Data privacy impact assessments
Conduct systematic assessments to identify and mitigate data privacy risks. A DPIA is not a form — it is a decision record. The output that matters is not the completed template but the change that was made because of it, and the evidence that a risk was accepted knowingly.
- Start with screening questions that most systems answer in five minutes, so the full assessment is reserved for the systems that need it.
- Cover necessity and proportionality explicitly. This is the section regulators read first and the one most often left thin.
- Keep a risk register with owners and target dates, and route residual risk to someone with the authority to accept it.
- Use one template across GDPR, DPDPA and PDPPL rather than three — the underlying analysis is common, only the citations differ.
Data subject rights
Implement processes to handle data subject requests efficiently. The statutory clock is unforgiving and the work is mostly discovery: finding every copy of a person's data across systems that were never designed to be searched by subject.
- Build the intake channel first — a single, verifiable route with identity checks proportionate to the request.
- Connect the request to the data inventory. If the inventory is wrong, every DSAR becomes a manual investigation.
- Automate the repeatable parts — acknowledgement, routing, deadline tracking — and keep human judgement for scope and exemptions.
- Log every request and its outcome. The log is the evidence that the right was honoured.
Vendor management
Establish processes for managing third-party data processors. Most personal data leaves the organisation at some point, and the obligation does not leave with it.
- Screen at onboarding, when you still have commercial leverage, rather than at renewal.
- Hold a live register of processors, sub-processors, the data each receives, and the transfer mechanism relied on.
- Negotiate the data processing agreement alongside Legal, Procurement and Security — not after the contract is signed.
- Re-assess on a risk basis: a payroll processor and an analytics pixel do not warrant the same depth.