Direct answer
I would split the work into three buckets: non-negotiable (the minimum scope the law and the deadline require, plus the evidence an auditor will ask for), delayed (valuable work that does not depend on this year), and dropped (work whose value does not survive the capacity cut). Then I give the business a plain price list in features and quarters, not an apology. Steps 1 to 3 below make the decision; the cases after them apply the same method.
Step 1: Establish what the regulation actually requires
Ask legal for a written reading that separates "must" (obligations and dates) from "should" (best practice). Gold-plating (building beyond what the rule requires) is how a one-year project becomes two. Treat the legal reading as an input, not as engineering's own interpretation.
Step 2: Capacity arithmetic (illustrative)
A 12-person team where the regulation needs 7.5 FTE (full-time-equivalent people) leaves 12 - 7.5 = 4.5 FTE, so compliance takes 62.5% of capacity. If 1.5 of the remaining 4.5 FTE go to keeping existing systems running, new product work is 3.0 FTE, or 25% of the original team.
Step 3: Sort the work
| Bucket | Examples | Rule |
|---|
| Non-negotiable | Legally required controls by their dates; audit evidence (records that prove a control works, such as access logs); the highest-severity items in the compliance backlog | Scored by severity x likelihood |
| Delay | Features without a dated customer or revenue commitment; nice-to-have refactors | Dated revisit, not an open-ended "later" |
| Drop | Experiments with low confidence | Say so explicitly |
Scoring example (severity and likelihood each 1 to 5, illustrative):
| Item | Severity | Likelihood | Score |
|---|
| Retention cleanup job that deletes customer data on request (product ranks it a chore) | 5 | 4 | 20 |
| Access-log export for the auditor | 4 | 3 | 12 |
| Consent banner wording update | 2 | 3 | 6 |
The cleanup job looks low priority to product but scores 20, so it is protected first; the banner wording is a candidate to batch.
Applying the same method to common situations
- Conflicting requests on personal data. Legal wants data minimization (collect and keep only what you need), product wants analytics, sales wants customer-specific retention. Legal's mandatory constraints are fixed, and product and sales get the closest compliant alternative: aggregated data (totals, not individuals), anonymized data (identity removed), or opt-in (the user explicitly agrees).
- Region-specific legal rules. Build one configurable control, for example a data-location setting per region, instead of one code fork per region.
- High-value feature competing with compliance. Compare its dated revenue with the penalty and the delay risk of missing the deadline, and phase it behind the compliant core.
Quantify market entry
Entering a region that carries heavy compliance cost: compare expected gross profit (say $1.5M ARR, annual recurring revenue, x 80% margin = $1.2M per year once ramped) against the build (say 2 FTE x $200k = $400k) and an assumed ongoing audit burden of $200k a year. Net is $1.2M - $0.2M = $1.0M a year, so the build repays in about 0.4 years, roughly 5 months of ramped profit ($400k / $1.0M x 12 = 4.8). Entry is worth it on these numbers; delay it only if the ramp is slow or the compliance team cannot be spared this year.
Contingency for lost velocity (the amount of work the team ships per period)
Contractors help, but Brooks's law (Fred Brooks, 1975: adding people to a late software project makes it later) warns that new people need onboarding from existing staff. Assume 3 contractors deliver about half their capacity (1.5 FTE) in the first quarter and full capacity (3.0 FTE) later, and put them on well-bounded work, not on the critical path (the chain of tasks that sets the finish date). Phase delivery so partial compliance ships in quarter order.
Telling the business
Tell them in one page: what stops, what slows, what continues, when it returns, and what they could choose to trade back. Brief key customers before they hear it second-hand, and re-forecast every quarter.
Illustrative one-page price list, using the capacity arithmetic above: Stops: experiments with low confidence and nice-to-have refactors, for the full year. Slows: new product work falls to 3.0 FTE, 25% of the original team, so a feature set that took the whole team one quarter now takes about four quarters (1 / 0.25), before any help from contractors. Continues: keeping existing systems running (1.5 FTE) and features with a dated customer or revenue commitment. Returns: normal capacity in the quarter after the compliance deadline, re-forecast each quarter. Choice offered: the business can buy back capacity with contractors (about 1.5 FTE in the first quarter, 3.0 FTE later) or by narrowing the compliant scope the legal reading allows.