Define context
Describe purpose, scope, jurisdictions, data categories, stakeholders, and governing principles.
Create a structured policy covering scope, principles, accountability, classification, access, quality, metadata, sharing, retention, privacy, security, third parties, incidents, exceptions, monitoring, enforcement, and review.
Move from organisational context to a review-ready policy draft in three transparent steps.
Describe purpose, scope, jurisdictions, data categories, stakeholders, and governing principles.
Specify ownership, controls, exceptions, monitoring, enforcement, review, and approval expectations.
Assess coverage, edit the generated policy, print it, or download structured JSON and CSV files.
Required fields are marked with an asterisk. Your entries are preserved if validation fails.
Understand what the score represents, what it does not represent, and how to convert the draft into an operational policy.
The 100-point score measures declared coverage across ten fixed policy domains. It does not test whether controls are implemented or effective.
The tool cannot determine applicable law, validate facts, assess risk appetite, resolve conflicts, or replace qualified professional judgment.
Review with stakeholders, map every requirement to standards and controls, assign owners, collect evidence, train users, and monitor exceptions and outcomes.
Use these tools to connect policy requirements with maturity, controls, obligations, and measurable governance.
Practical answers for policy owners, governance leaders, risk teams, privacy professionals, security teams, and business stakeholders.
A data policy is an approved statement of mandatory principles, responsibilities, requirements, and controls for managing data throughout its lifecycle.
No. The output is a structured governance draft and should be reviewed by qualified legal, privacy, security, records, risk, and regulatory specialists.
The browser generates previews and downloads locally. A standard form submission may be processed by the hosting server to support non-JavaScript use, but this file does not implement external transmission or storage.
The score is a deterministic coverage score based on ten disclosed policy domains and fixed weights totalling 100 points. The same validated inputs always produce the same score.
Yes, but a global policy should be supplemented with jurisdiction-specific standards, procedures, notices, schedules, contracts, and legal requirements.
At least annually is common. Review earlier after material legal, regulatory, contractual, organisational, technology, risk, operating-model, or incident changes.
A senior accountable owner with authority across data governance, business operations, technology, privacy, security, and risk should own the policy.
A policy states mandatory intent and accountability. Standards define specific requirements. Procedures describe how work is performed. Guidance offers recommended approaches.
No. Controls should be proportionate to classification, sensitivity, criticality, legal duties, contractual commitments, threat exposure, permitted use, and business impact.
Document the justification, risk assessment, compensating controls, accountable approval, expiry date, review cadence, and closure decision.
Yes. With JavaScript enabled, the policy preview is editable before printing or exporting. User-specific content is visually marked in the preview.
Translate it into standards, procedures, controls, training, system configuration, metrics, evidence, assurance activities, exceptions, and tracked remediation plans.