Why DPOs and CISOs Keep Talking Past Each Other - And How to Actually Align a RoPA With an Asset Inventory
DPOs and CISOs often look at the same organisation through very different lenses. This article talks about the same
DPOs and CISOs often look at the same organisation through very different lenses. This article talks about the same
Part 3 of The Legal Basis Playbook There's a word in Article 6(1)(b) that almost nobody reads carefully. The contract basis applies where processing is necessary for the performance of a contract to which the data subject is party, or to take steps at their request
Most organisations collect consent carefully — then quietly breach it through purpose drift, broken withdrawal flows, and AI data reuse. Here's what real consent compliance looks like, and a practical audit you can run this week.
Part 1 of The Legal Basis Playbook Every piece of personal data your organisation processes needs a reason to exist. Not a business reason — though that matters too — but a legal reason. Under the GDPR, that reason is called a lawful basis for processing. Get it right, and you have
Most privacy professionals use the word "notice" as if it means one thing. It doesn't. And the organisations that haven't figured that out yet are operating with a document masquerading as a privacy program. Let's fix that. First: The Distinction Most People
A story about engineers, regulators, and a humble diagram that keeps showing up at the right time. It's the 1970s. There are no privacy laws. No GDPR. No data protection authorities. No DPIAs. The word "compliance" isn't keeping anyone up at night. But in
Every DPDPA playbook I have seen starts at zero. Gap assessments built as if the organisation never heard of privacy. Policy templates drafted as if consent frameworks don't already exist. Implementation timelines that completely ignore the three years of GDPR muscle the organisation spent building. I understand why.
Built for privacy professionals who live inside the frameworks, not just around them. Practical analysis on GDPR, India's DPDPA, cross-jurisdictional compliance, and the operational layer most legal blogs skip.
Let me tell you what most RoPA guides won't. They'll tell you what goes in a Record of Processing Activities. They'll list the fields. They'll show you a template. And then they'll leave you alone with a blank spreadsheet, a
When people hear “privacy,” they usually think of: Policies. Consent. Regulations. Checklists. And for a long time, I did too. But the more I’ve worked closely with products and teams, the more I’ve realised: Privacy work doesn’t really start with compliance. It starts with questions. Questions like: