Layer 1
Privacy Officer as a Service (POaaS)
$21,450

Fractional Privacy Officer
&
Ad-hoc Privacy Helpdesk

Fractional Privacy Officer


Privacy compliance has become increasingly important in today's business landscape, spurred by increased risks of data breaches, continually evolving privacy laws and regulations, and extraterritorial application of foreign privacy regulations like GDPR and CCPA. Now, the Australian Government are excellerating plans to amend the Australian privacy laws implementing 116 proposed changes closely aligned to stringent foreign regimes like the GDPR. We are seeing indications of a broader domestic and global trend towards stringent privacy regulations. As a result, many companies are recognising the need to prioritise privacy and data protection compliance.

While large organizations can afford dedicated Chief Information Security Officers (CISOs) to tackle these challenges, smaller companies often lack the resources. Virtual Chief Information Security Officers (vCISOs) offer a cost-effective solution for smaller businesses, providing expert security guidance on an as-needed basis. However, it's crucial to note that vCISOs, and CISOs, primarily focus on cyber security and may not address privacy compliance adequately.

This is where the Fractional Privacy Officer comes in, a role distinct from CISOs and vCISOs. Fractional Privacy Officers are responsible for managing various privacy tasks, including reporting, data inventories, compliance with privacy laws, privacy impact assessments, and third-party privacy and data protection due diligence and management. Unlike vCISOs, Fractional Privacy Officers specialise in privacy compliance, ensuring that companies adhere to privacy laws and regulations effectively safeguarding consumer information and trust.


Privacy compliance is essential due to the constantly evolving legal landscape, with new laws and regulations emerging regularly. Failure to comply with these regulations can result in severe consequences, making the role of a Fractional Privacy Officer indispensable. By proactively managing privacy compliance, Fractional Privacy Officers help companies navigate complex privacy requirements and mitigate potential risks.

In contrast to Data Protection Officers (DPOs) mandated by GDPR, Fractional Privacy Officers have a broader focus, encompassing all privacy laws and regulations, not just one regulation. While DPOs primarily oversee GDPR compliance, Fractional Privacy Officers manage privacy compliance across various laws and regulations, ensuring comprehensive coverage across the full spectrum of a company's business activities and data exposures.

As privacy regulations continue to evolve, companies must prioritise privacy compliance to avoid legal repercussions and protect customer data. Hiring a Fractional Privacy Officer offers a strategic solution for managing privacy compliance effectively, regardless of the company's size or resources. With their expertise and tailored approach, Fractional Privacy Officers play a crucial role in strengthening privacy programs and ensuring regulatory compliance in today's privacy-centric environment.

Once a company engages our Fractional Privacy Officer solution, the workflow will follow a defined process:


Subscriptions renew monthly until cancelled. One month written notice is required to cancel monthly subscriptions.

The Fractional Privacy Officer solution does not include incident or data response services or work relating to large projects or complex issues (typically requiring more than 4hrs effort on a single enquiry or relating to: machine learning, facial recognition, artificial intelligence, data breach response, insurance claims, or disputes & litigations).

All prices are in AUD excluding GST.

Ad-hoc Privacy Helpdesk


In addition to the Fractional Privacy Officer subscription model, AB offers a Privacy Helpdesk service as a once-off purchase of a block of hours to support the privacy needs of businesses that don't require a dedicated Fractional Privacy Officer.

Privacy Helpdesk hours cannot be used on include data breach / incident response services or work relating to large projects or complex issues (typically requiring more than 4hrs effort on a single enquiry or relating to: international privacy law, machine learning, facial recognition, artificial intelligence, data breach / incident response, insurance claims, or disputes & litigations).

Transparent and Flexible Pricing

Fractional Privacy Officer Plans

Billing frequency

Foundations Package

$1,700 / month
1Privacy Package - Foundations (SME)
  • Privacy Policy updates/drafting and 1 round of editing by a privacy lawyer
  • Data Breach Response Plan template, guidance, and 1x review
  • Collection Notices and Consent Forms
  • General ad-hoc privacy enquiries (up to 4 hours per month)


Advanced Package

$4,500 / month
1Privacy Package - Mature (SME)
  • Everything in Established plus:
    • Model Data Processing Agreement (DTA): Controller - Processor
    • Business Continuity Plan template, 1 hr workshop, and 1 round of review and edits of your completed BCP
    • Privacy Impact Assessment covering 1 major system with 1 round of editing, conducted by a privacy lawyer
    • 4 additional hours per month for general ad-hoc privacy enquiries (total = 12 hours per month)


Privacy Helpdesk - Ad-hoc hours

Privacy Helpdesk
4 hours

$1,800
1Privacy Helpdesk (3 hrs / 6 mth)
  • Access to senior privacy lawyer
  • 4 hours of informal privacy advice
    • review of draft privacy documents
    • ad-hoc privacy advice
  • Hours valid to use for 12 months from date of purchase

Privacy Helpdesk hours are not usable for data breach response services or work relating to large projects or complex issues (typically requiring more than 4 hrs effort on a single enquiry or relating to: complex international or multi-jurisdictional privacy law, machine learning, facial recognition, artificial intelligence, data breach response, insurance claims, or disputes & litigations)

Privacy Helpdesk
8 hours

$3,500
1Privacy Helpdesk (6 hrs / 6 mth)
  • Access to senior privacy lawyer
  • 8 hours of informal privacy advice
    • review of draft privacy documents
    • ad-hoc privacy advice
  • Hours valid to use for 12 months from date of purchase


Privacy Helpdesk
12 hours

$5,000
1Privacy Helpdesk (12 hrs / 6 mth)
  • Access to senior privacy lawyer
  • 12 hours of informal privacy advice
    • review of draft privacy documents
    • ad-hoc privacy advice
  • Hours valid to use for 12 months from date of purchase

Benefits to your business



Get a no obligation consultation

At Albrecht Burrows, we understand the complexity and urgency of cyber and privacy risks facing businesses today. Get a no obligation consultation with our experts to better understand how your business can increase your resilience to cyber and privacy threats and regulatory risks. Our team of experienced multidisciplinary professionals will work closely with you to create personalised risk management solutions tailored to your business' unique needs needs and budget. Don't wait until it's too late – schedule your no-obligation consultation today and take proactive steps towards protecting your business from cyber threats and privacy breaches.


Testimonials

What sets AB apart is their flexible and pragmatic approach - they share our values, our DNA, and they think outside the box. The team are highly skilled commercial lawyers who possess unparalleled expertise in regulatory areas, a deep understanding of business, and exceptional negotiation skills."

Regan Carey
Head of Legal and Compliance
Craigs Investment Partners

AB offers exceptional legal advice delivered by highly skilled and brilliant lawyers who are fantastic to deal with; personable, easy to talk to and compassionate. The commerciality of their advice is matched only by their commitment to simplifying the law and finding practical, creative solutions!

Tas Demos
Managing Partner
BDH Leaders


Meet Our Team

James A. Cole

Partner | Head of Cyber & Privacy

James is a lawyer, computer scientist, and criminologist practicing in cyber and technology, data protection and privacy, data breach response, and cyber insurance. With over 25 years of experience in information security and a multidisciplinary background, James combines technical and legal expertise to help clients navigate the complex and evolving cyber and privacy landscape.

James has handled hundreds of cyber and privacy breaches and is passionate about helping businesses build resilience to cyber and privacy risks.

Mark Anderson

Legal Consultant, Lawyer (NZ)

Mark is a highly awarded legal risk adviser and barrister. He is a leading expert in a variety of legal risk areas, including cyber, privacy and technology law.

Mark has provided incident response advice globally to clients in need, including those in Europe, Australia, New Zealand and across APAC, after developing global incident response panels drawing together legal, IT, Forensic and PR professions to manage cyber crises. He has managed some of the highest profile cyber breaches in Australasia.


Case Studies

1. Financial Institution Compliance: Our hybrid computer science – legal team members helped the client successfully map their current cyber maturity level and legal obligations, establish a maturity uplift roadmap in coordination with their IT provider, and worked with their insurance broker to complete accurate proposal form responses resulting in the successfully obtaining cyber insurance coverage for an affordable premium. 2. SaaS Company AI & Facial Recognition Compliance: We helped an Australian SaaS web app maker successfully navigate the complexities of international data protection laws as they apply to biometric information in retail virtual try-on technology minimising their overall privacy and data protection risks and helping the company implement a sound multinational expansion strategy aligned to the client's risk tolerance. 3. Transport Logistics Incident Response: Working with a prominent logistics company, we provided timely and compassionate advice and assistance in responding to a devastating ransomware attack from day 1 through to full recovery and post-recovery risk mitigation successfully returning the client to normal operations in less than one week with no regulatory actions or adverse media.

Data breach emergencies

If you have experienced a data breach, whether unintential employee errors, employee data theft, or you’ve been the victim of a cyber-attack, the first 48 hours is crucial. So don’t waste any time, just get in touch.

Reach out, day or night.

If you don’t reach us straight away, we will get in touch ASAP!

Email us on [email protected]

Breach emergency Line: 02 8318 5980

woman holding silver iPhone 6



Assessment Solutions

Policy and Process

Complaints

Breach Prevention and Response

Awareness and Culture


Terms and Conditions

We are required by the Legal Profession Uniform Law (NSW) (Uniform Law) to set out the following terms of our engagement for your acceptance or further negotiation.

In these Terms, references to Albrecht Burrows, "we", "us", "our" refer to Alliance Legal Pty Ltd (ABN ) trading as Albrecht Burrows of Level 12, 111 Elizabeth Street, Sydney NSW 2000.

This document, together with our General Terms of Business, sets out the terms of our offer to provide legal services to you and constitutes our costs agreement and disclosure pursuant to the Uniform Law. The Terms and the Accepted Options in this Proposal form the entire agreement between You and Us during our engagement and any references to the "Proposal" in this document refers to both the Terms and the Accepted Option.

By accepting this Proposal as set out herein and below in the Terms, you agree that this Proposal serves as a binding Costs Agreement and Disclosure under Schedule 1 of the Legal Profession Uniform Law (NSW) between Albrecht Burrows and You for the provision of legal services and may be enforced in the same way as any other contract.


Smart Commercial Lawyers


Delivering emotionally intelligent legal solutions

ablaw.com.au | [email protected]

Reception 02 8014 2511