Operational adequacy schemes – implementing data protection (operationalisation)Focus on operational adequacy schemesThe three layers of an organisationImplementing data protection in the people layerGovernance structuresSteering committeeRecruitment and onboardingEducation and trainingAccess rights and privilegesMonitoringWorker disciplineFlowing requirements to data processorsImplementing data protection in the paper layerData Protection by Design and Default (DPbDD, or PbD)Governance structuresRecords of processing activitiesRisk registers and assessment tools and methodologiesLegitimate interests assessmentsTransfer assessmentsTransparency noticesContracts and similar documentsPolicies, procedures and controls frameworksRecords of significant eventsProgramme and project plansTechnology architectureAssurance recordsOther mechanisms for assuranceImplementing data protection in the technology and data layerPrivacy Enhancing TechnologiesRegulatory sandboxes‘The Journey to Code’Risk management – implementing measures to assess risks to rights and freedoms and the appropriateness of controlsThe adequacy testThe impact of the ‘consensus of professional opinion’ – what are the risks and what should be done about them?Risk management – dealing with adverse scrutinyGlobalisation – implementing data protection on an international stageInternational transfers – adequacy, appropriate safeguards and derogationsMeaning of ‘adequacy’ for the purposes of international transfersAdequacy of the UKAppropriate safeguardsDerogationsWider operational challenges of international activitiesImpacts for micro, small and medium-sized enterprisesSize of enterprise and size of riskFinancial resources, cost and riskSecurity and connection to wider legal and operational frameworksSummary