Guides

Guides

In-depth compliance guides for privacy professionals. Practical, actionable, and regulation-specific.

Regulation

DPDP Act Compliance Guide

A comprehensive guide for Indian businesses to achieve and maintain compliance with the Digital Personal Data Protection Act 2023 — covering consent, DSR workflows, breach response, and Significant Data Fiduciary obligations.

1Understanding the DPDP Act 2023
2Who Does the Law Apply To?
3Consent Obligations & Notices
+5 more chapters
45 min readRead Guide
Regulation

GDPR Compliance Playbook

The definitive GDPR playbook for compliance teams — from establishing lawful bases and managing data subject rights to maintaining your Article 30 RoPA and surviving a regulator audit.

1GDPR Fundamentals
2Lawful Bases for Processing
3Data Subject Rights in Practice
+5 more chapters
60 min readRead Guide
Regulation

CCPA/CPRA Compliance Guide

Everything California businesses (and those serving California residents) need to know about the CCPA and CPRA — from consumer rights to opt-out mechanisms and annual risk assessments.

1CCPA vs CPRA: What Changed
2Consumer Rights Under CCPA/CPRA
3Handling Verifiable Consumer Requests
+4 more chapters
35 min readRead Guide
Privacy Ops

Privacy Operations Handbook

Build and scale a privacy operations function from scratch. Covers team structures, tooling, KPIs, escalation paths, and how to operationalise privacy across engineering, product, and marketing.

1What Is Privacy Ops?
2Building Your Privacy Team
3Tooling Stack for Privacy Teams
+4 more chapters
55 min readRead Guide
Privacy Ops

Data Mapping & RoPA Guide

Step-by-step guidance on building and maintaining a Record of Processing Activities that satisfies GDPR Article 30, DPDP Act requirements, and regulatory audit expectations.

1Why Data Mapping Matters
2Building Your Data Inventory
3RoPA Structure & Required Fields
+3 more chapters
30 min readRead Guide
Consent

Consent Management Best Practices

Design consent flows that are genuinely free, specific, and informed — and build the infrastructure to capture, store, version, and withdraw consent at scale across all channels.

1Principles of Valid Consent
2Cookie Consent & TCF 2.2
3Consent UX That Converts
+3 more chapters
25 min readRead Guide
AI Governance

AI Governance Framework

A practical framework for governing AI systems under the EU AI Act, GDPR, and emerging global AI regulations — including risk classification, DPIA requirements, and human oversight controls.

1AI Risk Classification (EU AI Act)
2AI Inventory & Documentation
3DPIA for AI Systems
+4 more chapters
40 min readRead Guide
Privacy Ops

Breach Notification Playbook

A step-by-step incident response playbook covering breach detection, risk assessment, regulatory notification timelines (GDPR 72-hour, DPDP Act, PDPA 3-day), and affected individual communication.

1What Constitutes a Data Breach
2Immediate Containment Steps
3Risk Assessment Framework
+3 more chapters
28 min readRead Guide
Privacy Ops

Vendor Risk Assessment Guide

Assess, monitor, and manage privacy risks from third-party processors. Covers vendor questionnaires, DPA execution, sub-processor management, and ongoing monitoring programs.

1Why Vendor Risk Matters for Privacy
2Building a Vendor Privacy Questionnaire
3Executing Data Processing Agreements
+3 more chapters
32 min readRead Guide
Privacy Ops

Privacy Program Maturity Model

Benchmark your organisation's privacy program against a five-level maturity model — from ad hoc compliance to automated, proactive privacy management — with a clear roadmap to advance.

1The Five Maturity Levels
2Level 1: Ad Hoc (Reactive)
3Level 2: Defined (Policy-Led)
+4 more chapters
20 min readRead Guide
Privacy Ops

Shadow IT Discovery Guide

Personal data hiding in unauthorised SaaS tools is one of the biggest compliance risks organisations face. Learn how to discover shadow IT, assess risk, and bring it into your governance program.

1What Is Shadow IT?
2Why It's a Privacy Risk
3Discovery Techniques
+3 more chapters
22 min readRead Guide
GDPR

GDPR for SaaS Companies

GDPR compliance for SaaS businesses is different from enterprises. This guide focuses on sub-processor management, DPA templates, privacy-by-default product features, and handling enterprise customer audits.

1Are You a Controller or Processor?
2Your DPA as a Business Asset
3Sub-Processor Chain Management
+3 more chapters
38 min readRead Guide
DPDP Act

India DPDP for Startups

A practical, startup-friendly guide to India's DPDP Act — focused on what you need to do now, what you can defer, and how to build a compliance foundation without a dedicated privacy team.

1Does the DPDP Act Apply to Your Startup?
2Minimum Viable Compliance
3Writing Your Privacy Notice
+3 more chapters
18 min readRead Guide

Need a custom compliance assessment?

Our privacy experts can conduct a bespoke gap analysis and build a roadmap for your organisation.