Compliance
Privacy, data protection and regulatory checklists for small organisations.
Download all 16
- Answer a security questionnaire
Drafts answers to a customer's security or vendor due-diligence questionnaire strictly from documented practices, citing evidence for each answer and marking gaps instead of overclaiming.
- Assess EU AI Act obligations
Maps an AI system to the EU AI Act's risk categories and roles such as provider or deployer, and lists the likely obligations and application dates to verify with counsel.
- Audit a product for data protection
Audits a software product, its code and processes against data protection expectations such as GDPR and CCPA, with a pass, partial or gap status per requirement and the product change each gap needs.
- Audit a website's privacy compliance
Checks a website's cookie banner, consent, privacy notice, forms and trackers against common privacy-law expectations and lists prioritised fixes to confirm with a privacy professional.
- Build a compliance readiness checklist
Builds a readiness checklist for a named regulation or framework applied to a specific business, covering applicability, evidence, owners, priorities and points to verify with counsel.
- Check email and SMS marketing compliance
Checks an email or SMS marketing programme against consent and content rules such as GDPR, ePrivacy, CAN-SPAM and CASL for each market, and lists concrete fixes ranked by risk.
- Check endorsement disclosures
Checks influencer, affiliate and endorsement content against advertising disclosure expectations for the market and platform, flags hidden or unclear disclosures, and suggests compliant wording.
- Compliance officer
Acts as a pragmatic compliance officer for small organisations who reads obligations closely, turns them into proportionate controls with evidence, and escalates interpretation to counsel.
- Draft a data protection impact assessment
Drafts a data protection impact assessment for a project, covering screening, the processing, necessity, risks to people by likelihood and severity, mitigations and residual risk.
- Handle a personal data request
Guides a small organisation through answering a personal-data access or deletion request, covering identity checks, where to search, exemptions to check, deadlines and the reply.
- Map personal data processing
Drafts a record of personal-data processing activities from business processes, listing purposes, data categories, recipients, transfers, retention and open questions for privacy review.
- Plan a personal data breach response
Plans a small organisation's personal data breach response covering containment, risk assessment, notification thresholds and deadlines to verify, notice templates and a breach log.
- Review a vendor data processing agreement
Reviews a SaaS vendor's data processing agreement against core requirements such as instructions, security, subprocessors, transfers, breach notice, audits and deletion, and lists the gaps to raise.
- Technology law guide
Acts as a technology-law information guide for software teams on privacy, licences, product terms and contracts, drafting for counsel review and separating general information from legal advice.
- Write a data retention schedule
Drafts a records and data retention schedule listing each record type, owner, system, retention trigger, period to verify, basis, and deletion or archiving method, with legal holds and review steps.
- Write a workplace risk assessment
Writes a workplace health and safety risk assessment covering hazards, who is at risk, existing controls, risk ratings, further actions with owners and a review date.
Not: secure coding (security).