Expertise / 03

PRIVACY & DATA

Privacy governance from legal obligation to operational control.

Privacy compliance depends on more than policies and notices.

OSTRAI helps organisations establish the governance, accountability, documentation, controls and decision-making structures needed to manage personal data lawfully across products, services, operations and technology environments.

Our work combines regulatory interpretation with practical implementation across privacy governance, data protection engineering, risk, transfers, incident response, international privacy frameworks and the wider European data regulatory landscape.

Layered glass and stone privacy sculpture in soft architectural light

PRIVACY & DATA GOVERNANCE

Privacy obligations operate across the data lifecycle.

Privacy regulation applies across the way organisations collect, use, share, retain, secure and delete personal data.

The regulatory position depends on the nature of the processing, the organisation's role, the purposes and legal bases involved, the categories of data and individuals affected, the systems and third parties used, and the jurisdictions through which data moves.

OSTRAI helps organisations bring these elements into one coherent privacy-governance framework.

  1. Processing context

    Purpose · Data · Individuals · Systems · Business activity

  2. Regulatory role

    Controller · Processor · Joint controllership · Other roles

  3. Lawfulness & transparency

    Legal basis · Fairness · Notices · Purpose limitation

  4. Risk & accountability

    DPIA · RoPA · Controls · Governance · Evidence

  5. Data flows & third parties

    Processors · Vendors · Sharing · Transfers · Contracts

  6. Continuing compliance

    Rights · Incidents · Monitoring · Changes · Regulatory response

PRIVACY & DATA ADVISORY

From processing activity to accountable governance.

OSTRAI supports organisations in translating privacy and data-protection requirements into governance, documentation, operational controls and continuing compliance.

  1. Privacy governance & accountability

    Privacy frameworks, governance structures, responsibility mapping, policies, decision-making processes and accountability evidence.

  2. RoPA, data mapping & processing analysis

    Records of processing activities, processing inventories, data-flow analysis, controller / processor role assessment, legal-basis analysis and processing documentation.

  3. DPIA, risk & privacy by design

    Data protection impact assessments, high-risk processing analysis, privacy-by-design requirements, mitigation measures and integration into product and operational decision-making.

  4. International data transfers

    Transfer mapping, adequacy analysis, Standard Contractual Clauses, transfer impact assessments, supplementary measures and cross-border data-transfer governance.

  5. DPO & continuing compliance

    DPO support, independent monitoring, compliance advice, governance review, training, audits, regulatory monitoring and ongoing privacy-function support.

  6. Incidents, rights & regulatory response

    Personal-data breach assessment, notification support, data-subject rights, complaints, supervisory-authority engagement, investigations and corrective-action support.

  7. Data regulation & data access

    Data Act, Data Governance Act, data-access and sharing obligations, connected-product data, data spaces and sector-specific data frameworks.

  8. International privacy & representation

    Multi-jurisdiction privacy programmes, EU and UK GDPR representation, territorial-scope analysis and regulatory coordination across selected international frameworks.

Stone arch and transparent panels beside a stack of governance volumes

ACCOUNTABILITY

Compliance must be demonstrable, not assumed.

The GDPR accountability principle requires organisations not only to comply, but to be able to demonstrate compliance.

That requires a connected body of governance, records, decisions, assessments, controls and evidence that reflects how processing actually takes place.

OSTRAI supports organisations in building that evidence around real processing activities rather than producing documentation in isolation.

  1. Governance

    Roles · Responsibilities · Escalation · Oversight

  2. Documentation

    RoPA · Policies · Notices · Assessments · Decisions

  3. Controls

    Access · Retention · Third parties · Security · Rights

  4. Evidence

    Approvals · Reviews · Monitoring · Remediation · Audit trail

RECORDS OF PROCESSING

The RoPA should describe the organisation that actually exists.

A Record of Processing Activities is not simply an inventory of forms or systems.

A useful RoPA should identify coherent processing activities and document the purposes, individuals, personal data, recipients, transfers, retention, systems, security context and organisational responsibility associated with them.

OSTRAI supports organisations in designing RoPA methodologies, reviewing existing records, identifying gaps and rebuilding processing records where the existing structure does not provide a reliable compliance picture.

  1. Define processing activities

  2. Map purposes & roles

  3. Map data, individuals & recipients

  4. Assess legal basis & transfers

  5. Retention & security context

  6. Validate with process owners

  7. Maintain & govern

DPIA & RISK

Risk assessment must follow the processing, not a template.

Where processing is likely to result in a high risk to individuals, the DPIA becomes part of the organisation's decision-making and accountability process.

OSTRAI supports DPIAs from initial screening through processing analysis, necessity and proportionality assessment, risk identification, mitigation and residual-risk evaluation.

  1. Processing analysis

    Nature · Scope · Context · Purpose

  2. Necessity & proportionality

    Legal basis · Data minimisation · Purpose · Alternatives

  3. Risk to individuals

    Likelihood · Severity · Rights · Consequences

  4. Mitigation & decision

    Controls · Residual risk · Approval · Consultation where required

Layered glass panels and privacy-by-design volumes on a stone surface

PRIVACY BY DESIGN

Privacy requirements should enter the design process early.

Privacy by design and by default require data-protection considerations to be integrated into products, services, systems and operational processes rather than added after implementation.

OSTRAI supports organisations in translating legal requirements into design decisions, governance controls and implementation evidence.

  1. Data minimisation

    What data is actually required?

  2. Default settings

    What happens before the individual takes action?

  3. Access & separation

    Who can access data and for what purpose?

  4. Lifecycle controls

    Collection · Use · Retention · Deletion · Change

INTERNATIONAL DATA TRANSFERS

A transfer mechanism is only one part of the analysis.

Cross-border transfers require organisations to understand where personal data moves, who receives it, what transfer mechanism applies and whether the destination environment affects the level of protection.

OSTRAI supports transfer programmes across data mapping, transfer mechanisms, transfer impact assessment, contractual implementation and supplementary measures.

  1. Transfer mapping

  2. Transfer mechanism

  3. Destination analysis

  4. Supplementary measures

  5. Documentation & governance

Adequacy · SCCs · Transfer impact assessments · Supplementary measures · Processor chains · Continuing review

DATA RELATIONSHIPS

Contractual roles must reflect the real processing relationship.

Privacy responsibilities depend on the factual and legal role performed by each organisation.

OSTRAI advises on controller, processor and joint-controller positions, processor appointment, sub-processing, data-sharing arrangements and allocation of responsibility across complex technology and service relationships.

  1. Controller

    Purpose · Means · Accountability

  2. Processor

    Instructions · Security · Assistance · Sub-processors

  3. Joint controllers

    Shared determination · Allocation · Transparency

  4. Data sharing

    Purpose · Legal basis · Responsibility · Governance

DATA REGULATION

Privacy is one part of the European data framework.

The European data rulebook increasingly governs not only the protection of personal data, but also access to, use of, sharing of and portability of data across products, services and sectoral ecosystems.

OSTRAI advises organisations on the interaction between privacy law and the wider European data framework, including the allocation of rights, obligations and governance across personal and non-personal data.

  1. Data Act

    Connected-product data · User access · Data sharing · Third-party access · Cloud switching · Contractual data terms

  2. Data Governance Act

    Data intermediation · Data altruism · Reuse of protected public-sector data · Data-sharing governance

  3. European Health Data Space

    Health data · Primary use · Secondary use · Access · Reuse · Governance

  4. Data Spaces & sectoral data regimes

    Common European Data Spaces · Sector-specific access and sharing · Interoperability · Governance

OSTRAI assesses these frameworks alongside GDPR and other applicable privacy rules where the same data, products or services engage several regulatory regimes.

Data Act Legal Representative

MULTI-JURISDICTION PRIVACY

Privacy programmes increasingly need to work across jurisdictions.

Organisations operating internationally may need to reconcile several privacy regimes across the same products, systems, data flows and governance structures.

OSTRAI advises on European privacy requirements alongside selected international frameworks, helping organisations identify where obligations converge, where they differ and how a coordinated operational programme can support compliance across jurisdictions.

  1. European Union

    EU GDPR · ePrivacy framework · EDPB guidance · Member State requirements

  2. United Kingdom

    UK GDPR · Data Protection Act 2018 · PECR · Data (Use and Access) Act 2025

  3. Middle East

    KSA PDPL · UAE PDPL · Egypt data-protection framework · Local implementation requirements

  4. Cross-jurisdiction programmes

    Governance mapping · Transfers · Notices · Rights · Processor relationships · Incident processes

The objective is not to force different legal regimes into one model, but to identify common operational controls while preserving jurisdiction-specific requirements.

EU & UK GDPR REPRESENTATION

A regulatory representative is more than a contact address.

Controllers and processors established outside the European Union or United Kingdom may, depending on their territorial activities and the applicable exemptions, be required to appoint a representative under the relevant GDPR framework.

EU and UK GDPR representative services are distinct appointments. UK GDPR Representative services are provided through PRIVACY MINDERS (UK) LIMITED, a UK-established company. OSTRAI supports organisations in establishing the separate representation arrangements, maintaining the required regulatory interfaces and coordinating privacy matters under each mandate.

  1. Territorial scope

    Offering goods or services · Monitoring behaviour · Establishment analysis · Applicable exemption

  2. Formal appointment

    Written mandate · Representative details · Privacy notices · Processing records

  3. Regulatory interface

    Data subjects · Supervisory authorities · ICO · Requests · Communications

  4. Continuing support

    Processing changes · Rights · Complaints · Regulatory enquiries · Compliance coordination

EU GDPR Representative

EU GDPR representation for organisations within the relevant territorial scope, with the representative established in the European Union in accordance with the applicable requirements.

UK GDPR Representative

UK GDPR representation for organisations within the relevant territorial scope, with the representative established in the United Kingdom.

The representative acts as a contact point and regulatory interface under the applicable mandate. Appointment does not transfer the controller's or processor's responsibility for compliance.

DPO & PRIVACY FUNCTION

Privacy governance needs independent challenge and continuing oversight.

The DPO function is not limited to answering privacy questions.

It supports independent monitoring, advice, awareness, risk escalation, supervisory-authority cooperation and the organisation's continuing ability to identify and address compliance issues.

OSTRAI provides DPO and privacy-function support tailored to the organisation's regulatory position, scale and processing risk.

  1. Advise

    Legal requirements · Processing · Projects · Change

  2. Monitor

    Policies · Controls · DPIAs · Compliance programmes

  3. Challenge

    Risk · Decisions · Escalation · Accountability

  4. Engage

    Individuals · Management · Supervisory authorities

Where OSTRAI acts as DPO, the role is structured to preserve the independence and absence of conflicts required by the applicable framework.

INCIDENT RESPONSE

Privacy incidents require legal and operational judgement.

Not every security incident is a personal-data breach and not every personal-data breach requires the same regulatory response.

OSTRAI supports organisations in assessing the incident, determining the affected data and individuals, evaluating risk, documenting the decision and managing notifications and communications where required.

  1. Incident identification

  2. Personal-data impact

  3. Risk assessment

  4. Notification decision

  5. Remediation & record

72-hour notification window where applicable · Supervisory authority · Individuals · Documentation · Corrective action

INDIVIDUAL RIGHTS

Rights handling requires consistent legal judgement.

Access, erasure, objection, restriction, rectification, portability and automated-decision rights can require detailed analysis of identity, scope, exemptions, competing obligations and technical feasibility.

OSTRAI supports organisations in designing rights-handling procedures and in responding to complex or contested requests.

  1. Process

    Intake · Identity · Scope · Deadline

  2. Legal analysis

    Right · Exemption · Restriction · Competing obligation

  3. Response

    Search · Review · Redaction · Decision · Evidence

DIGITAL PRIVACY

Tracking technologies sit between privacy, consent and digital regulation.

Websites, applications, advertising technologies and consent-management systems can involve overlapping requirements concerning device access, personal-data processing, transparency, consent and legitimate interests.

OSTRAI advises organisations on tracking technologies, consent architecture, cookie governance and related privacy obligations across digital products and services.

  1. Tracking inventory

    Cookies · SDKs · Pixels · Similar technologies

  2. Consent architecture

    Choice · Withdrawal · Granularity · Evidence

  3. Processing position

    Purpose · Legal basis · Recipients · Profiling

  4. Implementation review

    Banner · Consent manager · Notices · Third parties

REGULATORY INTERSECTIONS

Privacy increasingly operates alongside other digital rules.

OSTRAI assesses these intersections so that privacy compliance is integrated into the wider regulatory position rather than treated as a standalone workstream.

  1. Artificial intelligence

    Training data · Inference · Profiling · Automated decisions · Governance

  2. Cybersecurity

    Security of processing · Incident response · Resilience · Access controls

  3. Data regulation

    Data Act · Data Governance Act · Data spaces · Data access and sharing

  4. Digital services & tracking

    Platforms · Advertising · Consent · Transparency · User data

SUPERVISORY AUTHORITIES

Regulatory engagement requires accuracy, evidence and judgement.

Complaints, information requests, investigations and enforcement matters require organisations to understand the regulatory issue quickly, establish the factual record and respond in a way that is accurate, proportionate and supported by evidence.

OSTRAI supports organisations across:

  1. Complaints

    Internal investigation · Facts · Legal position

  2. Authority requests

    Information · Evidence · Deadlines · Coordination

  3. Investigations

    Document review · Response strategy · Remediation

  4. Corrective action

    Governance · Controls · Monitoring · Follow-up

Privacy & data

Build privacy governance around the way data is actually used.

OSTRAI helps organisations translate privacy and data requirements into governance, evidence, operational controls and continuing compliance across European and selected international regulatory frameworks.

Discuss a privacy or data matter