GDPR Compliance
A Practitioner’s Field Guide: the complete three-volume set
Each volume stands alone, with its own index. Read in order — Learn, Run, Operate — or take the one you need.
GDPR compliance as a working machine, not a legal treatise. The three volumes cover the law and the compliance machine, breach and enforcement and operations, and the templates and worksheets that operationalise both.
Companion to the GDPR Checklist toolkit — the assessment and ready-to-use templates that put this book to work.
From the blog: Which GDPR lawful basis actually applies? · The 72-hour clock — when does it actually start? · Telling your customers about a breach — essay-length previews of the same ground this set covers, free.
The Law and the Compliance Machine
Volume 1 of the three-volume GDPR Compliance set: the law and the compliance machine, covering what GDPR actually is, the controller-processor distinction, the six lawful bases, personal-data categories, data subject rights, the RoPA discipline, DPIAs, the DPO function, international transfers, and vendor management, with a closing part applying the law to data maps, consent surfaces, cookies, privacy-first systems, and the marketing engine. Volume 2 covers breach, enforcement, and operations; Volume 3 is the Operator's Workbook of templates. Each volume stands alone. Each is modestly priced in ebook.
Breach, Enforcement, and Operations
Volume 2 of the three-volume GDPR Compliance set: breach, enforcement, and operations, covering the Article 33/34 seventy-two-hour breach window, supervisory-authority engagement, UK GDPR and EEA divergence, fines and the EDPB, subject-rights surges, worked enforcement cases, three compliance-by-tier portraits (small operator, mid-market, multinational), GDPR and AI systems, the annual compliance cycle, and the maturity model, with the supervisory-authority engagement templates as Appendix A. Volume 1 covers the law and the compliance machine; Volume 3 is the Operator's Workbook of templates. Each volume stands alone. Each is modestly priced in ebook.
The Operator's Workbook
Volume 3 of the three-volume GDPR Compliance set: the Operator's Workbook, holding the DPIA template set, the RoPA structure, controller-processor agreement clauses, breach-notification templates built for the seventy-two-hour clock, subject-rights response templates, the vendor due-diligence set, the template finder with tier manifests, the GDPR maturity rubric, and the glossary, all in four tier-matched variants. Volume 1 covers the law and the compliance machine; Volume 2 covers breach, enforcement, and operations. Each volume stands alone. Each is modestly priced in ebook.
The set at a glance
Swipe sideways to see the full table →
| Volume | Pages | Depth | ISBN | Price |
|---|---|---|---|---|
| Volume 1 | 324 | 15 chapters | TBD | TBD |
| Volume 2 | 343 | 14 chapters | TBD | TBD |
| Volume 3 (Workbook) | 325 | 7 chapters | TBD | TBD |
Where to buy
GDPR Compliance will be available in paperback, hardcover, and ebook through print-on-demand retailers, each volume sold separately. The links activate the moment the titles list; until then, email us and we’ll tell you at launch.
Cover art, pricing, and availability are not yet final and will be updated when these titles are listed for sale. Books are sold through print-on-demand retailers (KDP, IngramSpark, Amazon, and independent bookstores) — not through the Sylvan Assurance toolkit store.