05 / DEDICATED OFFER
Transparency Portal — Audit and Construction
A two-phase engagement: audit, then construction.
Positioning
Verb(s) mobilised: Design (primary), Secure (secondary)
Regulatory framework: RGPD Art. 12–14 (information of data subjects), Art. 30 (record of processing activities)
Priority targets: pharmaceutical companies, health startups, medical device / AI editors, health, prevention & life insurers (health data scope, strictly)
Starting point
A transparency portal is a public promise. It tells patients, policyholders or users: here is what we do with your data. That promise only has value if it has been verified beforehand — otherwise the portal becomes a false claim of control: a showcase presenting an appearance of mastery while part of the actual processing remains an unverified blind spot (rank-2 subcontracting, third-party cloud infrastructure, data reuse for model training, etc.).
Doctrine applied: proof before promise. KDPO does not draft a transparency portal from an organisation's declarative record; it verifies first what is actually under control.
The two phases
Audit
- Internal cartography of the treatments covered by the future portal (20–30 most significant processing activities)
- Classification of each treatment by actual level of control
- Isolation of blind spots — points that could not honestly be presented as controlled
- Cross-check against the existing Art. 30 record
Deliverable Audit report + control-level table + blind-spot section + prioritised levers
Construction
- Drafting of portal content based only on treatments with demonstrated control
- Differentiated treatment of partial or blind-spot items: lever activated before publication, or honest and cautious wording
- Functional specification of the portal (structure, detail level, update mechanism)
- Consistency with KDPO's design system for a web deliverable
Deliverable Portal (prototype or specification) + correspondence document mapping audit findings to published content
Not sold separately: Phase 2 is never engaged without Phase 1 — publishing without a prior audit would contradict the "proof before promise" doctrine.
What this offer is not
- Not a generic, multi-sector compliance tool — scope stays health data and KDPO's four priority sectors.
- Not a citizen information desk or an individual complaints channel — the portal informs; it does not process incoming requests from individuals.
- Not sold as construction alone without the audit phase — building a portal without a prior internal audit would contradict the "proof before promise" doctrine.
Typical output format
- Audit report (control-level table + blind spots + levers)
- Correspondence note: treatment → control status → wording chosen for the portal
- Delivered portal (HTML prototype or specification, depending on the mandate's scope)
- Follow-up sheet: which treatments still need to evolve after publication, with deadlines