PrıvacyPoınt
// playbooks

Every work product
runs on a playbook.

Counsel-authored SOPs for the work we do most: executed on the platform, versioned, and always exam-ready. The judgment is a lawyer's; the procedure is what makes it repeatable and defensible. Every playbook below is live today.

sop/pia.md

Privacy Impact Assessment

Clear a new product, feature or data use before it ships. GDPR Art. 35 · CPRA.

01
Intake: scope the processing, data types and purpose
02
Auto-map the data flows and surface high-risk factors
03
Score necessity, proportionality and safeguards
04
Counsel reviews residual risk and records the rationale
05
Sign, version and schedule the re-review
sop/dpa.md

Data Processing Agreement

Review, counter and execute processor terms with flow-downs that hold.

01
Intake the paper and classify the processing roles
02
Redline against counsel-set fallback positions
03
Negotiate sub-processor and flow-down terms
04
Counsel signs off residual positions
05
Execute, version, calendar the renewal
sop/dsar.md

Data Subject Access Request

Intake to response on a clock, with identity checks and exemption logic.

01
Verified intake with identity confirmation
02
Locate and collate the subject’s data
03
Apply exemptions and third-party redactions
04
Counsel review of the response package
05
Respond in-deadline; log and close
sop/baa.md

HIPAA Business Associate Agreement

Review and redline BAAs; auto-detects whether the client is business associate or covered entity and applies the matching positions. 45 CFR 164.504(e).

01
Intake the BAA and detect the side: BA or CE
02
Term-by-term review against the firm playbook
03
Run the §164.504(e) required-provision checklist
04
Counsel signs the redline and residual positions
05
Execute, version, calendar the review
sop/triage.md

Use-Case Triage

Does this need a PIA, a mandatory DPIA, or can it proceed? Answered in a day, not a month, with the rationale recorded.

01
Intake the activity, data types and purpose
02
Screen against mandatory DPIA triggers
03
Check for privacy-policy conflicts
04
Route: PIA, DPIA, or proceed; rationale recorded
05
Log the decision; wire the re-review
sop/reg-gap.md

Regulatory Gap Analysis

A new reg drops: diff it against current policy and practice, output a gap list and a dated remediation plan.

01
Intake the regulation or amendment text
02
Diff against current policy and documented practice
03
Produce the gap list, ranked by exposure
04
Build the remediation plan: owners and dates
05
Counsel signs; feed the horizon.log
sop/policy.md

Policy Monitor

Keep the privacy policy current with practice: a weekly sweep of PIAs, DPA reviews and triage results to catch drift before a regulator does.

01
Sweep the week’s PIAs, reviews and triage results
02
Detect drift between policy and documented practice
03
Draft the policy update with rationale
04
Counsel approves the change
05
Publish and version the policy
sop/ir.md

Incident & Breach Response

Detection to multi-jurisdiction notice, privilege-first from the opening hour. GDPR Arts. 33–34 · HIPAA · US state breach statutes.

01
Open under privilege; start the record and the timeline
02
Scope it: systems, data types, individuals, jurisdictions
03
Test notifiability against every clock that applies
04
Counsel signs the notification decision and the drafts
05
Notify in-deadline; close with the post-incident review
sop/vra.md

Vendor / AI Risk Assessment

Score vendors and models before they touch your data, and again at every renewal.

01
Intake the vendor, the data it touches and the AI in its stack
02
Diligence security, sub-processors and training-data terms
03
Score the risk and set the conditions of use
04
Counsel signs the position; conditions land in the DPA
05
Version the assessment; calendar the renewal review
sop/ropa.md

Records of Processing

Article 30 records as a living register, maintained continuously rather than rebuilt every audit season. GDPR Art. 30.

01
Inventory the processing activities, systems and owners
02
Record purposes, lawful bases, categories and recipients
03
Map transfers, retention and the safeguards on each
04
Counsel reviews the entries and the gaps they expose
05
Publish the register; wire changes in from PIA and vendor reviews
trust / our-own-pia.mdwe are our own first client
publishedOur own AI-use PIA. Produced on the platform, in the platform's format, and published in the Trust Center; a privacy firm marketing AI tooling should be able to show its own paperwork.Trust Center
bring us the question →