Privacy-Ops
Why DPOs and CISOs Keep Talking Past Each Other - And How to Actually Align a RoPA With an Asset Inventory
DPOs and CISOs often look at the same organisation through very different lenses. This article talks about the same
Privacy-Ops
DPOs and CISOs often look at the same organisation through very different lenses. This article talks about the same
consent
Most organisations collect consent carefully — then quietly breach it through purpose drift, broken withdrawal flows, and AI data reuse. Here's what real consent compliance looks like, and a practical audit you can run this week.
Privacy-Ops
Most privacy professionals use the word "notice" as if it means one thing. It doesn't. And the organisations that haven't figured that out yet are operating with a document masquerading as a privacy program. Let's fix that. First: The Distinction Most People
Privacy-Ops
Let me tell you what most RoPA guides won't. They'll tell you what goes in a Record of Processing Activities. They'll list the fields. They'll show you a template. And then they'll leave you alone with a blank spreadsheet, a
Privacy-Ops
When people hear “privacy,” they usually think of: Policies. Consent. Regulations. Checklists. And for a long time, I did too. But the more I’ve worked closely with products and teams, the more I’ve realised: Privacy work doesn’t really start with compliance. It starts with questions. Questions like: