Resources
Templates, checklists and practical writing
Everything here is free to download and adapt inside your own organisation. No email wall, no forms in the way of the content.
Downloadable kits
Working starting points, not blank templates. Each one includes guidance on how to adapt it.
Data Inventory and RoPA Starter Kit
A ready-to-use RoPA/data inventory template with column definitions, a worked example row, risk-flagging rules, and an ownership and review cadence for keeping it accurate.
Open resourceAI Privacy Risk Checklist
A pre-adoption AI checklist with priority, owner role and required evidence for every check, plus approval criteria and a worked example.
Open resourceData Breach Response Checklist
A phased incident response checklist covering detect, triage, contain, assess, notify, recover and learn, with a severity matrix, incident log fields and role assignments.
Open resourceVendor Privacy Assessment Template
A tiered vendor privacy questionnaire covering 30 real questions across data handling, transfers, security, AI use and exit, with risk-rating rules and a completed example row.
Open resourceMicrosoft 365 Sensitive Data Checklist
A tenant-wide checklist covering Exchange, SharePoint/OneDrive, Teams, labels, DLP, retention, sharing, eDiscovery, Purview classification and audit logs, with priority, owner and evidence per check.
Open resourcePrivacy Program 90-Day Roadmap
A week-by-week 90-day plan for standing up a defensible privacy baseline, with phase outputs, owners, dependencies and success measures.
Open resourceArticles and guides
View the full article hubGDPR vs CCPA vs India DPDP
GDPR, CCPA/CPRA and India's DPDP Act use different applicability tests entirely — here's how to map your data flows against all three without building three separate programs.
How to Create a Personal Data Inventory
Inventories built from a system list miss most of the risk — build yours from actual business processes and the people who run them instead.
How to Conduct a Privacy Impact Assessment
A privacy impact assessment run during design changes decisions; run after launch, it only documents them.
How to Build a Data Subject Request Workflow
Most missed deadlines come from an unmonitored inbox, not a hard request. Here is the seven-stage pipeline that fixes that.
RoPA Explained With a Practical Example
A RoPA built properly answers 'where is this person's data' in minutes. Here's how to build one, with a filled-in example record.
Can Employees Upload Company Data to Generative AI?
A blanket ban doesn't work. Tier your data, tier your tools, and make the safe path the easy one.
How to Prepare Sensitive Enterprise Data for AI
AI doesn't create data exposure — it reveals it fast. Prepare purpose, minimisation, de-identification and access first.
How to Discover PII in Unstructured Data
Discovery is an inventory exercise that needs scanning, not a scanning exercise. Here's how to build one that works.
Anonymisation vs Pseudonymisation vs Redaction
These three techniques sit on a real risk spectrum, not a synonym list — pick the wrong one and you either lose data utility or leave people exposed.
A 90-Day Privacy Program for Startups
A phase-by-phase, 90-day plan with owners and outputs for building a real, working startup privacy program.