PRIVACYAF / PRACTITIONER WORKSPACEBring a better brief.
Find official sourcesBring a better brief.
Make a better decision.
Turn an AI or surveillance proposal into questions, evidence and assigned next actions. Free to use. No account required.
Your entries stay in this page’s memory. Reloading clears them. Download your brief before leaving. Changing the scenario keeps your entries; clear the brief before starting a different project.
What problem does this solve, and what less intrusive option was considered?
Define a specific use. “Improve efficiency” is not enough to explain whose information is needed or why.
Evidence to look for
Business purpose, expected benefit, alternatives and reasons for rejection.
ASK THE VENDOR / ASK THE TEAM
Questions for this conversation.
- Does each account tier have the same data terms?
- Can prompts, uploads, outputs and logs follow different retention rules?
- Which subprocessors or people can access the material?
- How are model updates and changes to terms communicated?
METHOD / REVIEWED OCTOBER 6, 2026
An inspectable foundation.
This PrivacyAF question set draws on impact-assessment and AI risk-management practices. It is a discussion aid, not a complete assessment template or a substitute for local requirements.
NIST AI RMF PlaybookVoluntary AI risk management resourceICO: How do we do a DPIA?United Kingdom regulator guidance; check current revisionsNCCoE: Agent identity and authorisationExploratory US standards project, not a certificationHelp improve the questions