Privacy Policy + Terms of Service Drafting
PDPA + GDPR + CCPA + COPPA + LGPD multi-jurisdiction · For New SaaS / app launch · Website redesign · Funding due diligence
Any organisation processing personal data (controller/processor) needs Privacy Policy + Terms of Service Drafting — NYC Legal's Privacy Counsel team holds CIPP/E + CIPM credentials and runs end-to-end.
500+ compliance programs delivered — covering PDPA, GDPR, CCPA, PIPL, LGPD, PIPA, APPI, DPDPA.
Privacy Policy + Terms of Service Drafting takes 7-21 working days at 25,000-85,000 บาท — includes gap analysis + drafting + implementation + training + ongoing support.
We coordinate with PDPC Thailand, EDPB and destination DPAs across Schrems II adequacy jurisdictions.
Privacy program coverage: PDPA Pack · GDPR Pack · CCPA · DPO · DPIA · ROPA · SCC/BCR · Breach · CMP · DSAR · Privacy Policy · ISO/IEC 27701.
95% DSAR backlog reduction — automated DSAR portal + 30-day SLA + audit trail.
Coverage
How it works
- 1
Data discovery + mapping
System audit + data-owner interviews + identification of processing activities + data-flow diagram.
- 2
Gap analysis + risk
Map against PDPA/GDPR/CCPA + risk register + DPIA for high-risk processing.
- 3
Drafting + controls
Draft policies + procedures + DPA + consent + security controls per NIST SP 800-53 / ISO 27001.
- 4
Implementation + training
Roll out CMP/DSAR portal + train DPO + staff awareness + privacy-by-design checklist.
- 5
Audit + ongoing support
Annual audit + monthly DPO report + breach drills + ROPA refresh + DPA inspection prep.
Frequently asked questions
Who needs Privacy Policy + Terms of Service Drafting?
New SaaS / app launch, Website redesign, Funding due diligence and any organisation processing personal data.
Total cost?
25,000-85,000 บาท, scaling with size and number of processing activities.
Timeline?
7-21 working days — faster if ISO 27001 baseline exists.
Is a DPO mandatory?
PDPA Sec. 41 mandates DPOs for public authorities, large processors, and sensitive data — GDPR Art. 37 mirrors the trigger.
Can we notify PDPC within 72 hours?
Triage likelihood + severity within 24h → notify decision within 72h — Tier-1 incident runbook included.
What is required for cross-border transfers?
PDPA Sec. 28: SCC, BCR, adequacy, consent, or derogation — we draft SCC + TIA.
DSAR SLA?
GDPR 30 days (extend 60) · PDPA 30 days · CCPA 45 days (extend 90) — DSAR portal tracks all.
Does ISO 27701 require ISO 27001?
Yes — 27701 is an extension of 27001 (combined implementation 9-12 months).