Skip to content

Privacy and preparation

Portfolio privacy screen: checking several companies' records before a data program

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

A portfolio data privacy assessment scores each operating company separately on five things: the systems holding its records, the personal data load in those records, the notices and contracts that govern them, its incident and dispute history, and its capacity to prepare data. The output is a readiness tier per company, not one portfolio verdict.

Key takeaways

  • Score each company separately; privacy burden varies more between sister companies than most sponsors expect.
  • Personal data load depends on record family: engineering records usually carry less than dispatch or candidate records.
  • Notice history and customer contract terms can move a company down a tier faster than good systems move it up.
  • Open disputes, holds and unresolved incidents usually pause a company rather than rule it out.
  • The screen runs on questionnaires and metadata, so the sponsor never needs to see personal data.

What a portfolio privacy screen decides#

A portfolio privacy screen decides, company by company, whether records can be brought to a releasable state at a reasonable preparation cost. It complements a data opportunity screen, which asks whether records are valuable; the privacy screen asks what it would take to share them responsibly.

The screen runs on questionnaires and metadata, not files. Each company's COO, IT lead or controller answers questions about systems, record types, notices and history, and counsel reviews the answers that touch legal exposure. The sponsor sees scores and notes, never the underlying personal data.

Running it before a program launches saves the most effort. A company that looks attractive on record quality can turn out to need months of notice archaeology, and finding that early lets the operating partner start with companies that can move.

The five scorecard dimensions#

The five dimensions below cover what most often decides a company's readiness. Rate each one as lower, moderate or higher burden, and keep a short note explaining the rating so another reviewer can follow it.

Keep the questions identical across companies. Comparable answers matter more than detailed ones at this stage, and unknowns should be recorded as unknown rather than guessed.

The five scorecard dimensions
DimensionWhat to collectLower burdenHigher burden
SystemsNamed systems, years of accessible history, export routesFew systems with documented exportsMany acquired or retired systems with unclear access
Personal data loadRecord families and the personal details they carryEngineering, quality or order recordsCandidate, household or email-heavy records
Notices and contractsPrivacy policy history, employee notices, customer data termsArchived notices and standard customer termsMissing history or customer clauses barring secondary use
Incidents and disputesIncident log, notifications, holds, regulator contactNo open mattersActive holds or unresolved incidents
Preparation capacityOwner, IT support, existing toolingNamed owner with IT timeNo owner and no technical support

Rating personal data load by record family#

Personal data load depends more on record family than on company size. A software company's code reviews and issue histories mostly carry employee names, while a home services company's job records carry homeowner names, addresses, access instructions and phone numbers on nearly every line.

Burden is not a verdict. A higher-burden family can still be prepared, but it needs more review, a narrower scope or exclusions, and that cost reduces the net value of the program for that company.

Rating personal data load by record family
Record familyTypical personal detailsUsual burden
Code reviews, issues and engineering ticketsEmployee names, occasional customer emails in bug reportsLower
Quality, NCR and maintenance recordsInspector and technician namesLower
Orders, shipments and exceptionsCustomer contacts, delivery addresses, driver namesModerate
Support tickets and CRM historiesCustomer contact details and free-text narrativeModerate
Job, dispatch and service records for householdsHomeowner names, addresses, access notes, phone numbersHigher
Email archivesEverything above, plus signatures and attachmentsHigher
Applicant and candidate recordsResumes, contact details and assessmentsHigher

Questions that move a company between tiers#

A handful of questions move a company between tiers more than any others. Ask them the same way in every company, and route the answers to counsel rather than resolving them inside the operating team.

Answers to these questions often sit with people who have left. When a founder, a former controller or an outsourced IT provider set up the original notices, check the deal files and the website platform's revision history before marking an answer unknown.

  • Which privacy policy versions applied when the records in scope were created, and are they archived?
  • Did any notice or customer contract promise not to share or reuse data beyond providing the service?
  • Do employee notices cover internal records such as email, chat and tickets?
  • Has the company sent breach notifications or received regulator inquiries, and are they closed?
  • Are any records under a litigation hold or subject to a protective order?
  • Did an add-on acquisition bring records collected under another company's notices?

Readiness tiers and what each one means#

Readiness tiers turn the scorecard into a decision the sponsor can act on. Keep the tier definitions fixed across the portfolio so companies are compared on the same scale, and record the single biggest reason for each tier.

Tiers are not permanent. A company on hold can move up after archiving its notices or closing a matter, and a ready company can move down after an acquisition or a new dispute.

Readiness tiers and what each one means
TierProfileNext step
ReadyLower burden on most dimensions and a named ownerProceed to a full inventory and rights review
ConditionalWorkable with exclusions or a narrower scopeAgree the exclusions, then inventory the remaining scope
HoldA fixable blocker, such as missing notice history or an open matterFix the blocker or wait, then rescreen
OutRecords dominated by high-burden personal data or barred by contractLeave out of the program and record why

Illustrative: a logistics platform screens four companies#

Illustrative: a fictional buy-and-build platform owns a 3PL, a freight brokerage acquired last year, an industrial parts distributor and a small TMS software company. The operating partner sends the same questionnaire to each COO and asks outside counsel to review the notice and incident answers.

The TMS software company rates Ready: issue histories and code reviews in Jira and GitHub, archived notices and a CTO willing to own preparation. The distributor also rates Ready on Epicor order and exception records with light personal data. The 3PL rates Conditional because its help desk tickets carry consignee names and addresses, so ticket narrative is scoped in and contact fields are excluded.

The brokerage rates Hold. Its records were collected under the seller's privacy policy, which nobody archived, and its carrier and driver records carry personal details. The platform starts with the two Ready companies and asks counsel to resolve the brokerage's notice question before rescreening it.

How SourceX applies a privacy screen across a portfolio#

SourceX runs each portfolio company as its own transaction under the SourceX five-step transaction: Supply, Rights, Preparation, Approval and Delivery. The initial fit check is metadata-only for every company, and each supplier entity approves its own scope.

The SourceX Enterprise Data Value Framework counts privacy burden and preparation cost as the drivers that lower net value, while human-generated signal, domain expertise and rights are among the drivers that raise it. A privacy screen is how those reducing drivers are estimated early, before any company spends effort on preparation.

Frequently asked questions

Who should fill in the scorecard for each company?

The COO or IT lead usually answers the systems and record questions, the controller or general counsel answers notice, contract and incident questions, and the sponsor's counsel or an outside privacy advisor reviews the legal answers. The operating partner owns the comparison across companies.

Does a past breach rule a company out?

Not usually. A closed incident with documented fixes often has little effect on readiness. Open investigations, unresolved notifications or ongoing disputes are different and generally place a company on hold until they are resolved.

Do add-on acquisitions inherit the platform's privacy notices?

Not automatically. Records collected by an acquired company were gathered under that company's notices and contracts, which may still govern them. Screen add-ons as separate entities until counsel confirms how the legacy promises apply.

How often should the screen be refreshed?

Refresh it when something changes: an acquisition, a system migration, a new privacy policy, a dispute or a sale process. Rescreening a single company is quick once the questionnaire exists, so there is little reason to wait for a portfolio-wide cycle.

Can the sponsor require companies to take part?

Governance documents and management agreements vary, and each company's leadership and authorized signer still approve any license of its records. Most programs work better when companies opt in after seeing a pilot succeed at a sister company.

Should the screen include companies heading to a sale?

Yes, with a different purpose. For a company heading to sale, the screen doubles as preparation for buyer privacy diligence, while starting a license mid-process can complicate it. Many sponsors screen such companies but defer any licensing decision until the sale timeline is clear.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify