Client Story

Global telecommunications company

Turning privacy and AI regulatory compliance into performance

A global telecommunications company operating across more than 80 countries had already built one of the strongest privacy foundations in its sector, including Binding Corporate Rules approval – a set of regulator‑approved rules that enable multinational companies to move personal data compliantly between countries.

With our support, it had deployed OneTrust – a leading provider of privacy, data governance, and compliance solutions – at scale, setting up the right architecture across the business.

The next challenge was about reducing operational friction, simplifying the privacy programme, and shifting the focus to high-risk areas. The company partnered with us and One Trust to move from compliance to performance.

We had invested significantly in our privacy programme and achieved regulatory milestones that set us apart. But after a global rollout of that scale, there is always work to do. Our risk registers needed attention, our assessments and the user experience was complex. We wanted the platform to be aligned with how the business actually operates and feel like a natural part of how people work rather than another opaque regulatory assessment. We needed a partner who understood both the ambition and the practicalities but most importantly, could navigate and deliver digitally enabled, automated, and elegant solutions.”
Global Telecommunications Company

Bringing focus back to the risk register

A global deployment at this scale inevitably generates volume. The privacy risk register had grown to an unmanageable number, mixing genuine risks with duplicates, historic findings, and items that no longer required action. As a result, the register had become an unreliable tool to facilitate decision‑making.

Taking a structured approach, our privacy and tooling experts reviewed and rationalised all open items, taking the required actions and remediation activities, and documenting a clear rationale for every decision.

We then reconfigured how risks are raised within the platform and future-proofed the model, enabling the programme to continue without re‑introducing unnecessary volume. Rather than raising risks indiscriminately, risks are now triggered only for genuinely high‑risk processing and cross‑border transfers. Lower‑risk issues are managed through task‑based workflows and resolved before assessments are completed. The result was a reduction of over 70 percent in open risk items, restoring the register as a focused, credible tool for leadership oversight and action.

Redesigning assessments around clarity and consistency

As the programme scaled globally, the assessment framework had grown complex. Multiple assessment types and expanding question sets made the process time‑consuming for business users, with overlapping themes answered more than once and declining consistency in responses.

We consolidated and simplified the assessment framework by merging overlapping assessments, removing outdated questions, and cutting the overall question volume by more than 50 percent. Key elements of the programme – such as legal basis, privacy notices, and processing purpose – were connected into a single, coherent framework, creating consistency across regions and business areas. We also leveraged conditional logic, workflows, and automation to reduce manual effort and minimise the risk of error going forward.

Privacy assessments should help people make the right decisions about data. When the process becomes a barrier, people disengage and the quality drops. Every change we made was about earning back that engagement – making every question count and giving people confidence that their time is well spent.”
Privacy and AI compliance expert, PA

Connecting privacy to the wider enterprise and leveraging AI

With the core programme running more efficiently, the next phase of the journey is focused on how OneTrust connects into the wider enterprise landscape, and how that connection can increasingly be automated and intelligent. Relevant privacy data sits across governance and risk platforms, data management systems, procurement tools, and internal applications, but has yet to flow into the platform in a consistent, structured way.

We carried out a discovery exercise across these systems, mapping data flows, assessing integration potential, and prioritising opportunities based on the value each connection unlocks. Alongside traditional integrations, we are exploring how agentic AI capabilities can help orchestrate data movement, trigger actions, reduce manual intervention, and move to a genuinely intelligent programme.

This was never a one-off implementation. We’ve worked alongside the company over time, helping their privacy programme adapt as the organisation scaled and expectations changed. Redesigning a system that people already rely on – while keeping it running – is the harder challenge, and that’s where the value was created. Together, we’re laying the groundwork for a more connected, intelligent, and future-ready privacy capability.”
Data privacy and AI governance expert, PA

Next Made Real

Build an intelligent enterprise that turns AI ambition into measurable, real-world impact.
A woman inside an indoor garden sitting down

Data privacy and ethics

Turn compliance into competitive advantage.

Bring ingenuity to your inbox.

Subscribe for the latest insights and event invites on strategy, innovation, technology, and transformation.

Explore more

Contact the team

We look forward to hearing from you.