| Current-state assessment | Establish strengths, gaps, risks, and dependencies | Process findings, controls, workload, systems, evidence, suppliers, and maturity | Privacy leadership, risk, programme sponsors |
| Future-state workflow pack | Define the full request lifecycle | States, routing, decisions, due dates, exceptions, approvals, and closure | Privacy operations, legal, service teams |
| Responsibility and escalation model | Make accountability explicit | RACI, owner directory, decision rights, escalation thresholds, and backup roles | Business and technology owners |
| Procedure and control catalogue | Support repeatable delivery and assurance | Verification, searches, redaction, secure transfer, review, evidence, retention | Operators, assurance, internal audit |
| Technology requirements | Guide configuration or procurement | Fields, statuses, roles, integrations, notifications, templates, reports, access | Product owners, architects, vendors |
| Test and transition pack | Support controlled go-live | Scenarios, acceptance criteria, defects, training, handover, support, KPIs | Delivery teams and operations |