YOUR PRACTICAL PRIVACY TOOLKIT

Less legal jargon.
More getting organised.

A website scan spots visible problems. Your privacy desk helps you organise the records and follow-up that happen behind the scenes.

Open your privacy desk

Map your data.

Start with one everyday activity: enquiries, orders or newsletters. Record its purpose, people, data categories, basis, suppliers, retention and safeguards.

Own the next action.

Give each request a case reference and responsible person. Keep the original correspondence in your secure case system and maintain a minimal progress summary here.

Review, then repeat.

Set a target date, opt into owner reminders and invite a colleague with the right access. Export records and case activity when needed.

Before you mark a record reviewed

  • Describe actual practices, not the process you wish you had.
  • Confirm supplier names, recipients, locations and signed agreements.
  • Document why the selected lawful basis and retention rule apply.
  • Record unresolved gaps and the person responsible for fixing them.
  • Revisit records after changing tools, markets, data uses or suppliers.

Completed fields measure record completeness. They do not establish legal compliance.

Plain-English glossary

Processing record / ROPA

A record of an activity involving personal information: what you use, why, who receives it, how long it stays and how it is protected. Article 30 documentation duties depend on your role and circumstances; small size alone does not settle whether an exemption applies.

Data subject request

A person asking to exercise a privacy right, such as access, correction or deletion. Record receipt and responsibility, assess the applicable deadline and respond through an appropriate secure channel.

Controller and processor

A controller determines why and how personal information is used. A processor handles it on a controller’s behalf. Your role can differ between activities.

Lawful basis

The legal ground you have assessed for a specific use of personal information. A form checkbox is not a substitute for deciding which basis applies.

International transfer

Making personal information available across borders may require a transfer assessment and safeguards. Record the destination and relevant mechanism.

Article 27 representative

An appointed contact in the relevant territory for certain organisations subject to GDPR without a local establishment. Website fixes or a software subscription do not create this appointment.

DPO

A data protection officer has a defined advisory and monitoring role. Not every business needs one, and a DPO is different from an Article 27 representative.

A review date versus a deadline

An internal target helps you act early. It is not automatically the legal response deadline; jurisdiction and circumstances still need assessment.

Official sources, directly

Explore the framework coverage guide →

Need the website fixed?

The records stay with you. Our paid service provides manual inspection, bespoke technical changes and a report.

Book website fixes