Governance
The rest of the Atlas describes what the law is. This layer is about what a specific piece of correspondence is actually asserting — and what it obliges the recipient to do about it.
If you are writing
The goal is a letter that cannot be deflected: each allegation tied to a provision, facts before conclusions, and questions that have answers. Work through the right you are asserting, then the assessment you expect the organisation to rely on, then the escalation route.
If you are receiving
The goal is to recognise quickly that this is no longer a customer-service ticket, separate the strands, and answer every point. Most complaints that reach a regulator escalated because of how the first fortnight was handled, not because of the original failure.
Principles
Rights
The rights, and how they interact
All eight rights in one place — what each obliges, which are qualified, and the interactions that catch organisations out when two are exercised together.
Rectification in practice
What Article 16 actually requires, the difference between acting on a correction and acknowledging one, and the notification duty that almost everyone forgets.
Roles and responsibilities
Assessments and tests
Choosing and documenting a lawful basis
How to pick a lawful basis for processing, why consent is usually the worst default rather than the safest, and why you cannot quietly swap bases once processing has started.
The legitimate interests assessment
Three separate tests, not one. How to run each, how to attack each, and why "this is how the industry does it" is a habit rather than a lawful basis.
Disclosures to third parties
Every disclosure is processing and needs its own basis. What to record before sharing, and what to ask for when you discover a share you did not expect.
Data protection impact assessments that are worth doing
When a DPIA is genuinely required rather than merely prudent, how to scope one so it is useful, what makes a DPIA worthless, and who has to own the outcome.
Data lifecycle
Retention: schedules, deletion and the backup gap
Why a retention schedule beats ad-hoc deletion, why "keep it forever" is a liability rather than an asset, and the persistent gap between a deletion policy and what your backups actually do.
Anonymisation and pseudonymisation
One takes data out of scope entirely; the other does not. Why the distinction is the most consequential in the whole regime, and why most claimed anonymisation is not.
Security and design
Automation and AI
Data governance
Data quality
Accuracy is a legal obligation and quality is a broader operational one. The dimensions worth measuring, why quality failures become rights failures, and where to intervene.
Stewardship and the operating model
Who owns what, how the roles actually divide, and why a governance function with no decision rights produces documents instead of change.
Accountability
Records of processing that earn their keep
What a record of processing activities is actually for beyond compliance theatre, the minimum content that is genuinely useful, and how a ROPA decays if you do not wire it to change.
When to report yourself
Why an unauthorised disclosure can be a notifiable breach even though nothing was hacked, and why a documented "not notifiable" is a good outcome but no assessment is not.
Complaints and disputes
Making a complaint that lands
How to structure a data protection complaint so it cannot be deflected — the order to put things in, what to ask for, and the sentences that make delay measurable.
Handling a complaint you have just received
A first-hour checklist for the DPO, how to recognise correspondence that is no longer a customer-service ticket, and the three failures that turn a small complaint into a regulatory one.
Worked examples
Framework anchors
Each concept is anchored to the NIST Privacy Framework functions and to ISO/IEC 27701:2019 Annex A and B controls, as well as to the provisions of each legal family. Frameworks describe outcomes rather than statutes, so they hold in every jurisdiction — which is what stops a page written from GDPR articles quietly presenting itself as universal. The ISO control identifiers were taken from the mapping published in mukul975/Privacy-Data-Protection-Skills (Apache-2.0), which maps privacy procedures to NIST PF, ISO 27701 and the OWASP privacy risks.
Coverage map
What this section intends to cover, and what is written so far — 19 of 47. Outstanding entries are listed rather than omitted, on the same principle as printing a depth tier: a gap you can see is worth more than a gap you have to discover.
| Domain | Topic | Status | Framework anchor |
|---|---|---|---|
| Principles | The principles, end to end | For both sides | GV-P · ID-P |
| Purpose limitation and compatible reuse | Not yet written | — | |
| Transparency and privacy notices | Not yet written | — | |
| Fairness as a distinct test | Not yet written | — | |
| Rights | The rights, and how they interact | For both sides | CT-P · CM-P |
| Rectification in practice | For both sides | CT-P | |
| Erasure and restriction | Not yet written | — | |
| Portability and objection | Not yet written | — | |
| Rights over children’s data | Not yet written | — | |
| Roles and responsibilities | Controllers, processors and joint controllers | For both sides | GV-P · ID-P |
| The DPO, and data ownership beyond it | Not yet written | — | |
| Processor contracts and sub-processing | Not yet written | — | |
| Representatives and group structures | Not yet written | — | |
| Assessments and tests | Choosing and documenting a lawful basis | For the controller / DPO | GV-P · CT-P |
| The legitimate interests assessment | For both sides | GV-P · ID-P | |
| Impact assessment methodology | Not yet written | — | |
| Disclosures to third parties | For both sides | ID-P · CT-P | |
| Transfer risk assessments | Not yet written | — | |
| Special category and criminal offence conditions | Not yet written | — | |
| Data protection impact assessments that are worth doing | For the controller / DPO | ID-P · GV-P | |
| Data lifecycle | Retention and deletion | Not yet written | — |
| Data minimisation in practice | Not yet written | — | |
| Anonymisation and pseudonymisation | For the controller / DPO | PR-P · CT-P | |
| Collection and onward reuse | Not yet written | — | |
| Retention: schedules, deletion and the backup gap | For the controller / DPO | CT-P | |
| Security and design | Appropriate technical and organisational measures | For the controller / DPO | PR-P |
| Privacy by design and by default | Not yet written | — | |
| Access control and least privilege | Not yet written | — | |
| Data classification | Not yet written | — | |
| Automation and AI | Automated decisions and profiling | Not yet written | — |
| AI governance and model data | Not yet written | — | |
| Training data provenance | Not yet written | — | |
| Automated decisions, profiling and AI | For both sides | ID-P · CM-P | |
| Data governance | Data quality | For the controller / DPO | CT-P · ID-P |
| Catalogues, lineage and metadata | Not yet written | — | |
| Stewardship and the operating model | For the controller / DPO | GV-P | |
| Data sharing agreements | Not yet written | — | |
| Maturity and assurance | Not yet written | — | |
| Accountability | Records of processing | Not yet written | — |
| When to report yourself | For the controller / DPO | GV-P · CM-P | |
| Policy frameworks and standards | Not yet written | — | |
| Audit, assurance and evidence | Not yet written | — | |
| Records of processing that earn their keep | For the controller / DPO | ID-P | |
| Complaints and disputes | Making a complaint that lands | For the person complaining | CM-P |
| Handling a complaint you have just received | For the controller / DPO | CM-P · GV-P | |
| Regulators and escalation routes | Not yet written | — | |
| Worked examples | Anatomy of a data protection complaint | For both sides | CM-P |