Privacy Toolkit (GDPR+ISO 27001)
Privacy Toolkit (GDPR+ISO 27001)
General Information
The Privacy Toolkit is a collection of documents designed for privacy professionals who
wish to gain a thorough understanding of privacy and data protection requirements such as
GDPR, PDPL, and DPDPA. It also covers various frameworks including ISO 27701, ISO 29100,
ICO Accountability Framework, NIST Privacy Framework, NOREA Privacy Control Framework,
and Standard Data Protection Model (SDM). The Toolkit can help professionals prepare for
privacy-related certifications such as CIPP, CIPM, CIPT, CDPSE, IDPP, and assist them in
designing and implementing a Privacy Information Management System (PIMS) and/or a
Privacy Program.
It is used by over 1000 professionals around the world, including Data Protection Officers
(DPOs), Chief Privacy Officers (CPOs), Data Protection Managers, Internal and External
privacy lawyers, Privacy engineers, Privacy consultants, Chief Information Security Officers
(CISOs), Information Security Managers, GRC Managers, Compliance Managers, and Internal
Auditors.
It is a nonprofit project created by Andrey Prozorov, a cybersecurity and privacy expert with
15+ years of experience in implementation and audit.
The toolkit is divided into five parts: Intro, Planning, Management, Operation, and Special
Cases, each of which covers all major topics related to privacy.
Implementation
Intro
1. Planning 2. Management 3. Operation 4. Special cases
The toolkit is regularly reviewed and updated. The current version is 6.0.
200+ documents are available on Patreon - https://www.patreon.com/posts/66191153
You can support this project and get access to all the documents ("Only Privacy Toolkit" or a
higher subscription is needed). The list of documents is further.
The most important (valuable) documents are marked by 🔥.
Intro
Date of
# Name Type Format creation /
update
1. Regulation (GDPR, CCPA, PDPL and DPDPA)
1.1. 🔥 One-page document with key points of GDPR review pdf, docx upd.21.03.2022
1.2. 🔥 GDPR Mindmap review pdf, xmind upd.21.04.2023
1.3. The most important GDPR links links links upd.26.04.2022
1.4. 🔥 EU Cybersecurity and Privacy, mindmap review pdf, xmind upd.15.01.2024
1.5. EU Cybersecurity and Data Protection Regulations review pdf, docx upd.05.02.2023
1.6. Evolution of Data Protection Law in Europe (with review pdf, docx 06.01.2020
short description)
1.7. GDPR vs CCPA review pdf 08.08.2020
1.8. CCPA Articles Mindmap review pdf, xmind 07.08.2020
1.9. GDPR vs PDPL (Saudi Arabia) review pdf, docx upd.02.03.2023
1.10. The Digital Personal Data Protection Act, 2023 review pdf, xmind 14.08.2023
(India)
2. Authorities
2.1. My presentation «EU Institutions and bodies» slides pdf upd.21.04.2023
2.2. 🔥 European Data Protection Authorities (DPAs) links pdf, docx, 31.01.2024
+ Valuable guides and tools links
2.3. 🔥 European National Cybersecurity Authorities and links pdf, docx 24.01.2024
CSIRTs
3. Privacy Principles
3.1. Privacy principles: Models review pdf, docx upd.13.02.2023
3.2. 🔥 My presentation about the privacy principles slides pdf 05.04.2023
3.3. 🔥 GDPR: Principles relating to processing of review pdf, xmind 29.01.2023
personal data
3.4. The privacy principles of ISO/IEC 29100 review pdf, xmind 01.02.2023
3.5. APEC Information Privacy Principles review pdf, xmind 13.02.2023
3.6. The Australian Privacy Principles (APPs) review pdf, xmind 08.02.2023
3.7. Fair Information Practice Principles (FIPPs) review pdf, xmind 27.01.2023
3.8. OECD Privacy Principles review pdf, xmind 05.02.2023
3.9. PIPEDA’s 10 fair information principles review pdf, xmind 30.01.2023
3.10. The SCF Privacy Management Principle review pdf, xmind 03.02.2023
3.11. The 10 Generally Accepted Privacy Principles review pdf, xmind 08.06.2023
(GAPP)
Date of
# Name Type Format creation /
update
4. General Terms
4.1. 🔥 Information Security and Data Protection links pdf, links upd.04.01.2023
Glossaries
4.2. Privacy (term and definitions) review pdf, docx upd.09.12.2022
4.3. 🔥 GDPR Scope (criteria) review pdf upd.01.01.2023
4.4. 🔥 GDPR: Controller and Processor review pdf, docx 28.08.2023
4.5. 🔥 GDPR Lawfulness review pdf, xmind 31.10.2019
4.6. 🔥 GDPR Legitimate interests review pdf, xmind upd.14.06.2023
4.7. 🔥 Personal data rights (ICO UK) review pdf, xmind 17.05.2023
4.8. Rights of the data subject review pdf, docx upd.25.04.2022
4.9. GDPR The lawful basis and rights of the data review pdf upd.14.06.2023
subject
4.10. Right to be informed and Right of access review pdf, docx upd.26.04.2022
4.11. Do I need... (DPO, DPIA, Records of processing review pdf 09.10.2019
activities)
4.12. 🔥 Data Retention review pdf, xmind upd.11.05.2023
4.13. The hierarchical structure of the core privacy review pdf, xmind 14.07.2023
topics by ISACA
5. Standards and Frameworks
5.1. 🔥 Best Privacy Standards and Frameworks links pdf, docx upd.12.09.2023
5.2. 🔥 12 Best Privacy Frameworks slides pdf 11.09.2023
5.3. 🔥 Standards and best practices for CISOs and advice pdf, docx upd.02.11.2022
DPOs
5.4. ISO 27701 is on one page review pdf 10.10.2019
5.5. 🔥 ISO 27701:2019 Privacy Information review pdf, xmind upd.12.09.2023
Management
5.6. 🔥 ISO 27701. Additional guidance for PII review pdf, xmind 21.11.2022
controllers and processors
5.7. A mapping of ISO 27701:2019 to GDPR review pdf, docx 28.01.2022
5.8. ISO 27018:2014 Code of practice for protection of review pdf, xmind 17.02.2022
personally identifiable information (PII) in public
clouds acting as PII processors
5.9. Privacy Frameworks review pdf, docx 13.01.2022
5.10. 🔥 ICO's Accountability Framework review pdf, xmind upd.15.11.2022
5.11. A mapping of the Nymity’s Privacy Management advice pdf, xlsx 27.01.2022
Accountability Framework to GDPR and ISO 27701
5.12. Data Privacy by the ISF SoGP 2022 review pdf, xmind 19.09.2022
Date of
# Name Type Format creation /
update
5.13. The three-level control framework (TLCF) and review pdf, docx 10.03.2021
Privacy
5.14. Information Security and Data Protection review pdf, docx upd.02.01.2023
Frameworks
5.15. ISO 31700 Privacy by Design mindmap and review pdf, xmind upd.05.02.2023
requirements
5.16. ISO 27701. Privacy by design and by default review pdf, xmind 05.01.2023
5.17. AICPA Privacy Management Framework (PMF) review pdf, xmind 12.06.2023
5.18. 🔥 MITRE Privacy Maturity Model review pdf, xmind 19.05.2023
5.19. 🔥 Standard Data Protection Model (SDM), v.3 review pdf, xmind 07.07.2023
5.20. 🔥 NOREA Privacy Control Framework (PCF) review pdf, xmind 12.09.2023
5.21. 🔥 ISO 29100 Privacy framework review pdf, xmind 08.09.2023
5.22. Europrivacy Certification Mindmap review pdf, xmind 14.10.2022
5.23. 🔥 The OCEG Integrated Data Privacy Capability review pdf, xmind 03.01.2024
Model (IDPCM)
6. Professional Certifications
6.1. 🔥 Core privacy certifications: IAPP vs ISACA review pdf, docx 19.10.2023
6.2. 🔥 CIPP/E Mindmap and resources for preparation review pdf, xmind 20.04.2023
6.3. CIPP/US Mindmap review pdf, xmind 22.04.2023
6.4. 🔥 CIPM Mindmaps for exam preparation review pdf, xmind 06.04.2023
6.5. CDPSE Mindmaps for exam preparation review pdf 13.05.2020
6.6. Integrated Data Privacy Professional (IDPP) review pdf, xmind 03.01.2024
Implementation
Date of
# Name Type Format creation /
update
1. Planning
1.1. Starting Point
1.1.1. Privacy Pain Points and Trigger Events example pdf, docx upd.25.07.2021
1.1.2. 🔥 The simple roadmap to ensure data protection template pdf, docx 08.08.2023
compliance
1.1.3. GDPR Implementation Roadmap advice pdf, xmind upd.25.08.2020
1.1.4. 🔥 Information Security and Data Protection advice pdf, docx 22.11.2022
Integrated Approach
1.1.5. The Key Steps to Take to Ensure GDPR advice pdf, docx 03.04.2023
Compliance
1.1.6. Privacy management plan by OAIC advice pdf, xmind 16.06.2023
1.2. Scope and Context
1.2.1. List of Requirements (ISMS and PIMS) advice pdf, xmind, 19.09.2023
docs
1.2.2. List of interested parties example pdf, docx upd.14.11.2022
1.2.3. Information Security and Data Protection context, review, pdf, xmind 24.09.2020
mindmap advice
1.2.4. 🔥 Data Protection Scope template pdf, docx upd.19.07.2022
1.3. Privacy risks
1.3.1. 🔥 Two types of privacy risks advice pdf, docx 02.08.2023
1.3.2. 🔥 Privacy Risks for organizations example pdf, docx 01.08.2023
1.3.3. Privacy impact and consequence examples that review pdf, xmind 05.07.2023
can arise from privacy events
(ISO/IEC 27557:2022)
1.4. Audit and Accountability
1.4.1. 🔥 GDPR Short Assessment advice, pdf, docx upd.09.10.2019
template
1.4.2. 🔥 ISO 27701 (PIMS) Gap Analysis Report template pdf, docx 17.04.2023
1.4.3. Request documents for GAP analysis (ISMS and advice pdf, docx upd.15.05.2023
PIMS)
1.4.4. Data Protection audit. Example question areas and review pdf, docx 16.02.2022
evidence
1.4.5. 🔥 GDPR Accountability Checklist checklist pdf upd.29.08.2020
Date of
# Name Type Format creation /
update
1.5. List of Documents
1.5.1. 🔥 List of GDPR documents advice pdf upd.27.11.2023
1.5.2. 🔥 Requirements for documented information in review, pdf, docx upd.28.11.2022
ISO 27001 and ISO 27701 advice
1.5.3. List of GDPR and PIMS documents advice pdf upd.17.02.2021
1.5.4. Privacy Information Management System (PIMS) advice pdf, xmind 14.10.2019
documents by ISO 27701, mindmap
1.6. Data Protection Officer (DPO)
1.6.1. 🔥 All about DPO (mindmap and guidelines) review pdf, xmind 16.03.2022
1.6.2. 🔥 DPO's plan for the year checklist pdf, pptx 14.01.2024
1.6.3. 🔥 Data Protection Officer (DPO): The first tasks checklist pdf, docx 12.06.2023
and quick wins
1.6.4. DPO mission statement template template pdf, docx 10.05.2023
1.6.5. DPO Types by CNIL review pdf, docx 16.03.2022
1.6.6. CPO vs DPO review pdf, docx 19.09.2022
1.6.7. 🔥 DPO Job Description example pdf, docx 08.02.2021
1.6.8. Declaration of a Data Protection Officer template pdf, docx 19.07.2021
1.6.9. The DPO's first 90 days checklist, mindmap advice pdf, xmind upd.23.08.2020
1.6.10. DPO's/CISO's first 90 days checklist advice pdf, docx 21.12.2022
1.6.11. Interview questions for CISOs and DPOs advice pdf, docx 05.07.2022
1.6.12. How to be the best DPO/CISO? advice pdf, docx 20.12.2022
1.6.13. 🔥 DPO Self-Assessment Checklist checklist pdf, docx 11.05.2023
1.6.14. 🔥 Templates and checklists that every DPO advice pdf, docx 15.08.2023
should have
1.6.15. Three types of DPOs (PDPC) review pdf, docx 29.11.2023
2. Management
2.1. Policy and Framework
2.1.1. 🔥 Checklist for Information Security and Data checklist pdf, docx upd.22.03.2022
Protection Policies
2.1.2. 🔥 One-page Data Protection Policy template pdf, docx upd.01.02.2023
2.1.3. 🔥 Privacy Notice vs Privacy Policy review pdf, docx upd.23.03.2022
2.1.4. Data Protection Framework, mindmap advice pdf, xmind upd.23.08.2020
Date of
# Name Type Format creation /
update
2.2. Roles and Responsibilities / RACI
2.2.1. 🔥 GDPR RACI chart example pdf upd.29.08.2020
2.2.2. 🔥 My presentation «Using RACI Chart for GDPR slides pdf upd.03.10.2022
implementation»
2.3. Review
2.3.1. Data Protection Metrics example pdf 01.09.2020
2.3.2. Privacy Management Review Report template pdf, docx 25.04.2022
2.4. Awareness
2.4.1. 🔥 Information Security and Data Protection advice pdf, docx upd.23.11.2023
Awareness Topics
2.4.2. Privacy awareness trainings, mindmap advice pdf, xmind 07.02.2021
2.4.3. Information Security and Data Protection culture review pdf, docx 02.12.2021
2.4.4. Information Security and Data Protection advice pdf, xmind upd.21.03.2022
Awareness. Main Topics. Mindmap
2.4.5. 🔥 Information Security and Data Protection review pdf, docx upd.03.11.2021
awareness
2.4.6. 🔥 Data Protection Awareness Presentation slides pdf, pptx 22.11.2023
(example and template)
2.5. Other
2.5.1. GDPR folder structure, mindmap advice pdf, xmind 21.08.2020
2.5.2. All about OneTrust, mindmap advice pdf, xmind 10.06.2022
3. Operation
3.1. Notices and Consents
3.1.1. 🔥 Privacy Notice Checklist checklist pdf, docx upd.23.08.2020
3.1.2. Privacy Notice Mindmap review pdf, xmind upd.14.06.2023
3.1.3. 🔥 GDPR Consent Mindmap review pdf, xmind upd.14.06.2023
3.1.4. 🔥 GDPR Consent Checklist checklist pdf, xmind upd.14.06.2023
3.1.5. ISO 29184 Online privacy notices and consent, review pdf, xmind 19.06.2023
mindmap
3.1.6. GDPR and ISO 29184: Contents of notice review pdf, docx 19.06.2023
3.1.7. 🔥 Opt-in vs Opt-out review pdf, docx 08.07.2022
3.1.8. 10 TIPS for a better online privacy policy and review, pdf, xmind 28.07.2023
improved privacy practice transparency advice
3.2. Requests
3.2.1. 🔥 Privacy Request Register template xlsx 02.05.2022
3.2.2. Request templates template docx 02.05.2022
Date of
# Name Type Format creation /
update
3.3. Records of processing activities (RoPA)
3.3.1. 🔥 List of personal data example pdf, docx 26.04.2022
3.3.2. Types of Personal data by AEPD example pdf, docx 13.10.2022
3.3.3. 🔥 Records of processing activities checklist checklist pdf upd.20.04.2023
3.3.4. 🔥 Records of processing activities template xlsx upd.06.06.2022
3.3.5. 🔥 RoPAs as Privacy Notices review pdf, docx 23.09.2023
Date of
# Name Type Format creation /
update
3.5.7. 🔥 My Data Protection Impact Assessment (DPIA) template pdf, docx upd.09.05.2022
and Legitimate Interests Assessment (LIA)
template
3.5.8. SA's DPIA templates + mindmaps review, pdf, docx, 07.03.2022
template xmind
3.5.9. DPIA Register template pdf, docx 06.02.2022
3.5.10. DPIA Blacklist. List of processing operations for review pdf, docx 06.03.2022
which a DPIA is required (CNIL)
3.5.11. 🔥 ISO/IEC 29134:2017 Guidelines for privacy review pdf, xmind 06.02.2022
impact assessment (mindmap)
+ List of generic threats
3.6. Data Breach
3.6.1. 🔥 Personal Data Breach Notification review pdf, docx upd.17.04.2023
(requirements)
3.6.2. 🔥 Preparing for a personal data breach checklist pdf, docx 13.09.2022
3.6.3. 🔥 Personal Data Breach Examples and advice, pdf, docx 17.04.2023
Assessment example
3.6.4. 🔥 Data Breach Notification template pdf, docx upd.17.04.2023
3.6.5. Data Breach Register advice pdf, xmind upd.17.04.2023
3.6.6. Incident management: Severity Matrix example pdf, docx 29.06.2021
3.6.7. 🔥 Simple General Data Breach Policy (template) template pdf, docx 12.11.2023
3.6.8. 🔥 NIS 2 and GDPR Incident Reporting Obligations review pdf, docx 23.01.2023
3.7. Security
3.7.1. 🔥 GDPR and Security, mindmap review pdf, xmind upd.14.06.2023
3.7.2. 🔥 My presentation «GDPR and Security» slides pdf 27.04.2020
3.7.3. 🔥 GDPR and Security. Core guidelines from links pdf, xmind, 27.10.2023
Supervisory Authorities (EU) links
3.7.4. 🔥 GDPR: Key design and default elements by review pdf, xmind 01.11.2020
EDPB
3.7.5. The best on-line tool for the security of personal review pdf, xmind 10.09.2020
data processing
3.7.6. 🔥 Privacy-enhancing technologies (PETs) review pdf, xmind upd.19.06.2023
3.7.7. Security Measures Checklist (CNIL) checklist pdf, docx 26.10.2023
3.7.8. Secure personal data checklist for Small Business checklist pdf, docx 26.10.2023
(EDPB)
3.7.9. 🔥 Simple Information security checklist (ICO UK) checklist pdf, docx 26.10.2023
See also the ISMS Implementation Toolkit (ISO 27001)
Date of
# Name Type Format creation /
update
4. Special cases
4.1. CCTV
4.1.1. GDPR Fines: Video surveillance (CCTV) review pdf, docx 12.01.2021
4.1.2. 🔥 CCTV and GDPR checklist pdf, docx upd.14.01.2021
4.1.3. CCTV warning sign template pdf, docx upd.14.01.2021
4.1.4. The 12 guiding principles in the Surveillance review pdf 14.09.2020
Camera Code of Practice, mindmap
4.2. Cookies
4.2.1. 🔥 Cookie Policy and Consent checklist checklist pdf 19.10.2020
4.2.2. Cookie banners (examples) example pdf 19.10.2020
4.3. HR and Monitoring
4.3.1. 🔥 My presentation «Employee Monitoring and slides pdf 08.11.2020
Privacy»
4.3.2. Data processing at work review pdf, xmind upd.14.06.2023
4.3.3. 🔥 Data protection and monitoring workers, checklist pdf, docx 05.10.2023
checklist
4.4. IT Startups
4.4.1. 🔥 GDPR for IT Startups, mindmap advice pdf, xmind upd.31.01.2022
4.4.2. GDPR Compliance Vision for IT Startups, mindmap advice pdf, xmind 27.10.2020
4.4.3. 🔥 GDPR Compliance for Startups: Documents and advice pdf 17.02.2021
records
4.4.4. GDPR developer guide review pdf, xmind 06.12.2022
Updates and new documents
If you like this Privacy Toolkit, want to support this project and
get access to all the documents, you can subscribe to my Patreon -
www.patreon.com/posts/66191153