Home/Documentation/Programme-level documentation
Data Privacy Programme
Privacy policies, standards and records for UK GDPR, EU GDPR and CCPA/CPRA, with the data-protection-by-design procedures that connect privacy to your security controls.
What this set does
Privacy documentation has two audiences: regulators and data subjects. This programme covers both, with the internal records (Article 30 register, DPIAs, retention schedule, breach log) and the external notices (privacy notice, cookie notice, subject-rights process) written to match each other.
What's inside
- Data protection policy and standards
- Record of processing activities (Article 30) workbook
- Data protection impact assessment procedure and template
- Retention and disposal schedule
- Data subject rights handling procedure with response templates
- Data breach assessment and 72-hour notification procedure
- Processor due diligence checklist and DPA clauses
- Privacy notice and cookie notice templates
Who it is for
Controllers and processors handling UK or EU personal data, and US organisations in scope of CCPA/CPRA.
How the documents are structured
Every document opens with its purpose, scope and owner, then the substantive content, then a control cross-reference showing which framework requirements it satisfies. Standards state requirements in testable language ("must", with the parameter). Procedures follow one format: trigger, roles, steps, frequency, records produced. Placeholders are limited to things only you can know: organisation name (which we fill in), system names, role titles, tool names and timelines. There are no "[insert policy here]" sections.
Tailoring effort
Expect to spend a few hours on a policies-and-standards set and longer on procedures, because procedures describe how your team actually works. The document register in each set lists every file with a suggested owner so you can split the work.
Included in these bundles
Licence
One purchase covers one organisation for internal use, with unlimited users and unlimited edits. Consultancies and MSPs tailoring documents for clients need the multi-client licence; see the terms or ask us.
Related products
Policies & Standards — ISO/IEC 27001:2022
A complete policy and standards set structured to the 93 Annex A controls of ISO/IEC 27002:2022, plus the clause 4–10 management-system requirements.
£495 · 41 documentsPolicies & Standards — NIST CSF 2.0
Policies and standards organised by the six CSF 2.0 functions, with standards written at the subcategory level so each one is auditable.
£445 · 36 documentsProcedures Library
Step-by-step operating procedures that show how each control is actually carried out, who does it, how often, and what record it produces.
£595 · 118 documents