Templates

Free compliance templates, shown in full.

Contracts, registers, policies and questionnaires for DPDP, GDPR, ISO 27001 and AI governance. Every template is on the page with a copy button, and none of them ask for an email address.

01

Every template

Each page gives the template itself, how to use it, what each part is for, and the statutory references behind it. All of them are free to copy and adapt; none is legal advice.

TemplateWhat it coversType
DPDP data processing agreementProcessor contract under DPDP s.8(2) and Rule 6, with GDPR Article 28 clauses mappedContract
Record of processing activitiesRoPA columns for GDPR Article 30 and the DPDP Act, with a worked rowRegister
Risk register5×5 scoring, inherent and residual risk, treatment, formulasRegister
ISO 27001 Statement of ApplicabilityAll 93 Annex A controls of ISO/IEC 27001:2022, with justification columnsISMS
Vendor security questionnaire50 questions in 13 groups, including DPDP, GDPR and AIQuestionnaire
AI acceptable use policyApproved tools, data rules, prohibited uses aligned to the EU AI ActPolicy
Data breach notification (India)Intimation to the Board and to affected Data Principals under the DPDP RulesNotice
Incident response planRoles, phases and the clocks that run from detectionPlan
DPDP consent noticeA section 5 notice, with the Eighth Schedule languagesNotice
DPIA templateData protection impact assessment structure under GDPR Article 35Assessment
02

Which compliance template do I need first?

For a privacy programme, the first template to fill is the record of processing activities, because the processor contracts, consent notice and DPIA all reuse its fields. For a security programme, it is the risk register, because ISO 27001's Statement of Applicability follows from the risks it records.

  • Getting ready for the DPDP Act. Record of processing, then the consent notice, then a processor agreement for each vendor, then the breach notification template. The DPDP Act guide sets out the dates.
  • Starting ISO 27001. Risk register, then Statement of Applicability, then the incident response plan. The ISO 27001 solution shows how the same work runs on a platform.
  • Buying software. Vendor security questionnaire before signing, data processing agreement at signing.
  • Rolling out AI tools. AI acceptable use policy, with a register of approved tools. The EU AI Act guide explains the duties behind it.
03

What a template cannot do

A template is a record of intention. It says what should happen and what you believe is in place. It does not notice when encryption is switched off, when a vendor adds a sub-processor, or when a consent was withdrawn and the data is still held. That gap between the document and the system is the most common finding in a privacy or security review.

TryTrustable closes it from the other side: controls are checked continuously, evidence is timestamped into a hash-chained ledger, residual risk moves with control state on the risk register, and consent is proven per person in the consent ledger. For quick checks without an account, see the free tools, starting with the cookie scanner.

Questions

The things people ask us

Are these compliance templates really free?

Yes. Every template is shown in full on its page, with a copy button. There is no email gate, no account and no download form. You can use them commercially, under your own name, without attribution. They are starting points written to be edited, and counsel should review anything contractual or legal before you rely on it.

Are the templates legal advice?

No. They are carefully written starting points, with the statutory references shown so you can check them against the source. Contracts, policies and notices have consequences that depend on your processing, sector and jurisdiction, so have counsel review them against how your organisation actually works before you sign or publish.

Which template should I start with?

For privacy, start with the record of processing activities: the data processing agreement, consent notice and DPIA all reuse its fields. For security, start with the risk register: the Statement of Applicability follows from it. For suppliers, send the vendor security questionnaire before signing the data processing agreement.

Do these templates cover India's DPDP Act?

Yes, where the DPDP Act applies. The data processing agreement is written around section 8(2) and Rule 6, the record of processing adds DPDP columns to the GDPR Article 30 set, the questionnaire asks the DPDP-specific questions, and the breach notification template follows the DPDP Rules. Each page cites the sections it relies on.

Why are some templates spreadsheets and others text?

Registers are tables that grow, so the risk register, record of processing and Statement of Applicability are given as tab-separated text that lands in columns when pasted into Google Sheets or Excel. Contracts, policies and questionnaires are prose, so they are plain text that pastes into any document.

What is the difference between a template and the platform?

A template records what you intend and what you remember. The platform records what your systems are doing: controls checked continuously, evidence collected from connected accounts, residual risk recalculated from control state and consent proven in a ledger. Many teams start with templates and move when keeping them current becomes the work.

Book a walkthrough

The template says what should happen. The platform shows what did.

Thirty minutes. We connect one cloud account live and show evidence landing against the same controls these templates describe.