Data Governance Atlas

Governance

The rest of the Atlas describes what the law is. This layer is about what a specific piece of correspondence is actually asserting — and what it obliges the recipient to do about it.

If you are writing

The goal is a letter that cannot be deflected: each allegation tied to a provision, facts before conclusions, and questions that have answers. Work through the right you are asserting, then the assessment you expect the organisation to rely on, then the escalation route.

If you are receiving

The goal is to recognise quickly that this is no longer a customer-service ticket, separate the strands, and answer every point. Most complaints that reach a regulator escalated because of how the first fortnight was handled, not because of the original failure.

Principles

Rights

Roles and responsibilities

Assessments and tests

Data lifecycle

Security and design

Automation and AI

Data governance

Accountability

Complaints and disputes

Worked examples

Framework anchors

Each concept is anchored to the NIST Privacy Framework functions and to ISO/IEC 27701:2019 Annex A and B controls, as well as to the provisions of each legal family. Frameworks describe outcomes rather than statutes, so they hold in every jurisdiction — which is what stops a page written from GDPR articles quietly presenting itself as universal. The ISO control identifiers were taken from the mapping published in mukul975/Privacy-Data-Protection-Skills (Apache-2.0), which maps privacy procedures to NIST PF, ISO 27701 and the OWASP privacy risks.

Coverage map

What this section intends to cover, and what is written so far — 19 of 47. Outstanding entries are listed rather than omitted, on the same principle as printing a depth tier: a gap you can see is worth more than a gap you have to discover.

Domain Topic Status Framework anchor
Principles The principles, end to end For both sides GV-P · ID-P
Purpose limitation and compatible reuse Not yet written
Transparency and privacy notices Not yet written
Fairness as a distinct test Not yet written
Rights The rights, and how they interact For both sides CT-P · CM-P
Rectification in practice For both sides CT-P
Erasure and restriction Not yet written
Portability and objection Not yet written
Rights over children’s data Not yet written
Roles and responsibilities Controllers, processors and joint controllers For both sides GV-P · ID-P
The DPO, and data ownership beyond it Not yet written
Processor contracts and sub-processing Not yet written
Representatives and group structures Not yet written
Assessments and tests Choosing and documenting a lawful basis For the controller / DPO GV-P · CT-P
The legitimate interests assessment For both sides GV-P · ID-P
Impact assessment methodology Not yet written
Disclosures to third parties For both sides ID-P · CT-P
Transfer risk assessments Not yet written
Special category and criminal offence conditions Not yet written
Data protection impact assessments that are worth doing For the controller / DPO ID-P · GV-P
Data lifecycle Retention and deletion Not yet written
Data minimisation in practice Not yet written
Anonymisation and pseudonymisation For the controller / DPO PR-P · CT-P
Collection and onward reuse Not yet written
Retention: schedules, deletion and the backup gap For the controller / DPO CT-P
Security and design Appropriate technical and organisational measures For the controller / DPO PR-P
Privacy by design and by default Not yet written
Access control and least privilege Not yet written
Data classification Not yet written
Automation and AI Automated decisions and profiling Not yet written
AI governance and model data Not yet written
Training data provenance Not yet written
Automated decisions, profiling and AI For both sides ID-P · CM-P
Data governance Data quality For the controller / DPO CT-P · ID-P
Catalogues, lineage and metadata Not yet written
Stewardship and the operating model For the controller / DPO GV-P
Data sharing agreements Not yet written
Maturity and assurance Not yet written
Accountability Records of processing Not yet written
When to report yourself For the controller / DPO GV-P · CM-P
Policy frameworks and standards Not yet written
Audit, assurance and evidence Not yet written
Records of processing that earn their keep For the controller / DPO ID-P
Complaints and disputes Making a complaint that lands For the person complaining CM-P
Handling a complaint you have just received For the controller / DPO CM-P · GV-P
Regulators and escalation routes Not yet written
Worked examples Anatomy of a data protection complaint For both sides CM-P