Skip to content
slide-deck.io
BlogGet started free

August 15, 2026

Data Privacy and GDPR Compliance Presentation

Data privacy presentations to boards and executive teams serve a specific governance function: ensuring that leadership understands the organization's obligations, has visibility into compliance posture, and can make informed decisions about privacy risk. The presentation should be honest, specific, and actionable — not a reassurance performance.

Slide 1: Our Data Privacy Obligations

Establish which regulations apply to the organization and what they require. Don't assume the audience knows the scope of GDPR or the specific obligations it creates. A one-slide orientation ensures the rest of the presentation is interpretable.

Key regulations to cover (as applicable):

  • GDPR: Applies to processing personal data of EU residents, regardless of where the organization is based. Core obligations: lawful basis for processing, data subject rights, breach notification within 72 hours, data protection by design, DPO requirement in certain cases.
  • CCPA/CPRA: California residents' rights to know, delete, and opt-out of sale of personal information.
  • HIPAA: If you process protected health information of US patients.
  • Sector-specific: Financial services (GLBA), children's data (COPPA/GDPR-K), biometric data (BIPA).

Frame it in terms of what's required of the organization — not what the regulations say in the abstract.


Slide 2: Data Map Summary

Leadership needs to understand what personal data the organization processes, where it lives, and why it's used. A data map (or records of processing activities under GDPR Art. 30) is the foundation of compliance — the presentation should summarize its current state.

Cover:

  • Categories of personal data processed (customer data, employee data, marketing data, financial data)
  • Where data is stored (countries/regions matter for GDPR transfer rules)
  • Who processes data on your behalf (key third-party processors)
  • Lawful basis for each major data processing activity

Common problem: Organizations that haven't completed a data map are in a significant compliance gap. If the map is incomplete, say so, state the timeline for completion, and explain what's known and what isn't.


Slide 3: Data Subject Rights Program

Regulators and board members want to know how the organization handles individual rights requests. GDPR grants individuals the right to access, rectify, delete, restrict, and port their personal data.

Cover:

  • How requests are received (intake channel)
  • Who handles them and what the review process is
  • How you identify and locate data for a given individual across systems
  • Response time performance vs. the regulatory deadline (30 days for GDPR)
  • Volume of requests received and handled in the reporting period
  • Any requests that were not completed within the deadline and why

Slide 4: Third-Party Processor Management

GDPR requires that organizations have data processing agreements (DPAs) in place with all vendors that process personal data on their behalf. Third-party processor risk is one of the most common GDPR compliance gaps.

Cover:

  • Total number of third-party processors identified
  • Percentage with executed DPAs in place
  • Sub-processor disclosure compliance
  • International data transfer mechanisms for processors in non-adequate countries (Standard Contractual Clauses, Binding Corporate Rules, adequacy decisions)
  • High-risk processor assessment status

Slide 5: Privacy by Design and New Project Review

GDPR requires data protection to be built into new systems and processes from the start (Privacy by Design, Art. 25) and Data Protection Impact Assessments (DPIAs) for high-risk processing.

Cover:

  • Privacy review process for new products, features, and data uses
  • Number of DPIAs conducted in the reporting period
  • How privacy requirements are embedded in the development process
  • Any high-risk processing activities identified and mitigated

Slide 6: Incidents and Breach History

Report the organization's breach and near-miss history accurately. Regulators and board members need to understand what happened, how it was handled, and what was done to prevent recurrence.

Cover:

  • Breaches or potential breaches identified in the reporting period
  • Whether each breach met the GDPR notification threshold (risk to rights and freedoms of individuals)
  • Supervisory authority notifications made (if any)
  • Individual notifications made (if any)
  • Root cause and remediation for each reportable incident
  • Near-misses and what they revealed about control gaps

If no breaches occurred: "No reportable personal data breaches occurred in this period. We investigated [X] potential incidents; none met the notification threshold." Explain why — not just assert it.


Slide 7: Compliance Gaps and Remediation

Report the current compliance gaps honestly. No organization is in perfect GDPR compliance — the question is whether gaps are known, risk-assessed, and being remediated.

Format per gap:

  • Gap description (what obligation isn't fully met)
  • Risk level (likelihood and potential regulatory consequence)
  • Remediation plan and timeline
  • Owner

Prioritize by regulatory risk. A missing DPA with a high-volume data processor is higher risk than incomplete retention schedules for a low-volume data set.


Slide 8: Regulatory Landscape and Upcoming Requirements

Privacy regulation is expanding rapidly. Show that the organization is tracking changes that will affect compliance obligations.

Cover:

  • Regulatory developments relevant to the organization (new state laws in the US, EU AI Act implications, adequacy decision changes, regulatory enforcement trends)
  • Expected compliance actions required to address upcoming requirements
  • Timeline and resource implications

Slide 9: Governance and Accountability

Privacy compliance requires clear governance. Board members are increasingly accountable for data protection under GDPR — they need to know who owns privacy within the organization and how oversight is structured.

Cover:

  • DPO appointment status and mandate (if required or voluntarily appointed)
  • Privacy governance structure (who is accountable for what)
  • How the board receives privacy updates and what their oversight role is
  • Privacy training completion rates for relevant staff
  • What the board should formally document as evidence of oversight

What Regulators Look For in Board Minutes

If the board discusses data privacy, the minutes should record: the metrics reported, any gaps disclosed, the board's challenge and response to management, and any decisions or directions given. Regulators reviewing board conduct in the event of a significant breach will look for evidence of genuine oversight — not just that privacy was on the agenda.

Build your next presentation with AI

Generate editable .pptx decks in minutes. Free to start — no card required.

Try it free →