Privacy and preparation
Portfolio privacy screen: checking several companies' records before a data program
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
A portfolio data privacy assessment scores each operating company separately on five things: the systems holding its records, the personal data load in those records, the notices and contracts that govern them, its incident and dispute history, and its capacity to prepare data. The output is a readiness tier per company, not one portfolio verdict.
Key takeaways
- Score each company separately; privacy burden varies more between sister companies than most sponsors expect.
- Personal data load depends on record family: engineering records usually carry less than dispatch or candidate records.
- Notice history and customer contract terms can move a company down a tier faster than good systems move it up.
- Open disputes, holds and unresolved incidents usually pause a company rather than rule it out.
- The screen runs on questionnaires and metadata, so the sponsor never needs to see personal data.
What a portfolio privacy screen decides#
A portfolio privacy screen decides, company by company, whether records can be brought to a releasable state at a reasonable preparation cost. It complements a data opportunity screen, which asks whether records are valuable; the privacy screen asks what it would take to share them responsibly.
The screen runs on questionnaires and metadata, not files. Each company's COO, IT lead or controller answers questions about systems, record types, notices and history, and counsel reviews the answers that touch legal exposure. The sponsor sees scores and notes, never the underlying personal data.
Running it before a program launches saves the most effort. A company that looks attractive on record quality can turn out to need months of notice archaeology, and finding that early lets the operating partner start with companies that can move.
The five scorecard dimensions#
The five dimensions below cover what most often decides a company's readiness. Rate each one as lower, moderate or higher burden, and keep a short note explaining the rating so another reviewer can follow it.
Keep the questions identical across companies. Comparable answers matter more than detailed ones at this stage, and unknowns should be recorded as unknown rather than guessed.
| Dimension | What to collect | Lower burden | Higher burden |
|---|---|---|---|
| Systems | Named systems, years of accessible history, export routes | Few systems with documented exports | Many acquired or retired systems with unclear access |
| Personal data load | Record families and the personal details they carry | Engineering, quality or order records | Candidate, household or email-heavy records |
| Notices and contracts | Privacy policy history, employee notices, customer data terms | Archived notices and standard customer terms | Missing history or customer clauses barring secondary use |
| Incidents and disputes | Incident log, notifications, holds, regulator contact | No open matters | Active holds or unresolved incidents |
| Preparation capacity | Owner, IT support, existing tooling | Named owner with IT time | No owner and no technical support |
Rating personal data load by record family#
Personal data load depends more on record family than on company size. A software company's code reviews and issue histories mostly carry employee names, while a home services company's job records carry homeowner names, addresses, access instructions and phone numbers on nearly every line.
Burden is not a verdict. A higher-burden family can still be prepared, but it needs more review, a narrower scope or exclusions, and that cost reduces the net value of the program for that company.
| Record family | Typical personal details | Usual burden |
|---|---|---|
| Code reviews, issues and engineering tickets | Employee names, occasional customer emails in bug reports | Lower |
| Quality, NCR and maintenance records | Inspector and technician names | Lower |
| Orders, shipments and exceptions | Customer contacts, delivery addresses, driver names | Moderate |
| Support tickets and CRM histories | Customer contact details and free-text narrative | Moderate |
| Job, dispatch and service records for households | Homeowner names, addresses, access notes, phone numbers | Higher |
| Email archives | Everything above, plus signatures and attachments | Higher |
| Applicant and candidate records | Resumes, contact details and assessments | Higher |
Questions that move a company between tiers#
A handful of questions move a company between tiers more than any others. Ask them the same way in every company, and route the answers to counsel rather than resolving them inside the operating team.
Answers to these questions often sit with people who have left. When a founder, a former controller or an outsourced IT provider set up the original notices, check the deal files and the website platform's revision history before marking an answer unknown.
- Which privacy policy versions applied when the records in scope were created, and are they archived?
- Did any notice or customer contract promise not to share or reuse data beyond providing the service?
- Do employee notices cover internal records such as email, chat and tickets?
- Has the company sent breach notifications or received regulator inquiries, and are they closed?
- Are any records under a litigation hold or subject to a protective order?
- Did an add-on acquisition bring records collected under another company's notices?
Readiness tiers and what each one means#
Readiness tiers turn the scorecard into a decision the sponsor can act on. Keep the tier definitions fixed across the portfolio so companies are compared on the same scale, and record the single biggest reason for each tier.
Tiers are not permanent. A company on hold can move up after archiving its notices or closing a matter, and a ready company can move down after an acquisition or a new dispute.
| Tier | Profile | Next step |
|---|---|---|
| Ready | Lower burden on most dimensions and a named owner | Proceed to a full inventory and rights review |
| Conditional | Workable with exclusions or a narrower scope | Agree the exclusions, then inventory the remaining scope |
| Hold | A fixable blocker, such as missing notice history or an open matter | Fix the blocker or wait, then rescreen |
| Out | Records dominated by high-burden personal data or barred by contract | Leave out of the program and record why |
Illustrative: a logistics platform screens four companies#
Illustrative: a fictional buy-and-build platform owns a 3PL, a freight brokerage acquired last year, an industrial parts distributor and a small TMS software company. The operating partner sends the same questionnaire to each COO and asks outside counsel to review the notice and incident answers.
The TMS software company rates Ready: issue histories and code reviews in Jira and GitHub, archived notices and a CTO willing to own preparation. The distributor also rates Ready on Epicor order and exception records with light personal data. The 3PL rates Conditional because its help desk tickets carry consignee names and addresses, so ticket narrative is scoped in and contact fields are excluded.
The brokerage rates Hold. Its records were collected under the seller's privacy policy, which nobody archived, and its carrier and driver records carry personal details. The platform starts with the two Ready companies and asks counsel to resolve the brokerage's notice question before rescreening it.
How SourceX applies a privacy screen across a portfolio#
SourceX runs each portfolio company as its own transaction under the SourceX five-step transaction: Supply, Rights, Preparation, Approval and Delivery. The initial fit check is metadata-only for every company, and each supplier entity approves its own scope.
The SourceX Enterprise Data Value Framework counts privacy burden and preparation cost as the drivers that lower net value, while human-generated signal, domain expertise and rights are among the drivers that raise it. A privacy screen is how those reducing drivers are estimated early, before any company spends effort on preparation.
Frequently asked questions
Who should fill in the scorecard for each company?
The COO or IT lead usually answers the systems and record questions, the controller or general counsel answers notice, contract and incident questions, and the sponsor's counsel or an outside privacy advisor reviews the legal answers. The operating partner owns the comparison across companies.
Does a past breach rule a company out?
Not usually. A closed incident with documented fixes often has little effect on readiness. Open investigations, unresolved notifications or ongoing disputes are different and generally place a company on hold until they are resolved.
Do add-on acquisitions inherit the platform's privacy notices?
Not automatically. Records collected by an acquired company were gathered under that company's notices and contracts, which may still govern them. Screen add-ons as separate entities until counsel confirms how the legacy promises apply.
How often should the screen be refreshed?
Refresh it when something changes: an acquisition, a system migration, a new privacy policy, a dispute or a sale process. Rescreening a single company is quick once the questionnaire exists, so there is little reason to wait for a portfolio-wide cycle.
Can the sponsor require companies to take part?
Governance documents and management agreements vary, and each company's leadership and authorized signer still approve any license of its records. Most programs work better when companies opt in after seeing a pilot succeed at a sister company.
Should the screen include companies heading to a sale?
Yes, with a different purpose. For a company heading to sale, the screen doubles as preparation for buyer privacy diligence, while starting a license mid-process can complicate it. Many sponsors screen such companies but defer any licensing decision until the sale timeline is clear.
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.