Guided journeys
Privacy Pathways
A pathway is an ordered set of free Privacy Lab diagnostics that fit together — a mini data-protection programme for a common situation. Browse the full journey up front, then work through it at your own pace. Anonymous to browse; sign in only to save progress.
By who you are
11 steps ~129 min
Just me, just starting
You are probably fine — but there are two or three things you genuinely cannot skip. Let's find out which, in about five minutes.
See the full journey17 steps ~153 min
An established small business
Real customer and staff records, and nobody assigned to look after them. Here is the full path to being licensed and defensible.
See the full journey22 steps ~199 min
Fintech or mobile money
High-volume, high-sensitivity financial data and automated decisions, across two regulators. This is the full programme.
See the full journey19 steps ~208 min
Clinic, hospital or health app
Patient data is sensitive data, the breach clock is 24 hours, and a DPIA is mandatory. Let's make sure patient data cannot sink you.
See the full journey18 steps ~193 min
School or education platform
Children's data at scale, and a new app in every classroom. Here is how to handle pupils' data properly and vet what you let in.
See the full journey19 steps ~204 min
App, SaaS or online shop
Privacy is a build task and a sales asset. Here is the order that gets you launched and through procurement.
See the full journey19 steps ~175 min
Charity or NGO
Donor data and beneficiary data are two different problems. Here is how to satisfy funders and protect the people you serve, cheaply.
See the full journey18 steps ~165 min
Working across the UK and Zimbabwe
Two regulators, one business, data moving both ways. Here is which rules apply where — and how to move data lawfully.
See the full journey11 steps ~129 min
I run it and I do everything
The shortest defensible path. Three things now, the rest when you have time.
See the full journey14 steps ~137 min
I was told to sort out the data thing
A vague task, turned into a concrete checklist you can act on and report upwards.
See the full journey13 steps ~145 min
I build the product
Privacy requirements as engineering tasks, in build order.
See the full journey10 steps ~108 min
I do the marketing
What you can legally send, to whom, on which channel — and how to do cookies and consent properly.
See the full journey15 steps ~132 min
I'm the (new) DPO
A full-programme baseline and a maturity roadmap you own.
See the full journey16 steps ~156 min
I advise clients on this
A repeatable diagnostic you can run per client, with exportable outputs.
See the full journey
By what you're trying to achieve
6 steps ~45 min
I want to stay out of trouble
Find what actually gets you fined, and confirm it is handled. Ranked, fix-first.
See the full journey6 steps ~74 min
I want to know what's expected of me
The map of your obligations, in plain language, tied to the actual law.
See the full journey3 steps ~22 min
I want to know if this applies to me at all
Whether the law reaches you, which regulators, and whether a licence or DPO is triggered. Under 50 subjects means no licence — the principles still apply.
See the full journey5 steps ~31 min
I want to register or get licensed
Confirmed tier, licence and DPO checklist, estimated fee, and what happens if you don't.
See the full journey4 steps ~35 min
I want to appoint or replace a DPO
Whether you need one, the certification and 90-day notification, and the competency gap.
See the full journey8 steps ~116 min
I want to launch my app or product compliantly
The full pre-launch privacy stack: data map, lawful bases, consent design, child flags, notice, DPIA screen, security baseline.
See the full journey3 steps ~29 min
Someone asked for their data
Respond correctly and on time: scope, identity check, exemptions, secure delivery.
See the full journey5 steps ~56 min
I want to market and email people legally
Consent versus legitimate interests per channel, a cookie fix-list, and the ad-platform sharing flags.
See the full journey6 steps ~50 min
I want to use AI without leaking data
Shadow-AI inventory, risk ranking, vendor and transfer flags, and whether a DPIA is now mandatory.
See the full journey8 steps ~66 min
I want to expand to a new country
Multi-regulator applicability, sequenced registration, transfer safeguards and a localised notice.
See the full journey8 steps ~67 min
I want to be investor or audit ready
The governance artefacts diligence will demand, formatted for a data room.
See the full journey6 steps ~81 min
I want to build customer trust
A graded notice, a transparency checklist, a consent-UX review, and a plain 'how we protect you' summary.
See the full journey5 steps ~43 min
I want to share data with a partner safely
Controller or processor, the agreement you need, the transfer verdict and the DPIA trigger.
See the full journey3 steps ~34 min
I want a quick privacy check
A fast, honest read — a number, your biggest gap, and which rulebook applies. About five minutes.
See the full journey8 steps ~75 min
I want to win this contract
Answer the security and privacy questionnaire and pass, with an evidence pack mapped to what buyers ask.
See the full journey4 steps ~33 min
Something happened — I need to handle a breach
Do the legally required things, in order, fast. Zimbabwe: 24 hours to POTRAZ, including a suspected breach. UK: 72 hours to the ICO.
See the full journey
By the question you came with
4 steps ~40 min
Do I even need to register or comply?
See the full journey5 steps ~37 min
Do I need a DPO?
See the full journey5 steps ~70 min
Do I need a privacy policy or notice?
See the full journey5 steps ~54 min
Consent, cookies and lawful basis
See the full journey5 steps ~54 min
Marketing and emails
See the full journey5 steps ~39 min
We had a breach
See the full journey5 steps ~41 min
Subject access and individual rights
See the full journey4 steps ~28 min
Keeping and deleting data
See the full journey5 steps ~44 min
Sending data abroad
See the full journey5 steps ~32 min
Working with vendors and processors
See the full journey5 steps ~65 min
Children's and sensitive data
See the full journey6 steps ~50 min
Using AI and new technology
See the full journey4 steps ~46 min
Fines and penalties
See the full journey
By sector
6 steps ~75 min
Clinic, hospital or health app — starter journey
Patient data is sensitive data, the breach clock is 24 hours, and a DPIA is mandatory. Let's make sure patient data cannot sink you.
See the full journey6 steps ~75 min
Small or medium business — starter journey
You don't need a privacy department — you need to know what actually applies to you. Confirm your tier, get your score, and fix things in that order.
See the full journey7 steps ~82 min
Law, accounting or consulting firm — starter journey
Confidentiality is your profession; the law now wants it evidenced. Check what client data you hold, your duties on information about third parties, and what happens the day a laptop goes missing.
See the full journey8 steps ~82 min
Bank, insurer, fintech or lender — starter journey
KYC files, credit histories and money moving across borders — the highest-stakes data there is. Size your exposure, settle the DPO question, and get transfers and vendors onto paper.
See the full journey8 steps ~93 min
School, university or training provider — starter journey
Minors' data needs the right consent and triggers a mandatory DPIA — and every parent, funder and employer request is a sharing decision. Here is the short route to getting pupils' data right.
See the full journey8 steps ~93 min
Product, data or AI team — starter journey
Your AI is only as compliant as the data it touches — and the tools you can't see are the first leak. Surface the shadow AI, score the estate, and build the data-flow evidence buyers ask for.
See the full journey7 steps ~98 min
Shop, marketplace or online store — starter journey
Loyalty schemes, marketing lists and checkout tracking all run on personal data. Check what you can legally send, what your app collects, and whether your notice keeps up.
See the full journey8 steps ~91 min
Government agency or parastatal — starter journey
Citizens can't choose another provider, so the CDPA holds public bodies to a higher bar. Confirm your tier and DPO duty, get ready for records requests, and put inter-agency sharing on a proper footing.
See the full journey7 steps ~92 min
Startup or SaaS founder — starter journey
Due diligence comes for every data-touching product — investors and enterprise buyers now ask before they sign. Confirm your tier, check what your app really collects, and finish with a market-entry roadmap instead of a compliance scramble.
See the full journey7 steps ~83 min
Charity or NGO — starter journey
Donors trust you with their money; beneficiaries trust you with far more. Check whether lighter obligations apply to you, get beneficiary and children's data on a safe footing, and be ready to show funders the notice they expect.
See the full journey