Risk and compliance resources

Practical guides for privacy compliance, AI governance, third-party risk and GRC / operational risk.

Privacy Compliance explained.

Short, plain-language explainers for the concepts that come up most often in privacy compliance work.

What is DPDx? Data Protection Dynamics framework

DPDx is a USA-focused privacy and data protection framework delivered through a specific PrivIQ partner, designed for organisations needing practical, evidenced privacy practices in the US market.

Read ->

What is privacy compliance software?

Privacy compliance software is a structured platform for managing privacy obligations across regulations - data inventories, ROPA, DSARs, breach response, processor oversight, consent and audit-grade evidence in one place.

Read ->

What is a DPIA? A guide to Data Protection Impact Assessments

A Data Protection Impact Assessment is a structured review of a processing activity that identifies privacy risks to individuals and decides how to mitigate them. GDPR requires one for high-risk processing - including most uses of AI on personal data.

Read ->

What is a TIA? A guide to Transfer Impact Assessments

A Transfer Impact Assessment evaluates whether personal data transferred outside the originating jurisdiction is afforded essentially equivalent protection. Required after Schrems II for most transfers from the EEA.

Read ->

What is a ROPA? Records of Processing Activities explained

A Record of Processing Activities is the structured inventory of how an organisation processes personal data. Required by GDPR Article 30, it underpins almost every other privacy activity.

Read ->

What is DSAR management? A guide to handling data subject requests

DSAR management is the structured workflow for receiving, validating, fulfilling and recording data subject requests - access, deletion, portability, correction, objection and similar rights.

Read ->

Privacy compliance software vs. spreadsheets – when to switch

Most privacy programmes start in spreadsheets. They rarely scale, and they almost never produce audit-grade evidence on demand. Here's how to know when it's time to move on.

Read ->

What is breach response and reporting?

Breach response is the structured handling of a privacy or security incident - discovery, evaluation, communication, recording and remediation. Tight regulator timeframes apply.

Read ->

What is GPDP? PrivIQ’s General Personal Data Protection framework

GPDP is PrivIQ's baseline privacy framework for organisations in jurisdictions without dedicated privacy regulation, or where a baseline personal data protection programme is required as a common floor across multiple jurisdictions.

Read ->

What is USCP? USA Consumer Protection privacy framework

USCP is PrivIQ's framework for organisations that need practical governance over consumer data handling, notices, rights, third-party risk and evidence of responsible practices in the USA's fragmented state-by-state landscape.

Read ->

AI Governance
explained.

Short, plain-language explainers for the concepts that come up most often in AI governance work.

Comparative Analysis

PrivIQ versus the legacy enterprise stack.

Side-by-side reviews of where PrivIQ Data Privacy Risk Management stands against the big incumbents – what they get right, where the gaps are, and what mid-market buyers should look out for.

PrivIQ vs OneTrust

One configurable engine versus a suite of separately-licensed modules.

PrivIQ vs TrustArc

Multi-jurisdictional engine versus a US-anchored privacy and consent platform.

PrivIQ vs PrivacyEngine

PrivIQ Data Privacy Risk Management vs PrivacyEngine

Ready to put any of this into practice?

Book a meeting or take the free 12-question assessment to see where your programme stands.