This Privacy Policy was last updated on 24th November 2025.

BH Consulting Privacy Policy

Introduction

BH Consulting takes the protection of your personal data seriously. This Privacy Policy describes how we respect your rights and process your data. We process all data in compliance with applicable data protection laws including the Data Protection Acts 1988 to 2018 (as amended) and Regulation (EU) 2016/679, known as the General Data Protection Regulation (GDPR) (collectively referred to as “Data Protection Laws”). 

For information on how we collect, store and use information gathered through our website (www.bhconsulting.ie), please refer to the Cookies Policy.

BH Consulting is a professional services firm specialising in Cyber Security and Data Protection services. We assist organisations in achieving compliance with data protection and cybersecurity frameworks, including ISO 27001 and ISO/IEC 27701, and in meeting the requirements of the GDPR, the EU AI Act, and related legislation. We process information including personal data when we provide these services. We act as a Data Controller in respect of the personal data we process, unless otherwise agreed.

Contact Details
Data Protection Officer
BH Consulting
The Linc, TUD Blanchardstown
Dublin 15, D15VPT3, Ireland
Email: dpo@bhconsulting.ie

Depending on the engagement or interaction, BH Consulting may process the personal data of:

The table below summarises the types of personal data we process, the reasons for processing, and the lawful bases relied upon:

Personal DataPurpose of ProcessingLawful Basis
Name, contact details, email address, telephone numberTo respond to enquiries, provide requested information, or communicate with you regarding our services.Legitimate interest (business communications)
Name, business contact information, and professional detailsTo perform and manage our professional services engagements, including project delivery and client support.Performance of contract
Name, email address, and consent preferencesTo send newsletters, event invitations, or updates where you have opted in.Consent
Employee or applicant information (CVs, qualifications, references)Recruitment, human resources administration, and employment management.Performance of contract / Legal obligation
Technical data from website and cookiesTo analyse website usage, improve functionality, and maintain cybersecurity.Legitimate interest / Consent (for non-essential cookies)
Name, address, PPS number, or compliance documentationTo meet our legal obligations under Irish and EU legislation, including anti-money-laundering or tax laws.Compliance with a legal obligation

We do not collect special categories of personal data about you unless you have asked us to or provide it as part of the agreed services.

Where personal data is required by law or contract and you fail to provide it when requested, BH Consulting may be unable to enter into or perform the relevant contract or engagement. In such cases, we will notify you promptly.

We may sometimes share your data with a third party to supply services on our behalf such as our website, marketing, cloud and IT vendors.. In some cases, the third parties may require access to some of your data. Where any of your data is required for such a purpose, we will take all reasonable steps to ensure that your data will be handled safely, securely, and in accordance with your rights. 

BH Consulting uses reputable service providers, including cloud and IT vendors, some of whom may process data outside Ireland Standard Contractual Clauses. Where personal data is transferred outside the EEA, BH Consulting ensures equivalent protection of your information by using legally approved mechanisms such as Standard Contractual Clauses (SCCs), or by relying on countries recognised by the European Commission as providing adequate protection.

BH Consulting does not knowingly collect personal data from children under 16 years of age. Our services and website are not directed at children. If you are under 16, please do not provide personal data through our website. Parents and guardians are encouraged to monitor children’s internet use and contact us if they believe a minor has provided personal information.

BH Consulting retains personal data only for as long as necessary for the purpose it was collected or as required by applicable laws. After this period, data is securely deleted or anonymised in accordance with our Data Retention Policy.

For cookie retention periods, please refer to our Cookie Policy.

BH Consulting applies robust organisational and technical measures to protect personal data against loss, misuse, or unauthorised access. We are certified with ISO 27001 and aligned with ISO/IEC 27701.

Measures include:

While we strive to protect personal data transmitted online, no internet communication can be guaranteed to be entirely secure. Once data reaches your network, its protection becomes your responsibility.

Under the Data Protection Laws, you have the following rights (subject to legal exemptions):

How to make a request:
Please contact us at: dpo@bhconsulting.ie.
We may need to verify your identity before processing your request. We aim to respond within one month as required under the GDPR.

If you remain dissatisfied, you may contact the Data Protection Commission,
6 Pembroke Row Dublin 2, D02 X963, or www.dataprotection.ie.

From time to time, BH Consulting may use your contact information to send newsletters, event invitations, or updates about our services that we believe may interest you. You may opt out of these communications at any time by contacting info@bhconsulting.ie 

Our marketing emails may contain cookies or tracking pixels to measure engagement, in accordance with our Cookie Policy.

We may update this Privacy Policy periodically. Any significant changes will be notified through our website or, where appropriate, via direct communication.

Compare key inclusionsView full comparison
Tier Sizing & Support
ServiceFoundationStandardProfessionalScale
Typical company size1–1010–5051–150151–250
Consulting days available261224
Governance & Strategic Advisory
ServiceFoundationStandardProfessionalScale
Virtual CISO advisoryQuarterlyQuarterlyQuarterlyQuarterly
Virtual Data Protection advisoryQuarterlyQuarterlyQuarterlyQuarterly
Virtual AI Officer advisoryQuarterlyQuarterlyQuarterlyQuarterly
Board presentationAnnualTwice yearly
Board awareness / cyber-literacy trainingAnnualTwice yearly
Key industry developments briefingAnnualAnnualTwice yearlyQuarterly
Compliance & security posture dashboardAnnualAnnualTwice yearlyQuarterly
Customer Trust Pack
Customer security questionnaire supportUp to 1/yearUp to 2/yearUp to 4/yearUp to 10/year
Executive reportingMonthly
Cybersecurity — Core Assurance
ServiceFoundationStandardProfessionalScale
Cybersecurity Maturity AssessmentLite
Cybersecurity Risk Assessment
Cybersecurity Risk Register
Cybersecurity PoliciesTemplatedTailoredTailoredTailored
Third-Party Vendor Risk Register
Third-party vendor exposure analysis3/year3/year
Supplier onboarding security pack
Backup & Restore posture review
Backup / DR tabletop exerciseAnnualAnnual
Backup & restore / ransomware recovery exerciseAnnual
Identity & Access Management review
MFA & privileged-access governance
Endpoint / EDR posture reviewAnnualAnnualTwice yearlyQuarterly
Dark web / credential monitoring
Firewall Security Assessment
Technical Testing & Exposure Management
ServiceFoundationStandardProfessionalScale
Vulnerability Assessment1 item/year2 items/year4 items/year4 items/year
External attack-surface monitoring
Penetration testing1/year2/year
Microsoft 365 / Google exposure review
Microsoft 365 / Google Workspace Security Assessment
Cloud Security Posture Assessment1/year2/year
Active Directory / Entra ID review
Simulated phishing testAnnualTwice yearlyQuarterlyQuarterly
Company & employee OSINT footprint
Domain & subdomain security
DNS / certificate / CA misconfiguration checks
Impersonation & brand protection – DMARC/SPF/DKIM
Exposed management interface checks
Public secrets exposure search
Awareness, Training & People
ServiceFoundationStandardProfessionalScale
Online Security Awareness Training platform
Staff awareness newsletter
Managed Cybersecurity Awareness Programme
Lunch & Learn awareness sessions1/year2/year
Role-based training – Developers, Finance, HR etc.1 role/year2 roles/year
AI literacy / staff AI awareness training
Incident Response & Resilience
ServiceFoundationStandardProfessionalScale
Incident Response & Data Breach PoliciesTemplatedTailoredTailoredTailored
Incident Response advisory support – business hoursAdd-onUp to 8 hrsUp to 16 hrsUp to 24 hrs
Incident Response runbooks12510
Incident Response Tabletop ExerciseAnnualTwice yearly
Breach notification drafting templates – DPC/ICOTemplated
Breach notification workflow & regulator communications playbook
Cyber Resilience & Business Continuity PlanAnnual reviewFull plan
Certification & Regulatory Compliance Readiness
ServiceFoundationStandardProfessionalScale
Cyber Essentials readiness & certification supportAdd-on
Cyber Essentials Plus readiness*Add-onAdd-on
Cyber Fundamentals alignment*Add-on
ISO 27001 alignment / gap analysisAdd-onAdd-on
ISO 27001 certification readiness*Add-onAdd-onAdd-on
SOC 2 readiness*Add-onAdd-onAdd-on
NIS2 / Cyber Security and Resilience Bill scoping & gap analysisAdd-onAdd-on
DORA / FCA Rules readiness – financial services*Add-onAdd-on
Other regulatory gap analysisAdd-onAdd-onAdd-onAdd-on
Readiness and alignment services support organisations in preparing for applicable standards, regulations, and certification schemes. BH Haven does not guarantee regulatory compliance or certification.
Cyber Insurance Support
ServiceFoundationStandardProfessionalScale
Cyber Insurance readiness assessment1/year1/year1/year
Cyber Insurance renewal assistance
PCI DSS — Where Applicable
ServiceFoundationStandardProfessionalScale
PCI Self-Assessment Questionnaire support
PCI DSS Assessment
PCI Vulnerability Scan
GDPR / Data Protection
ServiceFoundationStandardProfessionalScale
GDPR / Data Protection Gap AnalysisLite
GDPR / Data Protection PoliciesTemplatedTailoredTailoredTailored
ROPA development & review
ROPA annual maintenance
DPIA support1/year2/yearUp to 5/yearUp to 10/year
Transfer Impact AssessmentAdd-onAdd-onUp to 2/yearUp to 4/year
DSAR & data-subject rights procedureTemplatedTailoredTailoredTailored
Data retention & deletion process development
Cookie scan
Website Privacy Notice review
GDPR training
AI Governance
ServiceFoundationStandardProfessionalScale
AI AssessmentLite
AI PoliciesTemplatedTailoredTailoredTailored
AI inventory & shadow-AI discovery
AI Awareness Training
EU AI Act risk classification1 system/year
ISO 42001 alignment / gap analysisAdd-on
Sector-Specific Bolt-Ons
Optional serviceFoundationStandardProfessionalScale
FinTech – CBI/FCA outsourcing & operational resilienceAdd-onAdd-onAdd-onAdd-on
Healthcare – HSE/NHS supplier assurance packAdd-onAdd-onAdd-onAdd-on
Charity – OSCR/Charity Commission data-handling guidanceAdd-onAdd-onAdd-onAdd-on
SaaS/Technology – Customer due-diligence packAdd-onAdd-onAdd-onAdd-on
Compare key inclusionsView full comparison
Tier Sizing & Support
ServiceFoundationStandardProfessionalScale
Typical company size1–1010–5051–150151–250
Consulting days available261224
Governance & Strategic Advisory
ServiceFoundationStandardProfessionalScale
Virtual CISO advisoryQuarterlyQuarterlyQuarterlyQuarterly
Virtual Data Protection advisoryQuarterlyQuarterlyQuarterlyQuarterly
Virtual AI Officer advisoryQuarterlyQuarterlyQuarterlyQuarterly
Board presentationAnnualTwice yearly
Board awareness / cyber-literacy trainingAnnualTwice yearly
Key industry developments briefingAnnualAnnualTwice yearlyQuarterly
Compliance & security posture dashboardAnnualAnnualTwice yearlyQuarterly
Customer Trust Pack
Customer security questionnaire supportUp to 1/yearUp to 2/yearUp to 4/yearUp to 10/year
Executive reportingMonthly
Cybersecurity — Core Assurance
ServiceFoundationStandardProfessionalScale
Cybersecurity Maturity AssessmentLite
Cybersecurity Risk Assessment
Cybersecurity Risk Register
Cybersecurity PoliciesTemplatedTailoredTailoredTailored
Third-Party Vendor Risk Register
Third-party vendor exposure analysis3/year3/year
Supplier onboarding security pack
Backup & Restore posture review
Backup / DR tabletop exerciseAnnualAnnual
Backup & restore / ransomware recovery exerciseAnnual
Identity & Access Management review
MFA & privileged-access governance
Endpoint / EDR posture reviewAnnualAnnualTwice yearlyQuarterly
Dark web / credential monitoring
Firewall Security Assessment
Technical Testing & Exposure Management
ServiceFoundationStandardProfessionalScale
Vulnerability Assessment1 item/year2 items/year4 items/year4 items/year
External attack-surface monitoring
Penetration testing1/year2/year
Microsoft 365 / Google exposure review
Microsoft 365 / Google Workspace Security Assessment
Cloud Security Posture Assessment1/year2/year
Active Directory / Entra ID review
Simulated phishing testAnnualTwice yearlyQuarterlyQuarterly
Company & employee OSINT footprint
Domain & subdomain security
DNS / certificate / CA misconfiguration checks
Impersonation & brand protection – DMARC/SPF/DKIM
Exposed management interface checks
Public secrets exposure search
Awareness, Training & People
ServiceFoundationStandardProfessionalScale
Online Security Awareness Training platform
Staff awareness newsletter
Managed Cybersecurity Awareness Programme
Lunch & Learn awareness sessions1/year2/year
Role-based training – Developers, Finance, HR etc.1 role/year2 roles/year
AI literacy / staff AI awareness training
Incident Response & Resilience
ServiceFoundationStandardProfessionalScale
Incident Response & Data Breach PoliciesTemplatedTailoredTailoredTailored
Incident Response advisory support – business hoursAdd-onUp to 8 hrsUp to 16 hrsUp to 24 hrs
Incident Response runbooks12510
Incident Response Tabletop ExerciseAnnualTwice yearly
Breach notification drafting templates – DPC/ICOTemplated
Breach notification workflow & regulator communications playbook
Cyber Resilience & Business Continuity PlanAnnual reviewFull plan
Certification & Regulatory Compliance Readiness
ServiceFoundationStandardProfessionalScale
Cyber Essentials readiness & certification supportAdd-on
Cyber Essentials Plus readiness*Add-onAdd-on
Cyber Fundamentals alignment*Add-on
ISO 27001 alignment / gap analysisAdd-onAdd-on
ISO 27001 certification readiness*Add-onAdd-onAdd-on
SOC 2 readiness*Add-onAdd-onAdd-on
NIS2 / Cyber Security and Resilience Bill scoping & gap analysisAdd-onAdd-on
DORA / FCA Rules readiness – financial services*Add-onAdd-on
Other regulatory gap analysisAdd-onAdd-onAdd-onAdd-on
Readiness and alignment services support organisations in preparing for applicable standards, regulations, and certification schemes. BH Haven does not guarantee regulatory compliance or certification.
Cyber Insurance Support
ServiceFoundationStandardProfessionalScale
Cyber Insurance readiness assessment1/year1/year1/year
Cyber Insurance renewal assistance
PCI DSS — Where Applicable
ServiceFoundationStandardProfessionalScale
PCI Self-Assessment Questionnaire support
PCI DSS Assessment
PCI Vulnerability Scan
GDPR / Data Protection
ServiceFoundationStandardProfessionalScale
GDPR / Data Protection Gap AnalysisLite
GDPR / Data Protection PoliciesTemplatedTailoredTailoredTailored
ROPA development & review
ROPA annual maintenance
DPIA support1/year2/yearUp to 5/yearUp to 10/year
Transfer Impact AssessmentAdd-onAdd-onUp to 2/yearUp to 4/year
DSAR & data-subject rights procedureTemplatedTailoredTailoredTailored
Data retention & deletion process development
Cookie scan
Website Privacy Notice review
GDPR training
AI Governance
ServiceFoundationStandardProfessionalScale
AI AssessmentLite
AI PoliciesTemplatedTailoredTailoredTailored
AI inventory & shadow-AI discovery
AI Awareness Training
EU AI Act risk classification1 system/year
ISO 42001 alignment / gap analysisAdd-on
Sector-Specific Bolt-Ons
Optional serviceFoundationStandardProfessionalScale
FinTech – CBI/FCA outsourcing & operational resilienceAdd-onAdd-onAdd-onAdd-on
Healthcare – HSE/NHS supplier assurance packAdd-onAdd-onAdd-onAdd-on
Charity – OSCR/Charity Commission data-handling guidanceAdd-onAdd-onAdd-onAdd-on
SaaS/Technology – Customer due-diligence packAdd-onAdd-onAdd-onAdd-on