Sector guidance
Privacy guidance for your industry
The obligations are broadly similar across sectors; the data flows and failure modes are not. These pages describe where personal data actually concentrates in each sector and which controls make the biggest difference.
SaaS and technology
Product telemetry, customer data processed as a processor, and fast-moving AI features — three privacy problems that pull in different directions.
Read the guidanceFinancial services
Long retention obligations, heavy third-party ecosystems and automated decisions about people — privacy work that has to coexist with prudential and AML rules.
Read the guidanceHealthcare and life sciences
Health data is sensitive by default, shared across many organisations, and increasingly used for research and AI — a combination that leaves little room for informal practice.
Read the guidanceRetail and e-commerce
High-volume consumer data, heavy marketing technology and loyalty analytics — the sector where consent quality and tag governance decide compliance.
Read the guidanceEducation
Children's data, third-party learning platforms and safeguarding records — a sector where transparency and vendor control matter more than documentation volume.
Read the guidanceProfessional services
Client confidentiality, document-heavy estates and rapid AI adoption — a sector where unstructured data is the whole privacy problem.
Read the guidancePrivacy Practice Lab publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation. Sector pages are written globally and do not account for jurisdiction-specific sectoral rules that may apply to your organisation.