Purpose
Ninety days is enough to move from "we don't really know what we have" to a defensible, documented privacy baseline — not a mature program, but a foundation that can withstand a regulator inquiry, a due-diligence questionnaire, or an actual incident. This roadmap breaks the work into three phases with weekly outputs, owner roles, dependencies and success measures.
It assumes a small team, even one person plus willing stakeholders. Use the Data Inventory and RoPA Starter Kit, Vendor Privacy Assessment Template, Data Breach Response Checklist and Microsoft 365 Sensitive Data Checklist as the working templates behind the steps below. For grounding, see Global Data Privacy Fundamentals; for build-out, Practical Privacy Program Implementation; if AI tools are in scope, AI Privacy and Data Readiness. Consider the assessment first to identify which phase matters most for you.
How to use it
Treat week numbers as a sequencing guide, not a rigid deadline. What matters most is order: you cannot build a credible rights-request workflow or breach plan before you know what data lives where.
Phase 1: Establish (Days 1–30)
Goal: know what you have, who owns it, and where questions go.
| Week | Output | Owner | Dependencies |
|---|---|---|---|
| 1 | Sponsorship confirmed; scope defined (entities, jurisdictions, systems, data subjects) | Program lead + sponsor | None |
| 2 | Interview plan for the ten highest-volume processes; interviews begin | Program lead + process owners | Scope agreed |
| 3 | Draft inventory populated for interviewed processes, using the starter kit | Program lead | Interviews underway |
| 4 | Single intake route published for privacy questions and rights requests | Program lead + IT | Sponsorship helpful, not required |
Success measures: ten+ processes documented with a named owner each; the intake route has been used at least once; the sponsor can describe scope in one sentence.
Phase 2: Build (Days 31–60)
Goal: turn documentation into working processes.
| Week | Output | Owner | Dependencies |
|---|---|---|---|
| 5–6 | Inventory extended to remaining priority systems, including collaboration platforms (see the Microsoft 365 checklist) | Program lead + IT | Phase 1 inventory |
| 6–7 | Rights request workflow stood up, including identity verification | Program lead + legal | Inventory shows where data lives |
| 7–8 | Breach response plan drafted using the checklist; roles assigned to named people | Program lead + security + legal | Sponsorship for assigning roles |
| 8 | Top ten vendors reviewed using the vendor template | Program lead + procurement | Inventory identifies relevant vendors |
Success measures: a test rights request is processed end-to-end; named role-holders have read the breach plan; top ten vendors have a documented risk tier.
Phase 3: Operationalise (Days 61–90)
Goal: make the baseline durable without constant manual effort.
| Week | Output | Owner | Dependencies |
|---|---|---|---|
| 9–10 | Retention position agreed per data category; enforcement points identified | Program lead + legal + IT | Inventory shows where each category lives |
| 10–11 | Vendor assessment formalised in procurement; approved-tool register created | Program lead + procurement | Phase 2 vendor review |
| 11 | Five metrics defined (e.g. rights-request cycle time, % vendors assessed, inventory freshness) | Program lead + sponsor | Working processes to measure |
| 12 | Maintenance cycle set: who reviews what, how often, what triggers an early review | Program lead + sponsor | All prior outputs |
Success measures: metrics are tracked, even manually; the tool register has a real entry; a maintenance calendar exists with named owners.
Decision points along the way
- Prioritise systems/processes with the most sensitive data or largest population, not the easiest to document.
- Escalate to legal as soon as international transfers, special-category data or a known incident surface — don't wait for the formal Phase 2 plan.
- If the inventory reveals more systems or a live gap than expected, re-scope rather than rushing later phases.
Worked example (illustrative)
A 40-person SaaS company assigns its head of operations as program lead, founder as sponsor. Phase 1 interviews reveal support tickets contain more sensitive data than expected, including occasional payment details in free-text fields. This reprioritises Phase 2: the rights-request workflow and a support-tooling fix are pulled forward, while a lower-priority vendor review moves to Phase 3. By day 90 the company has a documented inventory, a tested rights-request process, a breach plan with named roles, and a maintenance calendar — plus an open action to fix the ticket data issue. Illustrative only.
Deliverable at day 90
A defensible baseline: inventory covering priority systems, a working rights-request process, a breach plan with assigned roles, a vendor assessment process for new engagements, a documented maintenance cycle, and a prioritised gap list with owners and dates for what didn't make the first 90 days.
Maintenance and review
- Review the maintenance calendar at least annually.
- Trigger an early review on entering a new jurisdiction, launching a materially new product involving personal data, or after an incident.
- Reassess named owners after significant team turnover.
Download formats
- Guidance (Markdown .md) — this page, including the phase plan, owners and success measures.
- Print / Save as PDF — a print-friendly version for planning sessions.
Nothing here is emailed — each option downloads or prints directly from your browser.