Skip to content

Insights

Practical privacy intelligence, explained

Long-form explanations of the decisions privacy teams actually face — what a regulation asks for, what good implementation looks like, and how to evidence it afterwards. Evergreen guidance, not news.

Topic

Content type

Jurisdiction

Global PrivacyComparison8 min read

GDPR vs CCPA vs India DPDP

GDPR, CCPA/CPRA and India's DPDP Act use different applicability tests entirely — here's how to map your data flows against all three without building three separate programs.

Privacy OperationsArticle6 min read

How to Create a Personal Data Inventory

Inventories built from a system list miss most of the risk — build yours from actual business processes and the people who run them instead.

Privacy OperationsGuide7 min read

How to Conduct a Privacy Impact Assessment

A privacy impact assessment run during design changes decisions; run after launch, it only documents them.

Privacy OperationsGuide6 min read

How to Build a Data Subject Request Workflow

Most missed deadlines come from an unmonitored inbox, not a hard request. Here is the seven-stage pipeline that fixes that.

Privacy OperationsGuide7 min read

RoPA Explained With a Practical Example

A RoPA built properly answers 'where is this person's data' in minutes. Here's how to build one, with a filled-in example record.

AI PrivacyArticle7 min read

Can Employees Upload Company Data to Generative AI?

A blanket ban doesn't work. Tier your data, tier your tools, and make the safe path the easy one.

AI GovernanceGuide7 min read

How to Prepare Sensitive Enterprise Data for AI

AI doesn't create data exposure — it reveals it fast. Prepare purpose, minimisation, de-identification and access first.

Data DiscoveryGuide7 min read

How to Discover PII in Unstructured Data

Discovery is an inventory exercise that needs scanning, not a scanning exercise. Here's how to build one that works.

Global PrivacyExplainer6 min read

Anonymisation vs Pseudonymisation vs Redaction

These three techniques sit on a real risk spectrum, not a synonym list — pick the wrong one and you either lose data utility or leave people exposed.

Career and LearningGuide7 min read

A 90-Day Privacy Program for Startups

A phase-by-phase, 90-day plan with owners and outputs for building a real, working startup privacy program.

Get new insights as they publish

Roughly monthly. Practical notes only, and you can unsubscribe from any email.