YOUR PRACTICAL PRIVACY TOOLKIT
Less legal jargon.
More getting organised.
A website scan spots visible problems. Your privacy desk helps you organise the records and follow-up that happen behind the scenes.
Open your privacy deskMap your data.
Start with one everyday activity: enquiries, orders or newsletters. Record its purpose, people, data categories, basis, suppliers, retention and safeguards.
Own the next action.
Give each request a case reference and responsible person. Keep the original correspondence in your secure case system and maintain a minimal progress summary here.
Review, then repeat.
Set a target date, opt into owner reminders and invite a colleague with the right access. Export records and case activity when needed.
Before you mark a record reviewed
- Describe actual practices, not the process you wish you had.
- Confirm supplier names, recipients, locations and signed agreements.
- Document why the selected lawful basis and retention rule apply.
- Record unresolved gaps and the person responsible for fixing them.
- Revisit records after changing tools, markets, data uses or suppliers.
Completed fields measure record completeness. They do not establish legal compliance.
Plain-English glossary
Processing record / ROPA
A record of an activity involving personal information: what you use, why, who receives it, how long it stays and how it is protected. Article 30 documentation duties depend on your role and circumstances; small size alone does not settle whether an exemption applies.
Data subject request
A person asking to exercise a privacy right, such as access, correction or deletion. Record receipt and responsibility, assess the applicable deadline and respond through an appropriate secure channel.
Controller and processor
A controller determines why and how personal information is used. A processor handles it on a controller’s behalf. Your role can differ between activities.
Lawful basis
The legal ground you have assessed for a specific use of personal information. A form checkbox is not a substitute for deciding which basis applies.
International transfer
Making personal information available across borders may require a transfer assessment and safeguards. Record the destination and relevant mechanism.
Article 27 representative
An appointed contact in the relevant territory for certain organisations subject to GDPR without a local establishment. Website fixes or a software subscription do not create this appointment.
DPO
A data protection officer has a defined advisory and monitoring role. Not every business needs one, and a DPO is different from an Article 27 representative.
A review date versus a deadline
An internal target helps you act early. It is not automatically the legal response deadline; jurisdiction and circumstances still need assessment.
Official sources, directly
Explore the framework coverage guide →Need the website fixed?
The records stay with you. Our paid service provides manual inspection, bespoke technical changes and a report.