may not be a longer report. Sometimes, it is seeing issues being addressed before the report is even complete.


I am currently working with a fintech organization developing an application designed to analyse users' income and spending patterns.


From a privacy perspective, this is naturally an interesting application to assess. Financial information can reveal a great deal about an individual, and an application analysing such information raises important questions around what data is collected, why it is required, how users are informed and how the information is subsequently processed.


Our initial engagement was fairly straightforward: conduct a Privacy Assessment, review the organization's practices and documentation, identify gaps and provide recommendations.


But the assignment started evolving almost from the beginning.


We Didn't Wait for the Final Report

As part of the assessment, I started raising questions about some of the existing practices and documentation.


Some required corrections. Others needed reconsideration from a privacy perspective. And some observations had implications for the application being developed.


What impressed me was what happened next.


The organization did not treat these observations as findings to be collected and addressed after receiving the final assessment report.


The team started working on them in parallel.


Documentation was corrected. Practices were reviewed. Discussions took place around the changes required in the application itself.


Consequently, by the time our assessment reached the actual application, several matters that could have appeared as findings in the final report had already been discussed or were being addressed.


The Assignment Had Quietly Changed

At some point, I realised that what had started primarily as a Privacy Assessment was gradually becoming something broader.


We were no longer simply assessing the current position and documenting gaps.

Assessment and implementation had started happening together.


I find this particularly encouraging because privacy assessments can easily become point-in-time exercises:


Assess

Document

Submit the report

Then start remediation.


There is nothing inherently wrong with that approach. Sometimes that separation is necessary.


But when an organization is still developing a product, there is an opportunity to do things differently.


If an issue is identified today and the product team can address it while the application is still being built, why wait for it to become a finding in a final report?


There Are Practical Advantages

Working this way can have several benefits.


Less rework later.Changing a process or application while it is being developed can be considerably easier than correcting it after deployment.


Assessment becomes more useful.The objective shifts from merely identifying gaps to actually improving privacy practices.


Privacy enters product discussions earlier.Developers, business teams and those responsible for privacy start discussing the same issues rather than privacy becoming a final compliance check.


Documentation and reality can evolve together.Policies and notices are more useful when they reflect what the application actually does, rather than being created independently and reconciled later.


The final report can become more meaningful.Instead of simply recording every issue discovered during the journey, it can reflect the organization's improved position and highlight matters that genuinely remain to be addressed.


Commitment Does Not Need to Wait for a Deadline

One aspect of this engagement that I particularly appreciate is the seriousness with which the organization has responded.


There may still be regulatory timelines available for organizations to prepare for India's evolving data protection requirements.


But an organization does not need to wait until the last possible date to start building better privacy practices.


In fact, an application that is still under development presents one of the better opportunities to ask privacy questions.

Why are we collecting this information?

Does the user understand what we are doing with it?

Do we really require every data element being requested?

Does our documentation accurately describe what happens inside the application?

Who will have access?

What happens to the information later?


These questions are much easier to address when they are part of the development conversation rather than an audit afterthought.


A Different Way to Look at Privacy Assessments

This experience has reinforced something for me.


The value of a Privacy Assessment should not be measured by the number of gaps we manage to put into a report.


A better measure may be how many meaningful improvements the assessment initiates.

In this engagement, I am grateful that the organization has been willing to discuss observations openly and, more importantly, act on them quickly.


What began as an assessment is gradually becoming a privacy implementation journey.


And perhaps that is exactly what a good assessment should sometimes achieve.



This article is based on my experience from an ongoing privacy engagement. Certain details have intentionally been generalized to protect client confidentiality.


Anuuj Medirattaa

Founder & CTO, Ace Data Devices Pvt Ltd

Ace Data works with organizations on Privacy Assessments, DPDP readiness, privacy governance and practical implementation of data protection requirements.


bottom of page