Home Resources
The toolkit

Put privacy into practice

Knowing what the law requires is only the beginning. You also need the right processes, tools, and documentation to put those requirements into practice.

The resources in this section can help you understand what data you have, how it moves through your organisation, and how to document your practices. These are general data management tools rather than privacy products, but each supports work that personal data protection requires.

A tool can support good governance, but no tool makes an organisation compliant by itself. Compliance depends on how your organisation uses these tools, the processes around them, and the requirements that apply to you.

Know what data you have

You can't govern data you can't see. A data catalog helps you understand what data your organisation holds, where it comes from, who is responsible for it, and how it is used.

Understand where your data goes

Data lineage shows where data comes from, how it changes, and where it goes as it moves through your organisation. This can help you understand how personal data flows between systems, identify who or what uses it, investigate data quality issues, and support privacy activities such as records of processing and deletion requests.

Keep your data accurate

Privacy laws often require organisations to take reasonable steps to keep personal data accurate and up to date. Data quality tools can help you find problems such as missing, invalid, inconsistent, or outdated data. They can also help you test data automatically and catch problems before they spread to other systems.

Make data expectations explicit

A data contract defines what a dataset should contain and how it should behave. It can specify things such as the expected fields, data types, allowed values, ownership, and quality requirements. Data contracts help teams agree on what data producers should provide and what data consumers can rely on. They can also make it easier to detect changes that could affect downstream systems.

Keep your documentation and policies up to date

Documentation is part of good governance. It helps people understand what data you have, how it is used, who is responsible for it, and what rules apply. Treating documentation and policies as code means keeping them in version-controlled files and updating them through the same workflows used for software. This makes changes easier to review, track, and audit.

Templates to get started Coming soon

The documents every compliance programme needs, ready to adapt.

No tool makes an organisation compliant. Everything on this page can support good governance, helping you see what data you hold, how it moves, and whether it is accurate but compliance depends on the processes around these tools and on the requirements that apply to you. Check your country's brief for those requirements, and adapt any template to your actual practices.