Knowledge hub · Privacy & GDPR
Privacy and GDPR in practice
A privacy question starts with what your organisation does with personal data. Bring the processing activity, parties involved and open decision together. This guide helps legal, privacy, IT and business teams identify what they can investigate themselves and where a review or temporary support is useful.
Zahed Ashkara · Legal counsel and freelance AI and privacy consultant · 13 september 2026
How do I scope a privacy question?
Describe the process in plain language: who uses which data, why and with whom is it shared? Gather existing arrangements and identify the decision that needs to be made. A concrete question makes a review more useful than asking for a blanket statement that a process is GDPR-compliant.
Privacy and GDPR adviceWhen should I seek DPIA support?
A DPIA addresses processing likely to create a high risk for people. Start with a screening if the need is unclear. Bring the purpose, data, affected people and existing measures together. Leave time to act on findings before the project decision is final.
DPIA support and reviewWhat should I discuss in a data processing agreement?
The actual supplier role determines the arrangements needed. Compare the contract with the real data flow. Ask who gets access, which subcontractors are involved, where data is stored and how incidents and exit are handled. A signed document alone does not show how the arrangement works in practice.
Data processing agreement reviewHow do I organise privacy work?
Keep one overview of open reviews with an owner, missing information and next decision. Separate everyday advice from projects involving several departments. Make earlier decisions accessible to new colleagues and reassess material changes.
Hire an interim privacy officer or counselWhat changes when AI is involved?
Identify which personal data enters the AI application and how its output is used. Connect privacy and AI governance reviews while keeping their conclusions distinct. AI classification does not replace a privacy review, and a DPIA does not automatically address every AI governance question.
AI governance consultingWhat should you share with a privacy consultant?
- The process or application and the decision you need to make.
- An overview of data, affected people, suppliers and data flows.
- Available contracts, earlier reviews and internal arrangements.
- Contacts in legal, IT and the business who can fill information gaps.
- Your desired start date, deadline and need for advice or temporary capacity.
Practical example: an HR team plans a new employee portal. First ask the team to describe the required data and suppliers. Gather the contract and security information, assign open questions and schedule the privacy review before the final configuration. This connects the assessment to the real project decision.
Further reading
Frequently asked questions
Is this guide a GDPR audit?
No. It prepares you for advice and decision-making. A substantive assessment needs information about your actual organisation and processing.
Does every business need a DPIA?
Not for every processing activity. The specific risks determine the need. When uncertain, start with a screening of the activity.
Can I request only a contract review?
Yes. You can engage Embed AI for a defined contract or privacy review without buying a broader AI engagement.
When is interim support useful?
When capacity is limited, several reviews run in parallel or the team needs specialist knowledge temporarily. We agree responsibilities, hours and handover.
Where should I start if my priorities are unclear?
The free privacy and AI scan gives attention points based on your answers. Your result is shown immediately, after which you can discuss a focused assignment.