PRIVACY & DATA
Privacy governance from legal obligation to operational control.
Privacy compliance depends on more than policies and notices.
OSTRAI helps organisations establish the governance, accountability, documentation, controls and decision-making structures needed to manage personal data lawfully across products, services, operations and technology environments.
Our work combines regulatory interpretation with practical implementation across privacy governance, data protection engineering, risk, transfers, incident response, international privacy frameworks and the wider European data regulatory landscape.

PRIVACY & DATA GOVERNANCE
Privacy obligations operate across the data lifecycle.
Privacy regulation applies across the way organisations collect, use, share, retain, secure and delete personal data.
The regulatory position depends on the nature of the processing, the organisation's role, the purposes and legal bases involved, the categories of data and individuals affected, the systems and third parties used, and the jurisdictions through which data moves.
OSTRAI helps organisations bring these elements into one coherent privacy-governance framework.
Processing context
Purpose · Data · Individuals · Systems · Business activity
Regulatory role
Controller · Processor · Joint controllership · Other roles
Lawfulness & transparency
Legal basis · Fairness · Notices · Purpose limitation
Risk & accountability
DPIA · RoPA · Controls · Governance · Evidence
Data flows & third parties
Processors · Vendors · Sharing · Transfers · Contracts
Continuing compliance
Rights · Incidents · Monitoring · Changes · Regulatory response
PRIVACY & DATA ADVISORY
From processing activity to accountable governance.
OSTRAI supports organisations in translating privacy and data-protection requirements into governance, documentation, operational controls and continuing compliance.
Privacy governance & accountability
Privacy frameworks, governance structures, responsibility mapping, policies, decision-making processes and accountability evidence.
RoPA, data mapping & processing analysis
Records of processing activities, processing inventories, data-flow analysis, controller / processor role assessment, legal-basis analysis and processing documentation.
DPIA, risk & privacy by design
Data protection impact assessments, high-risk processing analysis, privacy-by-design requirements, mitigation measures and integration into product and operational decision-making.
International data transfers
Transfer mapping, adequacy analysis, Standard Contractual Clauses, transfer impact assessments, supplementary measures and cross-border data-transfer governance.
DPO & continuing compliance
DPO support, independent monitoring, compliance advice, governance review, training, audits, regulatory monitoring and ongoing privacy-function support.
Incidents, rights & regulatory response
Personal-data breach assessment, notification support, data-subject rights, complaints, supervisory-authority engagement, investigations and corrective-action support.
Data regulation & data access
Data Act, Data Governance Act, data-access and sharing obligations, connected-product data, data spaces and sector-specific data frameworks.
International privacy & representation
Multi-jurisdiction privacy programmes, EU and UK GDPR representation, territorial-scope analysis and regulatory coordination across selected international frameworks.

ACCOUNTABILITY
Compliance must be demonstrable, not assumed.
The GDPR accountability principle requires organisations not only to comply, but to be able to demonstrate compliance.
That requires a connected body of governance, records, decisions, assessments, controls and evidence that reflects how processing actually takes place.
OSTRAI supports organisations in building that evidence around real processing activities rather than producing documentation in isolation.
Governance
Roles · Responsibilities · Escalation · Oversight
Documentation
RoPA · Policies · Notices · Assessments · Decisions
Controls
Access · Retention · Third parties · Security · Rights
Evidence
Approvals · Reviews · Monitoring · Remediation · Audit trail
RECORDS OF PROCESSING
The RoPA should describe the organisation that actually exists.
A Record of Processing Activities is not simply an inventory of forms or systems.
A useful RoPA should identify coherent processing activities and document the purposes, individuals, personal data, recipients, transfers, retention, systems, security context and organisational responsibility associated with them.
OSTRAI supports organisations in designing RoPA methodologies, reviewing existing records, identifying gaps and rebuilding processing records where the existing structure does not provide a reliable compliance picture.
Define processing activities
Map purposes & roles
Map data, individuals & recipients
Assess legal basis & transfers
Retention & security context
Validate with process owners
Maintain & govern
DPIA & RISK
Risk assessment must follow the processing, not a template.
Where processing is likely to result in a high risk to individuals, the DPIA becomes part of the organisation's decision-making and accountability process.
OSTRAI supports DPIAs from initial screening through processing analysis, necessity and proportionality assessment, risk identification, mitigation and residual-risk evaluation.
Processing analysis
Nature · Scope · Context · Purpose
Necessity & proportionality
Legal basis · Data minimisation · Purpose · Alternatives
Risk to individuals
Likelihood · Severity · Rights · Consequences
Mitigation & decision
Controls · Residual risk · Approval · Consultation where required

PRIVACY BY DESIGN
Privacy requirements should enter the design process early.
Privacy by design and by default require data-protection considerations to be integrated into products, services, systems and operational processes rather than added after implementation.
OSTRAI supports organisations in translating legal requirements into design decisions, governance controls and implementation evidence.
Data minimisation
What data is actually required?
Default settings
What happens before the individual takes action?
Access & separation
Who can access data and for what purpose?
Lifecycle controls
Collection · Use · Retention · Deletion · Change
INTERNATIONAL DATA TRANSFERS
A transfer mechanism is only one part of the analysis.
Cross-border transfers require organisations to understand where personal data moves, who receives it, what transfer mechanism applies and whether the destination environment affects the level of protection.
OSTRAI supports transfer programmes across data mapping, transfer mechanisms, transfer impact assessment, contractual implementation and supplementary measures.
Transfer mapping
Transfer mechanism
Destination analysis
Supplementary measures
Documentation & governance
Adequacy · SCCs · Transfer impact assessments · Supplementary measures · Processor chains · Continuing review
DATA RELATIONSHIPS
Contractual roles must reflect the real processing relationship.
Privacy responsibilities depend on the factual and legal role performed by each organisation.
OSTRAI advises on controller, processor and joint-controller positions, processor appointment, sub-processing, data-sharing arrangements and allocation of responsibility across complex technology and service relationships.
Controller
Purpose · Means · Accountability
Processor
Instructions · Security · Assistance · Sub-processors
Joint controllers
Shared determination · Allocation · Transparency
Data sharing
Purpose · Legal basis · Responsibility · Governance
DATA REGULATION
Privacy is one part of the European data framework.
The European data rulebook increasingly governs not only the protection of personal data, but also access to, use of, sharing of and portability of data across products, services and sectoral ecosystems.
OSTRAI advises organisations on the interaction between privacy law and the wider European data framework, including the allocation of rights, obligations and governance across personal and non-personal data.
Data Act
Connected-product data · User access · Data sharing · Third-party access · Cloud switching · Contractual data terms
Data Governance Act
Data intermediation · Data altruism · Reuse of protected public-sector data · Data-sharing governance
European Health Data Space
Health data · Primary use · Secondary use · Access · Reuse · Governance
Data Spaces & sectoral data regimes
Common European Data Spaces · Sector-specific access and sharing · Interoperability · Governance
OSTRAI assesses these frameworks alongside GDPR and other applicable privacy rules where the same data, products or services engage several regulatory regimes.
MULTI-JURISDICTION PRIVACY
Privacy programmes increasingly need to work across jurisdictions.
Organisations operating internationally may need to reconcile several privacy regimes across the same products, systems, data flows and governance structures.
OSTRAI advises on European privacy requirements alongside selected international frameworks, helping organisations identify where obligations converge, where they differ and how a coordinated operational programme can support compliance across jurisdictions.
European Union
EU GDPR · ePrivacy framework · EDPB guidance · Member State requirements
United Kingdom
UK GDPR · Data Protection Act 2018 · PECR · Data (Use and Access) Act 2025
Middle East
KSA PDPL · UAE PDPL · Egypt data-protection framework · Local implementation requirements
Cross-jurisdiction programmes
Governance mapping · Transfers · Notices · Rights · Processor relationships · Incident processes
The objective is not to force different legal regimes into one model, but to identify common operational controls while preserving jurisdiction-specific requirements.
EU & UK GDPR REPRESENTATION
A regulatory representative is more than a contact address.
Controllers and processors established outside the European Union or United Kingdom may, depending on their territorial activities and the applicable exemptions, be required to appoint a representative under the relevant GDPR framework.
EU and UK GDPR representative services are distinct appointments. UK GDPR Representative services are provided through PRIVACY MINDERS (UK) LIMITED, a UK-established company. OSTRAI supports organisations in establishing the separate representation arrangements, maintaining the required regulatory interfaces and coordinating privacy matters under each mandate.
Territorial scope
Offering goods or services · Monitoring behaviour · Establishment analysis · Applicable exemption
Formal appointment
Written mandate · Representative details · Privacy notices · Processing records
Regulatory interface
Data subjects · Supervisory authorities · ICO · Requests · Communications
Continuing support
Processing changes · Rights · Complaints · Regulatory enquiries · Compliance coordination
EU GDPR Representative
EU GDPR representation for organisations within the relevant territorial scope, with the representative established in the European Union in accordance with the applicable requirements.
UK GDPR Representative
UK GDPR representation for organisations within the relevant territorial scope, with the representative established in the United Kingdom.
The representative acts as a contact point and regulatory interface under the applicable mandate. Appointment does not transfer the controller's or processor's responsibility for compliance.
DPO & PRIVACY FUNCTION
Privacy governance needs independent challenge and continuing oversight.
The DPO function is not limited to answering privacy questions.
It supports independent monitoring, advice, awareness, risk escalation, supervisory-authority cooperation and the organisation's continuing ability to identify and address compliance issues.
OSTRAI provides DPO and privacy-function support tailored to the organisation's regulatory position, scale and processing risk.
Advise
Legal requirements · Processing · Projects · Change
Monitor
Policies · Controls · DPIAs · Compliance programmes
Challenge
Risk · Decisions · Escalation · Accountability
Engage
Individuals · Management · Supervisory authorities
Where OSTRAI acts as DPO, the role is structured to preserve the independence and absence of conflicts required by the applicable framework.
INCIDENT RESPONSE
Privacy incidents require legal and operational judgement.
Not every security incident is a personal-data breach and not every personal-data breach requires the same regulatory response.
OSTRAI supports organisations in assessing the incident, determining the affected data and individuals, evaluating risk, documenting the decision and managing notifications and communications where required.
Incident identification
Personal-data impact
Risk assessment
Notification decision
Remediation & record
72-hour notification window where applicable · Supervisory authority · Individuals · Documentation · Corrective action
INDIVIDUAL RIGHTS
Rights handling requires consistent legal judgement.
Access, erasure, objection, restriction, rectification, portability and automated-decision rights can require detailed analysis of identity, scope, exemptions, competing obligations and technical feasibility.
OSTRAI supports organisations in designing rights-handling procedures and in responding to complex or contested requests.
Process
Intake · Identity · Scope · Deadline
Legal analysis
Right · Exemption · Restriction · Competing obligation
Response
Search · Review · Redaction · Decision · Evidence
DIGITAL PRIVACY
Tracking technologies sit between privacy, consent and digital regulation.
Websites, applications, advertising technologies and consent-management systems can involve overlapping requirements concerning device access, personal-data processing, transparency, consent and legitimate interests.
OSTRAI advises organisations on tracking technologies, consent architecture, cookie governance and related privacy obligations across digital products and services.
Tracking inventory
Cookies · SDKs · Pixels · Similar technologies
Consent architecture
Choice · Withdrawal · Granularity · Evidence
Processing position
Purpose · Legal basis · Recipients · Profiling
Implementation review
Banner · Consent manager · Notices · Third parties
REGULATORY INTERSECTIONS
Privacy increasingly operates alongside other digital rules.
OSTRAI assesses these intersections so that privacy compliance is integrated into the wider regulatory position rather than treated as a standalone workstream.
Artificial intelligence
Training data · Inference · Profiling · Automated decisions · Governance
Cybersecurity
Security of processing · Incident response · Resilience · Access controls
Data regulation
Data Act · Data Governance Act · Data spaces · Data access and sharing
Digital services & tracking
Platforms · Advertising · Consent · Transparency · User data
SUPERVISORY AUTHORITIES
Regulatory engagement requires accuracy, evidence and judgement.
Complaints, information requests, investigations and enforcement matters require organisations to understand the regulatory issue quickly, establish the factual record and respond in a way that is accurate, proportionate and supported by evidence.
OSTRAI supports organisations across:
Complaints
Internal investigation · Facts · Legal position
Authority requests
Information · Evidence · Deadlines · Coordination
Investigations
Document review · Response strategy · Remediation
Corrective action
Governance · Controls · Monitoring · Follow-up
Privacy & data
Build privacy governance around the way data is actually used.
OSTRAI helps organisations translate privacy and data requirements into governance, evidence, operational controls and continuing compliance across European and selected international regulatory frameworks.
Discuss a privacy or data matter