When Elena Marsh took over group data protection at Voltaic, she inherited forty subsidiaries, eleven languages, and a record of processing that lived — charitably — in several hundred spreadsheets. “Every country had its own version of the truth,” she says. “Audit season meant flying people around to reconcile them.”

One structure for forty companies

The group started with the Privacy Flow: each subsidiary got its own workspace under a shared group structure, with roles, processing chains and responsibilities mapped exactly as they operate. Local privacy coordinators answer guided questionnaires in their own language; the group team sees completion, quality and risk in one dashboard.

  • All processing activities consolidated in eight weeks, imported from existing files.
  • Vendor reviews standardised across procurement in every country.
  • Subject-rights requests routed automatically to the right subsidiary.

The audit that finished early

The real test came with the group’s external audit. Instead of six weeks of evidence-chasing, auditors worked directly from the Privaquill workspace — versioned records, linked measures, complete history. “They finished in nine days,” Marsh says. “The lead auditor asked what system we used. That has never happened before.”

What the board sees now

Quarterly reporting went from a 60-slide deck assembled by hand to a live compliance overview: completion rates, open risks, upcoming reviews. “The board finally discusses privacy as a managed risk, not a mystery,” says Marsh. “That change alone was worth the project.”