Practical privacy intelligence, tools and training for modern organisations
Global privacy law explained without the legalese, working tools for the decisions you make each week, free training that ends in a verifiable certificate, and advisory when you need someone alongside you. Learn privacy. Implement it. Prove it.
- Jurisdiction guides
- 8Jurisdiction guides
- Free tools
- 8Free tools
- Certificated courses
- 3Certificated courses
Start here
Four routes through the platform, depending on what is in front of you this week.
Understand a privacy law
Plain-English overviews of the GDPR, UK GDPR, US state laws, India's DPDP Act and more — scope, rights, obligations and checklists, with links to the official text.
Explore privacy lawsBuild a privacy programme
Turn obligations into records, rights workflows, retention schedules and vendor controls that actually exist and can be evidenced.
Plan the next 90 daysGovern AI and sensitive data
Assess AI use cases, remediate permissions before assistants widen access, and keep sensitive data where it belongs.
Triage an AI or data projectDevelop practical skills
Free, quizzed courses with a verifiable certificate — no paid tier, no lead gate before the first lesson.
Open the AcademyPopular free tools
Every tool runs in your browser and is free to use. No sign-in, no paywall, and nothing is saved to your record unless you explicitly ask us to keep a copy.
AI Data Risk Challenge
Twelve real-world scenarios: would you paste this into an AI assistant? Score yourself and see where the line actually sits.
Open the toolPrivacyBuilt Readiness Score
Twenty questions across governance, data, rights, retention, vendors and AI. Your score and priority actions appear instantly — no email gate.
Open the toolGlobal Privacy Law Finder
Tell us where you operate and whose data you handle; get the laws that plausibly apply, with obligations and official sources.
Open the toolWebsite Privacy Hygiene Scanner
Check a site's privacy signals — transport security, headers, cookie and policy hygiene, tracker exposure — with a bookmarklet that runs entirely in your own browser. Nothing about the page leaves your device.
Open the toolBreach Response Simulator
A fictional global incident with ten decision points. Practise the first 72 hours before you have to live them.
Open the toolVendor Privacy Quick Check
A structured red/amber/green view of a supplier before you sign, share data or renew.
Open the toolUse or embed our tools
Publishers, associations and intranet owners can embed the law comparison, glossary and readiness widgets free of charge, with attribution.
Latest insights
Evergreen analysis of how privacy obligations translate into practice.
Explore privacy laws
Scope, principles, rights, obligations, transfers and enforcement for the frameworks that shape global programmes — each with an implementation checklist and links to the official source.
European Union / EEA
EU GDPR
Establishment in the EU/EEA, or targeting/monitoring people in the EU/EEA. No size threshold.
United Kingdom
UK GDPR
UK establishment, or offering goods/services to or monitoring people in the UK.
United States — state level
US state privacy
Threshold-based per state: revenue, data volume, or revenue from selling/sharing personal information.
India
India DPDP
Digital personal data processed in India, or processed abroad in connection with offering goods or services in India.
Canada (federal, private sector)
Canada PIPEDA
Private-sector collection, use and disclosure in commercial activities; provincial laws may displace it intra-provincially.
Australia
Australia Privacy Act
APP entities: agencies and non-exempt organisations, with an AUD 3m small-business exemption subject to carve-outs.
Singapore
Singapore PDPA
Organisations collecting, using or disclosing personal data in Singapore; separate framework for public agencies.
United Arab Emirates (federal, onshore)
UAE PDPL
Onshore UAE processing of data subjects in the UAE; DIFC and ADGM operate separate regimes.
Practical tools and templates
Everything below runs in your browser. Answers are not sent to us, stored, or associated with you.
3 minutes
DPIA triage
Answer eight questions about a planned processing activity and get a risk band with the assessment steps that usually follow.
5 minutes
Vendor privacy quick check
A twelve-point scored checklist for a supplier that will handle personal data, with risk flags and a printable summary.
4 minutes
Privacy programme planner
Choose your stage and priorities and generate a practical 30/60/90-day action plan you can print or take to leadership.
6 minutes
Would you upload this to AI?
Twelve realistic workplace scenarios that test whether you can tell safe AI inputs from confidential ones — with explanations, a category breakdown and a challenge link for colleagues.
4 minutes
Global privacy law finder
Describe where you operate, who you serve and where data is hosted, and see which frameworks may be relevant, why, and what to validate next.
1 minute
Website privacy hygiene scan
A preliminary technical review of a website's pages, run by a bookmarklet inside your own browser: HTTPS hygiene, privacy and cookie links, visible trackers and security headers.
8 minutes
Breach response tabletop simulator
Work a fictional incident through twelve decision points and see how your choices score on containment, documentation, communication and governance.
10 minutes
Privacy readiness assessment
Twenty questions across seven categories, producing a maturity level, category scores and a ranked list of risks.
Sector guidance
The obligations are broadly similar across sectors; the data flows and failure modes are not.
SaaS and technology
Product telemetry, customer data processed as a processor, and fast-moving AI features — three privacy problems that pull in different directions.
Financial services
Long retention obligations, heavy third-party ecosystems and automated decisions about people — privacy work that has to coexist with prudential and AML rules.
Healthcare and life sciences
Health data is sensitive by default, shared across many organisations, and increasingly used for research and AI — a combination that leaves little room for informal practice.
Retail and e-commerce
High-volume consumer data, heavy marketing technology and loyalty analytics — the sector where consent quality and tag governance decide compliance.
Education
Children's data, third-party learning platforms and safeguarding records — a sector where transparency and vendor control matter more than documentation volume.
Professional services
Client confidentiality, document-heavy estates and rapid AI adoption — a sector where unstructured data is the whole privacy problem.
Advisory
When you need hands-on help rather than another guide — readiness reviews, programme build-out, sensitive-data discovery and AI governance.
Privacy Readiness Assessments
An independent, structured review of where your privacy program stands today and what to fix first.
Privacy Program Implementation
Hands-on support to build the inventory, records, workflows and controls that make a privacy program real.
AI Privacy and Governance
Practical governance for generative AI adoption: tool assessment, data boundaries, oversight and incident handling.
Sensitive Data Discovery Strategy
Find where sensitive data actually lives across documents, mailboxes and collaboration platforms — and act on what you find.
Microsoft 365 Data Protection Reviews
A focused review of sharing, permissions, labelling and retention across SharePoint, OneDrive, Teams and Exchange.
Corporate Privacy Training
Role-specific privacy and AI training for the teams that handle personal data every day.
Structured training when you want depth
Three courses with quizzes and a verifiable certificate. Nothing is held back behind a paid tier.
Global Data Privacy Fundamentals
Foundation · 4 hours
Practical Privacy Program Implementation
Intermediate · 4 hours
AI Privacy and Data Readiness
Intermediate · 4 hours
Templates you can use today
Data Inventory and RoPA Starter Kit
A ready-to-use RoPA/data inventory template with column definitions, a worked example row, risk-flagging rules, and an ownership and review cadence for keeping it accurate.
AI Privacy Risk Checklist
A pre-adoption AI checklist with priority, owner role and required evidence for every check, plus approval criteria and a worked example.
Data Breach Response Checklist
A phased incident response checklist covering detect, triage, contain, assess, notify, recover and learn, with a severity matrix, incident log fields and role assignments.