Practical Privacy
Privacy programs live or die on the small, everyday decisions people make - whether to record a meeting, how long to keep a spreadsheet, who gets access to a shared mailbox. This reference distills practitioner-tested guidance on the situations that come up again and again inside a modern organization: surveillance and monitoring, offboarding, meetings, remote work, surveys, talent data, individual rights requests, sensitive data, consent, secondary use, external and regulatory requests, digital products, breach response, records management, and marketing.
None of this is legal advice, and none of it describes any single company's internal program - it is a genericized synthesis of practices that recur across privacy programs, intended as a practical starting point you can adapt to your own organization's tools, policies and legal environment. Wherever it says "your organization," substitute your own employer's approved systems, escalation paths and legal counsel.
Jump to a topic:
- 1. Video Surveillance, Photography & Location Tracking
- 2. Offboarding: Protecting Data When Someone Leaves
- 3. Accessing Another Person's Mailbox
- 4. Meetings: Recording, Transcripts & AI Notetaking
- 5. Remote & Hybrid Work: Privacy Risks Outside the Office
- 6. Surveys, Polls, Quizzes & Competitions
- 7. Privacy Through the Talent Lifecycle
- 8. Handling Requests to Exercise Privacy Rights
- 9. Sensitive (Special-Category) Personal Data & Biometrics
- 10. Consent: When It's the Right Tool (and When It Isn't)
- 11. Secondary Use: Reusing Data for a New Purpose
- 12. Responding to External Requests for Data
- 13. AI, Analytics & Automated Decision-Making (Emerging Area)
- 14. Engaging with Data Protection Regulators
- 15. Website & Digital Product Privacy Compliance
- 16. Data Breach Response & Incident Reporting
- 17. Records Management, Retention & Secure Sharing
- 18. Marketing & Direct Communications Compliance
1 Video Surveillance, Photography & Location Tracking
Why it matters: Cameras, photos, GPS trackers, and workplace monitoring tools all capture personal information, often about people who never agreed to be filmed or tracked. Because these methods are inherently intrusive, they are only justified when there's a clear, lawful business need paired with real transparency and safeguards - not just because the technology is available.
Key actions
- Treat any recording or tracking technology as a personal-data activity from day one - complete a privacy impact assessment before deployment.
- Understand and comply with local privacy and labor law before installing cameras, trackers, or monitoring software.
- Define narrowly what data is collected and why; get sign-off from your privacy and security functions where relevant.
- Notify people through signage, onboarding materials, or direct communication - a camera or tracker that nobody knows about is a red flag.
- Signage should name the controller, the purpose, the retention period, and how to exercise rights or get more information.
- Build in opt-out functionality wherever legally required, and apply firm retention and deletion schedules.
- For photos and event footage: explain the purpose and where images will be used, get general consent for group shots and explicit consent for anyone singled out as a focal subject, store only on approved platforms, and delete once the purpose is served.
- For location/GPS tracking: limit scope to work activity, disable tracking outside working hours where possible, and delete location data promptly.
Never
- Install hidden cameras without an exceptional, documented approval.
- Point cameras at bathrooms, locker rooms, private spaces, public streets, neighboring properties, or individual workstations.
- Share footage externally without privacy review, copy it to personal devices, or use facial recognition without a completed assessment and formal sign-off.
- Enable location tracking secretly, use it as a backdoor for disciplinary monitoring without a proper legal basis, or turn it on by default without purpose and notice.
- Reuse photos or video for a purpose different from what people were told, or edit media in misleading ways.
Worked example - delivery fleet GPS A logistics team wants to add GPS tracking to delivery vehicles for route optimization and driver safety. Good practice: tracking is scoped to working hours and disabled outside them, data is retained only as long as needed for operational purposes, and drivers are told clearly what's tracked and why. A companion event app that offers optional location sharing makes it strictly opt-in, user-controlled, and deletes the data once the event ends.
2 Offboarding: Protecting Data When Someone Leaves
Why it matters: The moment someone leaves an organization is a high-risk moment for data - for the departing person's own privacy, and for the company's information. Good offboarding protects both: personal content gets removed from company equipment, business records stay findable in the right place, and access closes cleanly.
Key actions
- Before your last day, delete personal photos, downloads, saved passwords, browser history, personal accounts, and any other personal files stored on company equipment - this protects your own privacy.
- Move business information into approved shared systems (document management, team collaboration, cloud storage) before access is removed, and complete handover with your manager and colleagues.
- Return laptops, phones, tablets, badges, and any role-specific equipment - this enables device sanitization and access closure.
- Leave business records where they are. Only personal content should be deleted; work records must remain available for legal, retention, and operational purposes. If you're unsure whether something is personal or business-related, ask your manager or IT.
- Once a device is returned and processed, expect a mandatory secure wipe - local data is then unrecoverable, while cloud-based information stays subject to normal retention and access rules.
Never
- Copy company files to personal devices or personal cloud services, or forward work emails to a personal account.
- Retain company documents after employment ends, or attempt to access company systems after termination.
- Store business documents only locally during your notice period unless the role specifically requires it.
If you're unsure: ask your manager, IT support, or your organization's privacy team before you delete or move anything.
3 Accessing Another Person's Mailbox
Why it matters: Reading someone else's mailbox is an exceptional measure, not a routine convenience. It should only happen when it's strictly necessary, no less-intrusive option exists, and proper governance is in place - because mailbox content is personal information and often contains far more than the business need requires.
When access may be appropriate
- An employee is on extended or unexpected leave and business-critical information is trapped in their inbox.
- Someone is unresponsive in a way that threatens business continuity.
- A legal or regulatory investigation requires it.
- An employee has departed without properly handing over information.
Every one of these situations still has to satisfy purpose limitation, fairness, and proportionality.
Key principles
- Least privilege: access only the minimum content needed - broad, unrestricted mailbox reviews are prohibited.
- Authorized and logged: access should go through identity and access management controls, with a formal request, documented approval, periodic review, and immediate removal once no longer needed.
- Logging and monitoring: every access should be logged (user, timestamp, IP address, read/update activity), and those logs must themselves be protected from tampering.
- Privileged access is temporary: any elevated access must be justified, time-boxed, and removed the moment it's no longer required - avoid permanent elevation.
- Documentation: keep records of the request, business justification, approvals, who accessed the mailbox, when, and what was reviewed or copied.
- Treat everything retrieved as sensitive company information: store only in approved systems, minimize duplication, and apply retention rules.
- People should normally be told their mailbox was accessed, unless notification would compromise an investigation, legal process, or create regulatory issues.
Never
- Request or share someone's password, use shared or generic accounts, or otherwise circumvent privileged-access controls.
- Copy an entire mailbox without approval, or retain retrieved information beyond the business purpose.
- Treat mailbox access as routine - every instance needs its own justification and approval chain (people manager, HR, privacy/legal review, IT/security).
Worked example - urgent customer handoff An account manager becomes unexpectedly unavailable and a customer needs urgent information sitting in their inbox. Good practice: document the justification, get privacy sign-off, restrict access to the specific relevant emails, grant temporary time-bound delegated access rather than full mailbox access, and keep a complete access record.
Worked example - misconduct investigation An employee is placed on leave and evidence may exist in their mailbox. Good practice: legal and HR are engaged, privacy reviews the scope, access is granted only to authorized investigators, irrelevant personal communications are excluded, every approval and access event is logged, and access is removed the moment the investigation concludes.
4 Meetings: Recording, Transcripts & AI Notetaking
Why it matters: A single meeting can generate recordings, transcripts, captions, attendance reports, chat logs, polls, and AI-generated summaries and action items - any of which may contain personal information, confidential business content, or legal advice. Whoever organizes the meeting is responsible for how all of that gets handled through its lifecycle.
Key actions
- Ask, before enabling recording, transcription, or an AI notetaker: is this actually necessary? Would notes achieve the same goal? Who needs access to the output, and what risk does creating it introduce?
- Match the tool to the meeting: routine training, town halls, and workshops are usually fine to record; HR matters, investigations, and legal-advice discussions generally should not be, or need explicit privacy/legal/HR sign-off first.
- As the organizer, control the recording and sharing settings, review who has access, review retention, and review AI-generated outputs before they're relied upon.
- For sensitive meetings, prefer a standalone meeting invite over a channel-based one - channel meetings tend to inherit broader team permissions than the discussion warrants, so a standalone invite with a defined attendee list reduces exposure.
- Apply short, defined retention windows to recordings, transcripts, chat files, and AI-generated prompts and summaries rather than letting them accumulate indefinitely.
- Before the meeting, tell participants if recording, transcription, or AI summarization is enabled, why, who will see the output, and how long it will be kept.
- Set up the meeting deliberately: use a waiting room where appropriate, restrict who can present, review bypass settings, and keep external and internal discussions separate.
During the meeting
- Share a single window or application rather than your whole screen, and pause sharing before opening email or messages.
- Avoid displaying or reading aloud personal information that isn't necessary for the discussion.
- Treat chat messages, polls, whiteboards, transcripts, and AI outputs as records, not throwaway ephemera.
- Verify unexpected attendees before continuing sensitive discussion.
Always / Never for AI-generated outputs
- Always review AI-generated summaries and action items before treating them as accurate, validate decisions and actions, remove unnecessary personal data, and correct errors.
- Never assume an AI summary is complete, treat it as an official record without review, share it externally without approval, or paste meeting content into an unapproved AI tool. Only approved AI tools should touch company information.
For high-risk meetings (employee relations, grievances, investigations, incident response, health matters, legal advice, commercial negotiations): consider notes instead of a recording and minutes instead of a transcript, use a standalone meeting rather than a channel meeting, and enable a lobby/waiting room with restricted bypass.
5 Remote & Hybrid Work: Privacy Risks Outside the Office
Why it matters: Working from home, a café, or on the road moves personal data and sensitive business information into less controlled environments. The obligations don't change just because the location did - three lenses still apply: privacy principles (fairness, purpose limitation, minimization), security controls (device management, access, monitoring), and records hygiene (approved storage, retention, timely deletion).
Remote-working checklist
- Connect through trusted networks and an approved VPN.
- Use a company-managed device with encryption, anti-malware, and current updates enabled.
- Lock your device whenever you step away.
- Share links rather than files where possible, and restrict access to people with a genuine business need.
- Store information in approved systems of record, and clean up duplicate local copies.
Major risk areas and controls
| Risk area | Typical risk | Core controls |
|---|---|---|
| Networks | Public Wi-Fi or insecure home networks | Use an approved VPN and encrypted connections; avoid unknown VPNs or proxies |
| Devices | Loss, theft, or unpatched endpoints | Managed devices only, encryption and anti-malware on, prompt updates, never share accounts, report loss immediately |
| Information sharing | Uncontrolled sharing, duplicate copies | Follow classification rules, share links not files, avoid personal email/cloud storage/consumer messaging apps |
| Meetings & screen sharing | Unintended disclosure | Verify attendees, share application windows not full screens, disable pop-up notifications, record only with a legitimate reason |
| Physical environment | Screen and document visibility | Use privacy screens, angle displays away from others, secure paper documents, keep devices under your control |
| Printing & disposal | Paper bypasses retention controls | Avoid printing where possible, file information in approved systems, destroy paper securely, respect legal holds |
| Test/development data | Live personal data used outside production | Use anonymized or masked data, delete promptly after testing |
Working while mobile: use trusted connectivity or a secure hotspot plus VPN, confirm recipients actually need what you're sharing, share restricted links rather than attachments, apply the right classification label, avoid unnecessary downloads, and upload anything temporary to an approved system before deleting the local copy.
Never
- Create personal workarounds when a requirement seems inconvenient - escalate and ask for a compliant solution instead. Formal exceptions need written justification, compensating controls, and appropriate governance approval.
- Keep information "just in case," or delete information subject to a legal or tax hold.
- Use personal email as a shortcut - it bypasses identity, access, and logging controls entirely.
Worked examples
- Café deadline: use a hotspot plus VPN, share a restricted link rather than a file, save the final version to an approved system, and delete the local copy.
- Home printout of an HR document: print only if necessary, keep it secured, upload it to an approved system, and shred it after use.
- Lost laptop: report immediately, begin containment, and expect a privacy risk assessment.
- Screen-share slip: share application windows only, verify who's actually in the meeting, and only record when there's a real need.
Report immediately: lost or stolen devices, misdirected emails, suspicious logins, malware, or any unauthorized access - through your organization's incident-reporting channel or confidential reporting route.
6 Surveys, Polls, Quizzes & Competitions
Why it matters: Surveys, quizzes, and competitions feel informal, but they routinely collect names, contact details, opinions, and sometimes sensitive information - and the same privacy, security, and retention requirements apply whether the audience is internal employees or the public.
Key actions
- Use only approved, vetted platforms and vendors - never a random consumer quiz app.
- Be transparent: tell participants why the activity is running, whether identities are collected, where data is stored, how long it's kept, who can access it, and whether participation is voluntary.
- Collect only what's genuinely needed - skip sensitive or unnecessary questions.
- Store responses securely and restrict access; avoid local storage, personal devices, or unapproved systems.
- Use the data only for the purpose participants were told, unless you get fresh notice/approval for anything new.
- Delete responses when the retention period ends, and make sure any vendor involved does the same.
Never
- Use consumer-grade quiz or survey tools for anything work-related.
- Repurpose survey or quiz results for monitoring or performance management without telling people first.
- Try to re-identify participants in an "anonymous" survey.
- Collect sensitive categories of information (health, religion, politics, other protected characteristics) in a pulse-check or feedback tool.
Customer competitions and promotions carry more risk. Always: use approved vendors, publish a clear privacy statement covering purpose, data collected, retention, deletion, and any transfers; get consent where required; explain the rules and how winners are notified; delete entries on schedule; and keep marketing use of entrant data separate from - and dependent on - a distinct, freely given consent. Never: use unapproved vendors, collect more than necessary, use entrant data for profiling or marketing without consent, or share it with partners without approval. Larger promotional activities may need a formal privacy impact assessment - build that into the planning timeline.
Worked example - anonymous employee survey No names, IDs, or IP addresses collected; responses reported only in aggregate; purpose, storage location, access list, and retention period all explained up front; participation voluntary. This works because there's nothing to re-identify, and every transparency box is checked.
Worked example - mandatory training quiz Completion is mandatory and results are tied to an employee ID - but that's disclosed clearly, storage is limited to the learning platform, access is restricted to compliance/learning teams, a retention period is defined, and results are explicitly not used for performance management. Identity is necessary here, so the focus shifts to purpose limitation and access control rather than anonymity.
7 Privacy Through the Talent Lifecycle
Why it matters: From attracting candidates through onboarding, performance management, and eventual offboarding, people-data touches every stage of the employment relationship - and each stage carries its own minimization, access, and retention expectations.
Recruitment & candidates
- Do: collect only what's needed to assess suitability, tell candidates when background checks are part of the process, use approved vendors and processes, store CVs and interview notes only in approved HR systems, and keep interview questions tied to skills and role requirements.
- Don't: download CVs into personal folders, ask irrelevant questions about age, family, or health, search social media without a formally approved check, or use personal email/messaging apps for recruitment activity.
Onboarding
- Do: collect only what employment administration requires, store identity documents in approved systems, and restrict access to authorized administrators and HR.
- Don't: store passports, licenses, or bank details locally, or forward onboarding documents outside the organization.
Performance management
- Do: keep feedback factual and role-related, store reviews and development plans only in the approved HR system, and restrict access to authorized participants.
- Don't: include personal assumptions, keep screenshots or duplicate copies, or share performance information outside the authorized process.
Learning & development, talent reviews, succession planning
- Do: use approved learning platforms, follow meeting-recording guidance for recorded sessions, keep talent-review discussions confidential, and stick to factual information in approved templates.
- Don't: export talent data into personal spreadsheets, discuss readiness or potential informally, or move talent information across borders without approval.
Employee relations & sensitive cases
- Do: store information securely, restrict access to authorized personnel, follow the approved case-management process, and involve HR, legal, or privacy for complex matters.
- Don't: record meetings without justification and notice, share case details outside the authorized group, or keep local copies after the case closes.
Digital collaboration
- Do: use approved systems for storing and sharing people data, and think carefully about AI-generated meeting summaries before relying on them.
- Don't: upload employee information into external or unapproved AI tools, or reuse employee data for a new purpose without checking first.
Offboarding
- Do: remove access promptly, retain only what law or policy requires, and transfer employee documentation to HR.
- Don't: keep personal copies of employee files, access a former employee's information without authorization, or disclose it unless legally required.
8 Handling Requests to Exercise Privacy Rights
Why it matters: Anyone - an employee, former employee, candidate, customer, or supplier - can ask to access, correct, delete, or restrict their personal data, object to how it's used, or withdraw consent. These formal rights requests come with strict legal deadlines, so getting them to the right team fast matters more than trying to handle them yourself.
How to recognize one - it doesn't need legal language. Treat these as rights requests and escalate immediately:
- "Can I have a copy of my data?"
- "Delete my information."
- "Correct my information."
- "Stop using my information."
- "Who have you shared my information with?"
- "I withdraw my consent."
- "Please stop contacting me."
Usually NOT a rights request: updating a customer's account contact details, requesting a payslip, or changing a supplier's billing email - these are routine operational asks, even though they involve personal information.
What you should do
- Escalate immediately to your organization's privacy team through the approved channel.
- Do not investigate it yourself, verify identity independently, release information, or respond substantively - even a well-intentioned reply can undermine the formal process. If in doubt, escalate anyway.
What the privacy team typically does: verifies identity, confirms scope and request type, identifies affected systems, coordinates data collection, reviews information before release, tracks the legal deadline, and communicates with the requester. You may be asked to help locate or clarify data relevant to the request.
Typical statutory response windows (these vary by law and country - confirm current requirements locally):
- EU/GDPR-style regimes: one month, extendable by up to two additional months for complex cases, with the requester told about any extension within the first month.
- Australia: around 30 calendar days, with reasonable identity verification and possible access fees.
- New Zealand: around 30 days, with a similar approach to identity verification and possible extensions.
Roles typically involved: the requester (submits the request, provides ID, clarifies scope); HR (logs internal requests, supports ID verification, gathers HR-held information); the privacy team (end-to-end coordination, ID verification, tracking, final response); legal (exemptions, redaction, complex cases); and a security/e-discovery function (search and secure extraction of records).
Common scenarios: a former employee requesting access to their HR file, a candidate asking for erasure, an employee asking for a correction, a data-portability export, or someone objecting to marketing. Each follows a version of the same pattern - verify identity, confirm scope and retention obligations, take the appropriate action, and record the outcome.
9 Sensitive (Special-Category) Personal Data & Biometrics
Why it matters: Some categories of personal data create outsized harm if mishandled - racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health information, and sex life or sexual orientation. Most privacy laws single these out for extra protection, and organizations should never collect them casually.
When it may be collected or used - one of these has to genuinely apply:
- There's a clear legal obligation (health and safety requirements, regulated workplace processes, specific reporting duties).
- The individual has given explicit, informed, documented consent, understanding exactly what's collected, why, how it's used, and who sees it.
- The purpose is necessary, defined, and proportionate - if the task can be done without this level of detail, don't collect it.
If none of these apply, don't collect or use it. Talk to your privacy team first.
Valid scenarios: an employee shares medical information to request a workplace accommodation; a visitor provides biometric data for secure-site access where local law permits it and privacy has approved it; health information is collected to manage a workplace incident where required.
Not valid: asking candidates about health or family plans; keeping informal notes about someone's background or beliefs; storing medical certificates in personal email or local files; rolling out a biometric or health-data tool without an assessment.
Always
- Loop in your privacy team before collecting or using sensitive data, and explain clearly why it's needed.
- Use only secure, approved systems, limit access as much as possible, and delete the information as soon as it's no longer needed.
Never
- Collect sensitive data without a valid purpose, store it in spreadsheets or personal email, forward it to people who don't need it, or use unapproved tools that capture biometric or health data.
Biometrics deserve their own scrutiny. Biometric data means information about physical or behavioral features used to identify or classify someone - facial images and facial recognition, fingerprints, voice patterns, keystroke patterns, gait analysis. A project likely involves biometrics if it scans a face, voice, or behavior, compares physical features against a stored record, or uses those features to make decisions about identity, access, attendance, or classification.
Some jurisdictions (New Zealand is a useful example) have dedicated biometrics codes and rules layered on top of general privacy law - for instance, requirements around necessity and proportionality, clear safeguards, advance transparency, restrictions on emotion-detection or inferring ethnicity/gender, extra care for children's data, and specific notification duties when biometric data is collected indirectly (from a source other than the individual). The specifics vary by jurisdiction, but the pattern is consistent: pause, assess, and get privacy sign-off before any biometric processing begins.
Before any biometric processing:
- Stop and assess - pause the project until privacy confirms which rules apply.
- Complete a formal privacy impact assessment - this is not optional for biometrics.
- Be ready to show why biometrics are necessary and why nothing less intrusive would work, how people will be told, what safeguards apply, and how bias and accuracy risks are managed.
- Don't sign a vendor contract or activate a system before privacy review is complete.
Never, without privacy review: trial or test a biometric tool, upload images or recordings of employees, contractors, or customers into an AI or cloud-based biometric system, use tools that infer emotion or other sensitive characteristics, or roll out facial recognition for attendance or access.
10 Consent: When It's the Right Tool (and When It Isn't)
Why it matters: Consent is the most misunderstood legal basis in privacy. It's often reached for by default, but it only works when people have a real, free choice - and many everyday business activities (payroll, security checks, performance management, access control) don't offer that choice, so consent is the wrong tool for them.
When consent is not the right basis: for anything people can't realistically refuse without a negative work consequence - payroll, IT security, safety checks, performance management, access control, or mandatory compliance activities. These rely on other lawful bases (contract, legal obligation, legitimate business need) paired with clear notice, not a tick-box.
Valid consent must be:
- Informed - the person understands what's collected, why, for how long, and who it's shared with.
- Voluntary - given freely, with no pressure or penalty for refusing.
- Specific and current - tied to a clearly defined purpose, and not assumed to survive a change in context.
- Given by someone with capacity - able to understand and communicate the decision (with extra care for minors, vulnerable individuals, or language/comprehension barriers).
Before adding a consent checkbox, ask: Is this actually optional? Can people say no without any negative impact? Is there a better basis (contract, legal obligation, safety, legitimate need)? Will people actually understand what they're agreeing to? Can withdrawal be tracked and honored? If the answer to any of these is no, consent probably isn't the right choice.
Do
- Use express consent (a signature, a verbal recording, a ticked box) for sensitive data or higher-risk activities.
- Keep each purpose separate - never bundle unrelated processing into one all-or-nothing request.
- Make withdrawal as easy as giving consent in the first place, and honor it promptly.
- Keep records of consent and withdrawal in line with your retention rules.
Don't
- Rely on silence, pre-ticked boxes, or inaction as consent.
- Use implied consent for sensitive data or high-risk uses - where there's any doubt, use express consent instead.
- Assume old consent still applies once the purpose, scope, or context has materially changed.
- Treat a privacy notice as consent - a notice informs; consent grants permission. They are not interchangeable.
Where consent works well: optional event photography, opt-in newsletters, voluntary wellbeing programs, and using someone's story or quote with their permission - situations where saying no genuinely carries no downside.
Marketing-specific note: consent (not implied browsing behavior) should back any optional communications, profiling, or non-essential cookie tracking; operational messages like safety notices or delivery confirmations generally rely on a different basis.
11 Secondary Use: Reusing Data for a New Purpose
Why it matters: Data collected for one purpose can't just be reused for another because it happens to be available. Every proposed new use needs its own check for lawfulness, transparency, and proportionality - reusing CCTV footage for an unrelated investigation, or repurposing delivery data for marketing analysis, are both examples of "secondary use" that need fresh scrutiny.
Core principles
- Confirm the original purpose first. If a proposed new use doesn't clearly fit what people were originally told, treat it as secondary use - even a small shift in purpose counts.
- Don't assume existing consent or notices cover a new purpose. A new use may need an updated notice, new consent, a new legal basis, a fresh privacy assessment, or added safeguards.
- Be transparent when purpose, processing, or audience changes - update privacy notices, system descriptions, or communications as needed.
- Never let a secondary use cause harm, create bias or discrimination, or happen just because the data exists.
- Document the decision: business justification, compatibility assessment, legal basis, consent status, privacy-review outcome, and final approval.
Escalate immediately when: the purpose differs materially, sensitive or children's data is involved, an automated decision could affect someone, a new vendor or third party is involved, data will cross borders, anonymization isn't possible, or data is being requested for a use that hasn't been assessed.
Common scenarios
- Marketing/advertising: using purchase history for targeted campaigns - assess compatibility, get consent where required, prefer pseudonymized data, and maintain suppression lists; never target sensitive categories or market to people who've opted out.
- Analytics & AI: training a model on internal data - prefer anonymized or pseudonymized datasets, complete a privacy assessment, test for bias, and maintain governance; never train on identifiable data without approval.
- Product development: using customer insights for new products - use aggregated or anonymized data, assess compatibility, update notices, and limit retention; never combine datasets in a way that could re-identify people without assessment.
- New vendor processing: bringing on a new analytics vendor - engage privacy, confirm the legal basis, put a data processing agreement in place, complete security due diligence, and confirm safeguards for any cross-border transfer.
12 Responding to External Requests for Data
Why it matters: Law enforcement, regulators, courts, insurers, and other outside parties occasionally ask for information - CCTV footage, personal data, access logs, visitor records, incident reports. These are different from individual rights requests, and the core rule is the same every time: never hand data over directly.
Core rule: if an external party asks for data, don't provide it and don't release it - escalate to your privacy and legal teams, who will determine whether disclosure is lawful, verify legal authority, minimize what's shared, confirm a secure transfer method, and maintain a full record of the disclosure.
Escalate for review whenever: personal data is involved (images, names, IDs, logs, audio, biometric data); the request is voluntary rather than backed by a court order or statutory notice; information would cross a border; the scope is broad or unclear ("all footage," "all logs"); or the request touches something especially sensitive (audio, staff facilities, high-risk areas).
What to gather before escalating: requester name, organization, and official contact details (badge/registration number for law enforcement); the type of request; the legal basis (court order, subpoena, warrant, regulatory notice); the precise scope (dates, times, location, camera or system identifiers); the data type requested; and any transfer requirements.
When disclosure may proceed: the request serves the same or a directly related purpose (a security or safety investigation), it's required or authorized by law, or the individual has actually consented. Minimize wherever possible - a specific camera, a specific timeframe, a specific incident, never a blanket handover.
Always
- Use secure transfer methods, restrict recipients, apply password protection and link expiration, minimize what's shared, and document the disclosure.
- Get external recipients to agree to use the information only for the approved purpose, avoid forwarding it, store it securely, delete it after use, and confirm deletion.
Never
- Send footage or data as an ordinary email attachment, share more than necessary, or release anything independently without review.
Emergency disclosures (rare): serious threat to life, medical emergency, missing person, natural disaster, or a court order can justify disclosure without consent - but even then, verify identity, share only what's necessary to manage the emergency, minimize (confirm presence or approximate location before anything broader), document everything (legal basis, requester, data disclosed, date, time, approver), and notify your privacy team immediately afterward. A request from a family member or friend, or from a third-party partner like a hotel or airline, should not lead to direct disclosure - refer it to emergency services or verified authorities instead.
13 AI, Analytics & Automated Decision-Making (Emerging Area)
Why it matters: AI-driven analytics and automated decision-making are moving fast, and formal guidance in this space tends to evolve quickly as tools and regulation mature. The underlying principles, though, are stable and worth applying even while detailed policy catches up.
Key actions
- Keep a human in the loop for any decision that meaningfully affects a person - treat AI outputs as a draft or input, not a final answer.
- Verify AI-generated outputs for accuracy before relying on them, especially facts, numbers, and anything used in a decision about a person.
- Use only approved AI tools for company or personal data - never paste confidential, personal, or sensitive information into a public or unapproved AI tool.
- Assess new AI-driven personalization, profiling, or automated-decision features for fairness and bias before launch, the same way you would any new data use.
- When in doubt about whether a specific automated process needs a privacy assessment, ask early rather than after launch.
Because this is an area where formal guidance shifts often, always check your organization's current AI/data-and-analytics policy for the latest specific requirements rather than relying solely on general principles.
14 Engaging with Data Protection Regulators
Why it matters: Regulators can investigate complaints, run inspections, and enforce privacy law - and how an organization responds in the first few minutes of contact matters. The core rule is simple: individuals should never engage with a regulator independently; every contact gets routed to the privacy and legal teams immediately.
Core rule - never engage independently. If a regulator calls, emails, writes, or shows up on-site, don't respond on your own. This applies just as much when a customer threatens to escalate to a regulator, or a supplier or partner signals regulator involvement.
Always involve your privacy team when: a regulator makes contact; inspectors arrive on-site; an authority requests information involving personal data; a complaint might escalate to a regulator; a privacy incident (or near miss) occurs; or a third party threatens regulatory action.
External communications discipline: don't send anything externally without approval - emails to regulators, government responses, incident reports, data extracts, screenshots, logs, or investigation notes all need review first.
If a regulator shows up unannounced:
- Reception/first contact: stay calm and professional, notify local leadership immediately, avoid handing over documents or granting access before authorized staff arrive.
- Local leadership: attend promptly, contact the privacy team immediately, wait for guidance before any substantive engagement.
- Privacy team: guides the inspection, confirms what can be disclosed, coordinates with legal and security, and records everything requested and disclosed.
- Everyone else: refer the regulator to the right lead; avoid explaining internal processes or discussing data handling unless specifically instructed to.
Example scenario - unannounced inspection: representatives from a data protection authority arrive at an office unexpectedly. Reception notifies leadership; leadership engages politely and calls the privacy team immediately; privacy coordinates with legal and security; every request and disclosure gets documented; information is released only after appropriate review. The result: a consistent, legal, and transparent response instead of an improvised one.
15 Website & Digital Product Privacy Compliance
Why it matters: Public-facing websites, microsites, portals, and mobile experiences all collect personal data - and just because something is technically possible on the web doesn't mean it's legally permitted. Privacy has to be considered before launch, not bolted on afterward.
When a formal review is required - raise it whenever you're:
- Launching something new (a website, microsite, portal, or campaign site).
- Adding new functionality (forms, cookies, pixels, tracking or analytics technologies).
- Changing the underlying technology (hosting provider, vendor, platform migration).
- Changing what's processed (new data categories, new markets, new AI capabilities, new automation).
- Using production/live personal data in testing, pilots, or pre-production environments.
A digital asset shouldn't launch or be materially modified without that review being complete - it should cover privacy, legal, procurement, technology, and security sign-off.
What the review should confirm: the correct lawful basis and consent mechanism; accurate, accessible, current privacy notices; defined retention and rights-handling processes; appropriate vendor contracts (processor obligations, transfer mechanisms, audit rights, deletion obligations, subprocessor terms); and secure hosting, access controls, encryption, and logging.
Common red flags and fixes
| Red flag | Fix |
|---|---|
| Analytics or tracking pixels firing before consent | Disable the tags, fix consent settings, retest |
| Outdated privacy notice | Update and republish |
| Excessive form fields | Remove unnecessary fields, update the notice |
| Undisclosed scripts | Remove, reassess, update the tracking inventory |
| Unapproved hosting location | Pause launch, assess cross-border transfer implications |
| No deletion evidence from a vendor | Get written confirmation |
| Access left active for a former team member | Remove access, review logs |
| New behavioral tracking or AI introduced without review | Route back through the review process |
Employee quick checklist
- Must do: get the required review, use approved vendors, use the correct privacy and cookie notices, block non-essential cookies before consent, minimize data collection, use HTTPS and MFA, restrict access, and define deletion arrangements.
- Must not: add undeclared tracking pixels or scripts, relaunch an old site without review, reuse an outdated notice, or retain data indefinitely.
Worked example - seasonal marketing microsite A marketing team plans a standalone campaign site that collects emails and competition entries and uses tracking pixels for analytics. Required controls: privacy involvement from the start, a cookie-consent banner, a campaign-specific privacy notice, data minimization in the entry form, and a defined retention schedule for entries once the campaign ends.
16 Data Breach Response & Incident Reporting
Why it matters: If you suspect a privacy or security incident - a misdirected email, unauthorized access, a lost device, malware, improper disposal of records - report it immediately. Speed matters more than certainty: many privacy laws impose strict regulator-notification windows (commonly measured in hours, not days) once an organization becomes aware of a reportable breach, and delay directly increases legal, financial, and reputational risk.
Key principle: you don't need to be certain. If something looks unusual or wrong, report it. Don't investigate alone, and don't wait until you have all the facts - early reporting is always preferred, and "when in doubt, report" is the operating rule.
How to report: through your organization's incident-reporting channel (portal, dedicated form, or direct email to your privacy/security team) - whichever your organization has published as the approved route.
Common incident types
- Email errors: sent to the wrong recipient, a "reply all" disclosure, misdirected customer or payroll data.
- System access issues: unauthorized HR or finance access, shared credentials, a former employee's account still active.
- Physical security: unattended printed documents, lost laptops, phones, or USB devices.
- Cyber threats: phishing, malware, ransomware, suspicious links.
- Improper disposal: confidential documents in general waste, hardware disposed of without wiping.
Incident lifecycle
- Intake - the incident is reported (e.g., a spreadsheet sent to the wrong recipient); immediate reporting is required.
- Investigation - what happened, what data and systems were involved, who was affected; containment (email recall, access removal, patching) can start immediately.
- Assess & decide - severity, harm, and whether regulatory or individual notification thresholds are met.
- Notify - regulators and/or affected individuals are notified where required, and post-incident improvements are considered.
Always: be alert, report immediately through the approved channel, respond to follow-up questions, and preserve evidence. Never: delay reporting, try to handle an incident independently, or wait until every fact is confirmed before raising it.
17 Records Management, Retention & Secure Sharing
Why it matters: Good record-keeping isn't just a compliance checkbox - it's how an organization protects its people and its business from information that's misused, lost, or seen by the wrong people. Every piece of information moves through a lifecycle (create, store, use, share, retain/archive, delete), and risk grows whenever data is overshared, kept too long, or stored in the wrong place.
A simple storage model
| Location type | Purpose | Appropriate use |
|---|---|---|
| Personal working space | Individual drafts, work in progress | Not for long-term or team records |
| Active collaboration space | Live team projects, shared editing | Keep access limited and review it regularly |
| Structured organizational storage | Final, managed, long-term records | Records that must stay findable and retained |
Through the lifecycle
- Create: collect or record only what's genuinely required; avoid "just in case" data; use existing systems of record rather than spinning up new copies; name files clearly; remember informal notes and emails can become records.
- Store: be intentional about which storage tier something belongs in; apply sensitivity labels to control access, and retention labels so records are kept and deleted correctly.
- Use: access only what your role needs; move meaningful content out of ephemeral chat channels and into governed locations - chat history that auto-deletes is not a substitute for a proper record.
- Share: share links instead of attachments; default to naming specific people rather than broad groups; check access before sending, especially for folders; explain security or retention expectations when sharing externally.
- Retain & archive: follow approved retention schedules; keep information only as long as legally or operationally required; move inactive records to designated archives; make sure backups don't quietly extend retention beyond the approved period; apply legal holds only when formally instructed.
- Delete: delete records once retention requirements are met, through the proper deletion process; shred paper and securely erase electronic files; confirm no legal, tax, audit, or regulatory hold applies first.
Classification labels - a simple four-tier model works well for most organizations:
| Label | Meaning | Examples |
|---|---|---|
| Public | Approved for public release | Published marketing material, public reports |
| Internal | Routine internal material, no personal or confidential data | Internal updates, templates without personal data |
| Confidential | Personal data or commercially sensitive information | Names, emails, phone numbers, IDs, contracts, pricing |
| Highly confidential | Sensitive personal data or high-risk operational information | Health data, payroll, identity documents, investigations |
When in doubt, choose the more restrictive label and ask.
Preventing accidental sharing of personal information
- Check the file first: look for hidden tabs, rows, or calculations; filters that hide rather than remove data; pivot caches with extra detail; comments, tracked changes, and old versions; embedded formulas, links, or objects. Use built-in document-inspection tools before sending anything out.
- Share the minimum necessary: ask what outcome the recipient actually needs; prefer aggregated, masked, or anonymized data; replace names with roles or functions where individual-level detail isn't needed; avoid exporting complete datasets.
- Validate recipients: confirm a genuine business need, confirm distribution-list ownership and current membership, and don't rely on autocomplete as your only recipient check.
- Use secure methods: prefer links over attachments, apply the correct sensitivity label, respect data-loss-prevention warnings, use time-limited and view-only external links, and disable downloads when not required.
- Clean up afterward: remove personal-level data from working copies once you're done with them, delete temporary files, and apply the correct retention label to the final record - but never purge anything that may be under a legal or audit hold.
- If something is shared by mistake: contact recipients and ask them to delete all copies, pause further sharing, tell your manager, report it to your privacy team immediately, and record who received it, when, what fields were included, and what containment steps were taken. Don't create new copies or request unnecessary screenshots containing the personal data in the process.
Using AI assistants (e.g., Copilot-style tools) responsibly
- Be clear about the task, tone, and output format you want, and work step by step.
- Review and verify outputs - especially facts, numbers, and assumptions - before relying on them.
- Never paste highly sensitive or restricted personal data into an AI assistant.
- Use only your organization's approved, sanctioned environment for it.
- Maintain human judgment and accountability throughout - don't use an AI assistant as a data repository, and clean up duplicate AI-generated content when retention rules allow.
Everyday security habits
- Change passwords when prompted (and sooner if you suspect compromise); never reuse the same password across services; never store passwords in notebooks, screenshots, or email drafts.
- Approve multi-factor authentication prompts only when you triggered them yourself - decline and report anything unexpected.
- Keep devices and key applications updated; avoid unapproved browser extensions; periodically review who has access to your documents and team spaces, especially external guests.
- Don't link personal email, cloud storage, or messaging accounts to a work device, and don't send work files through personal channels.
- Lock your device whenever you step away; don't leave printed personal data unattended; shred paper containing personal data.
Manager checklist
- Reinforce minimum-necessary sharing and avoid emailing large datasets; make sure staff can spot and remove hidden content in files.
- Review report recipients and distribution lists regularly, and prefer aggregated or pseudonymized data by default.
- Review team access, permissions, and file locations at least quarterly; remove departed team members and unnecessary access; prefer group-based over individual direct permissions.
- Make sure incidents and near-misses get reported immediately, and periodically review whether there's a safer way to handle recurring reporting needs.
18 Marketing & Direct Communications Compliance
Why it matters: Marketing uses personal information - emails, phone numbers, device and cookie identifiers, behavioral profiles - and is one of the most heavily regulated areas of data use. It carries meaningfully higher regulatory risk than routine operational customer communication, and regulators actively enforce against violations.
What counts as marketing: any communication whose primary purpose is to promote products or services, increase sales or engagement, or drive sign-ups - promotional emails, SMS campaigns, push notifications, newsletters, loyalty programs, competitions, product recommendations, cross-selling, event invitations, and behaviorally targeted advertising. It's still marketing even when sent to existing customers, and adding a promotional link to an otherwise operational message can convert the whole thing into marketing.
Core requirements
- Consent: valid opt-in consent before sending marketing, recorded with a timestamp, the exact wording shown, the channel, and the source - and consent should be channel-specific (email consent doesn't cover SMS).
- Transparency: people should understand who's collecting their data, why, how it's used, and how to unsubscribe.
- Unsubscribe: every marketing message needs a genuinely working, easy opt-out, processed promptly (some jurisdictions set a hard deadline - Australia, for example, requires processing within five business days).
- Truthful classification: never mislabel marketing as a service communication, or hide promotional content inside an operational message - this is one of the most commonly enforced violations.
- Data security: marketing data should be securely stored, appropriately protected, and only shared with approved vendors under proper transfer mechanisms.
Before launching any campaign, confirm: clear opt-in exists, the data source is lawful, the unsubscribe mechanism actually works, the vendor is approved, data collected is minimized, targeting isn't inappropriate, and any required privacy review is complete. If any of these isn't satisfied, don't launch.
Profiling and personalization: before using segmentation, behavioral analytics, audience modeling, or lookalike audiences, confirm the privacy notice actually covers it, apply data-minimization principles, and avoid any sensitive-category profiling (health- or ethnicity-based inferences, for example).
Marketing to children needs enhanced controls: never knowingly target, profile, or track children's behavior without review, and always involve privacy and legal before any campaign involving minors.
Using third-party/broker data: confirm it was lawfully collected and that individuals were informed (no scraping or deceptive collection); don't repurpose it for profiling or matching without review; make sure people are told when data comes from an indirect source; and put contractual controls in place (processing restrictions, security, audit rights, offshore-processing terms) before use.
What must never happen
- Mixing promotional content (discounts, product links) into service communications like delivery notices or order confirmations.
- Sending marketing without a functional, free unsubscribe mechanism.
- Assuming a message isn't "marketing" just because it's automated, triggered, or framed as a renewal or alert - any promotional content makes it marketing.
- Assuming a vendor will handle compliance for you - the sending organization remains accountable for template review, governance, and approvals.
A real-world cautionary example: a regulator fined a well-known apparel retailer roughly AUD 700,000 for sending more than 370,000 emails without a working unsubscribe mechanism - the messages contained promotional content but were treated as service communications. The lesson holds everywhere: keep service and marketing communications completely, structurally separate.
Marketing golden rules: get valid consent first and keep evidence of it; use only approved vendors; always include a working unsubscribe; never hide marketing inside a service message; minimize personal data collected; protect customer information; involve privacy for profiling, children's data, broker data, or unusual campaigns; keep it transparent; and if you're not sure, ask your privacy team before launching.