Privacy Policy - AI Contract Review

Clear explanations of 500+ contract clauses, written in plain English for businesses and individuals.

📄
Data protection

Privacy by Design

📖 3 min read

Privacy by design means building data protection into your systems from the start, rather than adding it later as an afterthought. This is a legal requirement under UK GDPR and a best practice under US law. For example, if you're building a customer

Read More →
📄
Data protection

Data Mapping

📖 3 min read

Data mapping means creating a detailed inventory of all personal information your organization collects, where it's stored, who can access it, and how it's used. This matters because UK GDPR and US laws (like CCPA) require you to know what data you h

Read More →
📄
Data protection

Records of Processing

📖 3 min read

This clause requires a company to keep detailed written records of what they do with personal data—what data they collect, who they share it with, how long they keep it, and what security measures they use. These records are like an audit trail that

Read More →
📄
Data protection

Lead Supervisory Authority

📖 3 min read

When data moves between multiple countries, this clause names which data protection regulator (like the UK Information Commissioner's Office or a German authority) is in charge of enforcing the rules. Without this clause, it's unclear who you complai

Read More →
📄
Data protection

Data Protection Registration

📖 3 min read

This clause requires a company to officially register with the data protection authority (like the UK's Information Commissioner's Office) and keep records showing they're complying with data protection laws. Registration is a legal requirement in mo

Read More →
📄
Data protection

Binding Corporate Rules

📖 3 min read

This is an internal rulebook that large multinational companies create to protect personal data when it moves between their own offices in different countries. For example, if Google transfers customer data from its London office to its Dublin office

Read More →
📄
Data protection

Standard Contractual Clauses

📖 3 min read

This clause allows companies to legally transfer personal data (like customer names and addresses) from the EU to countries outside the EU that don't have equivalent data protection laws. Think of it as a legal permission slip approved by the EU. Wit

Read More →
📄
Data protection

International Transfer Mechanism

📖 3 min read

This clause explains how personal data can be legally moved from one country to another—for example, from the UK to the US or to a cloud server in another country. This is legally complex because UK GDPR and EU law restrict sending personal data outs

Read More →
📄
Data protection

Data Protection Impact Assessment

📖 3 min read

A Data Protection Impact Assessment (DPIA) is a formal analysis that companies must do before processing personal data in risky ways—for example, before using facial recognition or combining datasets about vulnerable people. UK GDPR and similar laws

Read More →
📄
Data protection

Data Subject Rights

📖 3 min read

This clause describes how the other party will handle requests from individuals (like your employees or customers) who want to see, correct, or delete their personal data. Under UK GDPR and similar laws, individuals have legal rights to access their

Read More →

Ready to analyze your contracts?

Get instant AI-powered risk analysis. No legal degree required.

Get Started Free