Skip to content

Privacy Operations · Guide

Privacy Program 90-Day Roadmap

A week-by-week 90-day plan for standing up a defensible privacy baseline, with phase outputs, owners, dependencies and success measures.

Purpose

Ninety days is enough to move from "we don't really know what we have" to a defensible, documented privacy baseline — not a mature program, but a foundation that can withstand a regulator inquiry, a due-diligence questionnaire, or an actual incident. This roadmap breaks the work into three phases with weekly outputs, owner roles, dependencies and success measures.

It assumes a small team, even one person plus willing stakeholders. Use the Data Inventory and RoPA Starter Kit, Vendor Privacy Assessment Template, Data Breach Response Checklist and Microsoft 365 Sensitive Data Checklist as the working templates behind the steps below. For grounding, see Global Data Privacy Fundamentals; for build-out, Practical Privacy Program Implementation; if AI tools are in scope, AI Privacy and Data Readiness. Consider the assessment first to identify which phase matters most for you.

How to use it

Treat week numbers as a sequencing guide, not a rigid deadline. What matters most is order: you cannot build a credible rights-request workflow or breach plan before you know what data lives where.

Phase 1: Establish (Days 1–30)

Goal: know what you have, who owns it, and where questions go.

WeekOutputOwnerDependencies
1Sponsorship confirmed; scope defined (entities, jurisdictions, systems, data subjects)Program lead + sponsorNone
2Interview plan for the ten highest-volume processes; interviews beginProgram lead + process ownersScope agreed
3Draft inventory populated for interviewed processes, using the starter kitProgram leadInterviews underway
4Single intake route published for privacy questions and rights requestsProgram lead + ITSponsorship helpful, not required

Success measures: ten+ processes documented with a named owner each; the intake route has been used at least once; the sponsor can describe scope in one sentence.

Phase 2: Build (Days 31–60)

Goal: turn documentation into working processes.

WeekOutputOwnerDependencies
5–6Inventory extended to remaining priority systems, including collaboration platforms (see the Microsoft 365 checklist)Program lead + ITPhase 1 inventory
6–7Rights request workflow stood up, including identity verificationProgram lead + legalInventory shows where data lives
7–8Breach response plan drafted using the checklist; roles assigned to named peopleProgram lead + security + legalSponsorship for assigning roles
8Top ten vendors reviewed using the vendor templateProgram lead + procurementInventory identifies relevant vendors

Success measures: a test rights request is processed end-to-end; named role-holders have read the breach plan; top ten vendors have a documented risk tier.

Phase 3: Operationalise (Days 61–90)

Goal: make the baseline durable without constant manual effort.

WeekOutputOwnerDependencies
9–10Retention position agreed per data category; enforcement points identifiedProgram lead + legal + ITInventory shows where each category lives
10–11Vendor assessment formalised in procurement; approved-tool register createdProgram lead + procurementPhase 2 vendor review
11Five metrics defined (e.g. rights-request cycle time, % vendors assessed, inventory freshness)Program lead + sponsorWorking processes to measure
12Maintenance cycle set: who reviews what, how often, what triggers an early reviewProgram lead + sponsorAll prior outputs

Success measures: metrics are tracked, even manually; the tool register has a real entry; a maintenance calendar exists with named owners.

Decision points along the way

  • Prioritise systems/processes with the most sensitive data or largest population, not the easiest to document.
  • Escalate to legal as soon as international transfers, special-category data or a known incident surface — don't wait for the formal Phase 2 plan.
  • If the inventory reveals more systems or a live gap than expected, re-scope rather than rushing later phases.

Worked example (illustrative)

A 40-person SaaS company assigns its head of operations as program lead, founder as sponsor. Phase 1 interviews reveal support tickets contain more sensitive data than expected, including occasional payment details in free-text fields. This reprioritises Phase 2: the rights-request workflow and a support-tooling fix are pulled forward, while a lower-priority vendor review moves to Phase 3. By day 90 the company has a documented inventory, a tested rights-request process, a breach plan with named roles, and a maintenance calendar — plus an open action to fix the ticket data issue. Illustrative only.

Deliverable at day 90

A defensible baseline: inventory covering priority systems, a working rights-request process, a breach plan with assigned roles, a vendor assessment process for new engagements, a documented maintenance cycle, and a prioritised gap list with owners and dates for what didn't make the first 90 days.

Maintenance and review

  • Review the maintenance calendar at least annually.
  • Trigger an early review on entering a new jurisdiction, launching a materially new product involving personal data, or after an incident.
  • Reassess named owners after significant team turnover.

Download formats

  • Guidance (Markdown .md) — this page, including the phase plan, owners and success measures.
  • Print / Save as PDF — a print-friendly version for planning sessions.

Nothing here is emailed — each option downloads or prints directly from your browser.