Screening questions, necessity and proportionality, risk register and sign-off, usable under GDPR, DPDPA and PDPPL.
Request access →Blog
I write about laws, technology and AI governance
Notes from practice — what regulators actually ask for, how DPIAs go wrong, and where AI governance meets the existing data privacy program. Everything is published here, across four sections.
Sections
Four categories, each with its own page of articles.
Global data privacy regulations and compliance requirements — the full texts of India's DPDPA, Qatar's PDPPL, Saudi Arabia's PDPL and the UAE's PDPL, chapter by chapter.
Browse the section →The governance layer over AI systems — the EU AI Act, ISO/IEC 42001, NIST AI RMF, AI inventories, risk tiering, human oversight and AI impact assessment.
Browse the section →Best practices for managing and protecting personal data in your organization — the management framework, day-to-day operating practice, and the tooling that supports it.
Browse the section →Cutting-edge tools and technologies that enhance data security and data privacy protection — from encryption and anonymisation to zero-knowledge proofs.
Browse the section →Artefacts
Working documents from live programs, generalised for reuse. Previews below — email me and I will send the current version.
Article 30 record structure with data flow mapping, lawful basis, retention and transfer fields already wired together.
Request access →AI inventory schema, model classification and risk tiering, human oversight criteria and EU AI Act obligation mapping.
Request access →Three tracks — executive, engineering and business — delivered organisation-wide, adaptable to your jurisdiction.
Request access →Practitioner notes on data privacy operations and AI governance, published across the four sections above.
Read the articles →Longer write-ups of the three programs on the Contributions page, including control sets and regulator correspondence structure.
Request access →