California privacy operations guide
A source-backed operating map for California privacy risk assessments, consumer requests and DROP readiness.
Start with the job in front of you. Each guide turns current official material into a bounded operating record without pretending to make the final legal or risk decision.
Each guide explains a bounded operational task and links to the official material used in its review.
A source-backed operating map for California privacy risk assessments, consumer requests and DROP readiness.
The facts, controls and decision records needed for a reviewable California privacy risk assessment.
A practical evidence checklist for the California Delete Request and Opt-out Platform route.
How to preserve receipt, verification, routing, deadlines and delivery evidence for a California privacy request.
A practical operating model for AI inventory, supplier review and accountable AI decisions using NIST sources.
The minimum fields that make an AI system inventory usable for ownership, risk review and change control.
Evidence to collect before relying on an AI supplier for a material organisational use case.
A repeatable structure for recording an AI approval, restriction, monitoring decision or stop decision.
A source-backed operating map for KYC remediation and official sanctions data handling.
A practical checklist for finding incomplete, stale and contradictory KYC records without automating the risk decision.
How to record an OFAC source file, verify its digest and preserve a reproducible normalisation run.
The operational boundary between restructuring official list data and deciding whether a customer or transaction matches.
A practical explanation of the UK duties to facilitate, acknowledge, investigate and record data protection complaints.
How to calculate and record the UK data protection complaint acknowledgement deadline, including weekends and public holidays.
How to distinguish a UK data protection complaint from a data rights request and handle a message that contains both.
A practical field list for a UK data protection complaints register, case chronology and evidence record.
Practical steps for publishing a clear, accessible UK data protection complaints procedure and complaint form.