Consent Implementation Playbook
Product, growth and privacy engineeringDesign, deploy and prove consent capture across web, app and checkout.
- 01Reconcile consent purposes to approved RoPA purposes.
- 02Design purpose taxonomy and copy — reviewed by legal.
- 03Deploy consent widget per surface with language variants.
- 04Write consent receipt on capture — value, purpose, version.
- 05Wire withdrawal to propagate to downstream systems and vendors.
- 06Publish self-serve preference centre with public URL.
DSR Operations Playbook
Grievance Officer, privacy operations, support leadershipStand up a compliant grievance and rights workflow across the organisation.
- 01Appoint Grievance Officer per legal entity and publish contact.
- 02Build public intake form per legal entity.
- 03Design identity verification workflow with attempt log.
- 04Map task fan-out across systems from the inventory.
- 05Draft response letter template with lineage placeholders.
- 06Set SLA per request type with escalation paths.
Incident Response Playbook
CISO, DPO, incident response lead, legalRehearse the §8(6) workflow so the 72-hour clock is not the first surprise.
- 01Define incident types and severity thresholds.
- 02Pre-approve Board notification template with legal.
- 03Pre-approve data-principal notification template per cohort type.
- 04Define scope-drafting workflow against the inventory.
- 05Run two tabletop rehearsals per year — with the clock live.
- 06Retain post-incident review report on the platform.
Retention Enforcement Playbook
Records officer, DPO, engineeringTurn a retention schedule from a policy document into a run with evidence.
- 01Draft schedule per data category with lawful basis anchor.
- 02Register named holds — litigation, tax, contract.
- 03Configure dry-run cadence per schedule.
- 04Assign disposition executor per system.
- 05Reconcile against RoPA retention field.
- 06Publish per-run evidence to the audit register.
Vendor Governance Playbook
Procurement, legal, DPOBring processors under DPA discipline with renewal reviews and sub-processor tracking.
- 01Register every vendor in the enterprise inventory.
- 02Attach DPA to each vendor record with renewal date.
- 03Register sub-processors per vendor.
- 04Route change-of-sub-processor notifications into the review workflow.
- 05Trigger renewal review 90 days before expiry.
- 06Report on DPA coverage in the quarterly Board pack.
Board Reporting Playbook
DPO, CRO, audit committee secretariatAssemble the quarterly Board pack from the record — not from memory.
- 01Agree scope with the Board — legal entities, period, metrics.
- 02Compose pack from RoPA, DSR, incidents and retention registers.
- 03Reconcile every metric to underlying record IDs.
- 04Review with the accountable officer.
- 05Sign, stamp version and distribute.
- 06Retain the signed version with a change-log.