Skip to main content
Governance drafting tool

Build a practical, professional data policy

Create a structured policy covering scope, principles, accountability, classification, access, quality, metadata, sharing, retention, privacy, security, third parties, incidents, exceptions, monitoring, enforcement, and review.

Privacy-aware by design.
No external libraries or APIs are used. Browser exports are generated locally. The output is a governance draft, not legal advice.

How it works

Move from organisational context to a review-ready policy draft in three transparent steps.

1

Define context

Describe purpose, scope, jurisdictions, data categories, stakeholders, and governing principles.

2

Set requirements

Specify ownership, controls, exceptions, monitoring, enforcement, review, and approval expectations.

3

Review and export

Assess coverage, edit the generated policy, print it, or download structured JSON and CSV files.

Data policy builder

Required fields are marked with an asterisk. Your entries are preserved if validation fails.

Policy inputs

1. Organisation and policy context
Example: Acme Global Ltd.
Example: Enterprise Data Policy
State the outcome the policy is intended to achieve.
Identify people, entities, systems, processes, data, and third parties covered.
2. Jurisdictions and operating context

Select every material jurisdiction or operating context.

Select at least one.
3. Data categories in scope

Choose the categories the policy must govern.

Select at least one.
4. Accountable and operational roles

Select roles that will own, implement, oversee, or assure the policy.

Select at least one.
5. Data management principles

Select the principles that should guide decisions and controls.

Select at least one.
6. Ownership, classification, and access
Classification levels *
7. Data lifecycle requirements
8. Privacy, security, third parties, and incidents
Third-party controls *
9. Exceptions, monitoring, and enforcement
Monitoring activities *
Enforcement mechanisms *
10. Review, approval, and specific requirements
Allowed range: 1–36 months.

Privacy note: Browser preview and export calculations run locally. This self-contained file does not send data to external APIs or implement persistent storage. Standard server processing supports validation and no-JavaScript form submission; hosting environments should apply their existing secure logging, retention, and access controls.

Methodology and responsible use

Understand what the score represents, what it does not represent, and how to convert the draft into an operational policy.

Coverage methodology

The 100-point score measures declared coverage across ten fixed policy domains. It does not test whether controls are implemented or effective.

Important limitations

The tool cannot determine applicable law, validate facts, assess risk appetite, resolve conflicts, or replace qualified professional judgment.

Recommended use

Review with stakeholders, map every requirement to standards and controls, assign owners, collect evidence, train users, and monitor exceptions and outcomes.

Frequently asked questions

Practical answers for policy owners, governance leaders, risk teams, privacy professionals, security teams, and business stakeholders.

What is a data policy?

A data policy is an approved statement of mandatory principles, responsibilities, requirements, and controls for managing data throughout its lifecycle.

Is this generated policy legal advice?

No. The output is a structured governance draft and should be reviewed by qualified legal, privacy, security, records, risk, and regulatory specialists.

Does the tool transmit my data?

The browser generates previews and downloads locally. A standard form submission may be processed by the hosting server to support non-JavaScript use, but this file does not implement external transmission or storage.

How is the score calculated?

The score is a deterministic coverage score based on ten disclosed policy domains and fixed weights totalling 100 points. The same validated inputs always produce the same score.

Can the policy apply globally?

Yes, but a global policy should be supplemented with jurisdiction-specific standards, procedures, notices, schedules, contracts, and legal requirements.

How often should a data policy be reviewed?

At least annually is common. Review earlier after material legal, regulatory, contractual, organisational, technology, risk, operating-model, or incident changes.

Who should own the policy?

A senior accountable owner with authority across data governance, business operations, technology, privacy, security, and risk should own the policy.

What is the difference between a policy, standard, and procedure?

A policy states mandatory intent and accountability. Standards define specific requirements. Procedures describe how work is performed. Guidance offers recommended approaches.

Should every data category use the same controls?

No. Controls should be proportionate to classification, sensitivity, criticality, legal duties, contractual commitments, threat exposure, permitted use, and business impact.

How should policy exceptions be managed?

Document the justification, risk assessment, compensating controls, accountable approval, expiry date, review cadence, and closure decision.

Can the generated policy preview be edited?

Yes. With JavaScript enabled, the policy preview is editable before printing or exporting. User-specific content is visually marked in the preview.

What should happen after the policy is approved?

Translate it into standards, procedures, controls, training, system configuration, metrics, evidence, assurance activities, exceptions, and tracked remediation plans.