Enterprise AI, cybersecurity, cloud and software for organizations worldwide.
Retail

Protection for the customer data a retailer holds.

F Creative Studio 360 helps retailers in any country see what customer information they keep, who can reach it, and what a breach would require. The privacy law is the one that applies to those customers.

Trust is the data, not the slogan.

A retailer may be subject to the GDPR, the CCPA, or, where Australian law applies, the Privacy Act and the Notifiable Data Breaches scheme. Card data, where you store it, also brings PCI DSS.

F Creative Studio 360 reviews the controls. We do not decide if a person or a regulator must be told. Counsel does.

More than the checkout
Loyalty, marketing lists, returns and the suppliers who host them hold personal information too.
The law follows the customer
Selling into a country can create a duty there, even when the company is incorporated somewhere else. We do not give that legal opinion. Counsel does.
Access and copies
Former staff, agencies and unused exports are a common path out.
We do not notify
We can establish what left. The organisation sends any required notice.

What the review covers

The brands and countries you name.

What you collect
Account, order, loyalty and support data, and where each copy sits.
Who can use it
Staff, stores, agencies and platforms.
Suppliers
Parties that process customer information for you.
If it leaves
The factual record a counsel would need. Not the notice itself.

How an engagement runs

Shops and sites can be in different countries. The review follows the data.

  1. 1

    Name the brands

    And the countries whose customers are in scope.

  2. 2

    Map the copies

    Including marketing tools and backups.

  3. 3

    Review access

    Authorised testing is separate.

  4. 4

    Hand back the order

    What to close, without a claim that every privacy law is met.

What you receive

  • A map of consumer-data stores in scope.
  • An access and supplier review.
  • A note of which laws were treated as in scope, and which were not.
  • No regulatory notice filed by F Creative Studio 360.

Card data is separate

If the question is the card number rather than the customer profile, start with PCI DSS and payment security.

Common questions

Is this only the Australian Privacy Act?+

No. Retailers in any country are in scope. The Act and the NDB scheme are used when they apply. Other privacy laws are used when they apply.

Will you tell customers about a breach?+

No. We help establish the facts. The retailer and its counsel decide and send any notice.

Where do you deliver this?+

For organisations in any country. A local rule is used only when that organisation is actually subject to it. F Creative Studio 360 does not limit the work to one jurisdiction.

How much does it cost, and how long does it take?+

It depends on the systems in scope and whether you want an assessment only or help afterwards. A scoping conversation with F Creative Studio 360 is the way to get a quote. There is no obligation to proceed.

List the copies before the policy.

F Creative Studio 360 will look at the brands and the systems, then say what the review includes.