Blog

I write about laws, technology and AI governance

Notes from practice — what regulators actually ask for, how DPIAs go wrong, and where AI governance meets the existing data privacy program. Everything is published here, across four sections.

Flags of the EU, India, Qatar, the United States, Saudi Arabia and the UAE over a world map

Sections

Four categories, each with its own page of articles.

Section
Data Privacy Laws

Global data privacy regulations and compliance requirements — the full texts of India's DPDPA, Qatar's PDPPL, Saudi Arabia's PDPL and the UAE's PDPL, chapter by chapter.

4 articles

Browse the section →
Section
AI Governance

The governance layer over AI systems — the EU AI Act, ISO/IEC 42001, NIST AI RMF, AI inventories, risk tiering, human oversight and AI impact assessment.

3 articles

Browse the section →
Section
Data Privacy Management

Best practices for managing and protecting personal data in your organization — the management framework, day-to-day operating practice, and the tooling that supports it.

3 articles

Browse the section →
Section
Data Protection Technology

Cutting-edge tools and technologies that enhance data security and data privacy protection — from encryption and anonymisation to zero-knowledge proofs.

3 articles

Browse the section →

Artefacts

Working documents from live programs, generalised for reuse. Previews below — email me and I will send the current version.

Template
DPIA / PIA template

Screening questions, necessity and proportionality, risk register and sign-off, usable under GDPR, DPDPA and PDPPL.

Request access →
Framework
ROPA framework

Article 30 record structure with data flow mapping, lawful basis, retention and transfer fields already wired together.

Request access →
Framework
AI governance framework (ISO 42001)

AI inventory schema, model classification and risk tiering, human oversight criteria and EU AI Act obligation mapping.

Request access →