← All use cases · Full directory
Legal & Compliance Decision Trees
Legal and compliance decision trees: NDA type, contract review level, data breach response, GDPR classification, IP protection. Free to run and embed.
6 published trees in this category. Every one runs as a guided wizard in the browser — no signup — and can be copied as the starting point for your own version.
Trees in this category
GDPR Personal Data Classification
Processing personal data without a clear lawful basis is one of the highest-risk compliance failures under GDPR — fines reach 4% of global annual turnover. This tree walks you through the key classification questions for a specific dataset or processing activity, from identifying whether data is personal at all, through lawful basis and special category checks, to international transfer requirements.
How should I protect this intellectual property — patent, trademark, or copyright?
Narrows down the most appropriate intellectual property protection mechanism for a given asset by evaluating the nature of the creation, its technical character, prior disclosure status, and commercial exploitation intent. The elimination process identifies which protection regimes remain viable given the asset's characteristics. Always validate the outcome with qualified IP counsel before filing, relying on, or publicly communicating any protection strategy.
How should I respond to a data breach?
Determines the appropriate response actions following a suspected or confirmed data security incident, from simple internal containment through to full regulatory notification and crisis management. The assessment is calibrated to GDPR obligations under Articles 33 and 34 but is relevant to any privacy regime that imposes breach notification duties. Complete this assessment as soon as a potential incident is identified — time limits for regulatory notification begin from the moment you become aware, not from when the breach is confirmed.
What level of legal review does this contract need?
Determines the appropriate level of legal review a contract requires before execution. Considers contract value, risk profile, template availability, counterparty terms, and the presence of IP, data processing obligations, or regulated activities to route each contract to the right review tier. Use this tool at the outset of any new commercial engagement to avoid under- or over-investing legal resource.
Which dispute resolution method is right for this situation?
Guides the selection of the most appropriate dispute resolution pathway given the nature of the relationship, the value and urgency of the dispute, confidentiality requirements, and any pre-existing contractual dispute resolution obligations. Choosing the right mechanism early avoids unnecessary cost, relationship damage, and procedural delay. This tool should be used at the point a dispute becomes apparent, before any formal steps are taken.
Which type of NDA do I need — mutual, unilateral, or multilateral?
Guides the selection of the correct non-disclosure agreement structure for a given commercial relationship. Evaluates the direction of information flow, the number of parties involved, the anticipated relationship duration, and whether standard terms are acceptable to ensure the chosen NDA provides proportionate and enforceable protection. Complete this assessment before any confidential information is shared.
All Legal & Compliance trees
- GDPR Personal Data Classification — Processing personal data without a clear lawful basis is one of the highest-risk compliance failures under GDPR — fines reach 4% of global annual turnover. This tree walks you through the key classification questions for a specific dataset or processing activity, from identifying whether data is personal at all, through lawful basis and special category checks, to international transfer requirements.
- How should I protect this intellectual property — patent, trademark, or copyright? — Narrows down the most appropriate intellectual property protection mechanism for a given asset by evaluating the nature of the creation, its technical character, prior disclosure status, and commercial exploitation intent. The elimination process identifies which protection regimes remain viable given the asset's characteristics. Always validate the outcome with qualified IP counsel before filing, relying on, or publicly communicating any protection strategy.
- How should I respond to a data breach? — Determines the appropriate response actions following a suspected or confirmed data security incident, from simple internal containment through to full regulatory notification and crisis management. The assessment is calibrated to GDPR obligations under Articles 33 and 34 but is relevant to any privacy regime that imposes breach notification duties. Complete this assessment as soon as a potential incident is identified — time limits for regulatory notification begin from the moment you become aware, not from when the breach is confirmed.
- What level of legal review does this contract need? — Determines the appropriate level of legal review a contract requires before execution. Considers contract value, risk profile, template availability, counterparty terms, and the presence of IP, data processing obligations, or regulated activities to route each contract to the right review tier. Use this tool at the outset of any new commercial engagement to avoid under- or over-investing legal resource.
- Which dispute resolution method is right for this situation? — Guides the selection of the most appropriate dispute resolution pathway given the nature of the relationship, the value and urgency of the dispute, confidentiality requirements, and any pre-existing contractual dispute resolution obligations. Choosing the right mechanism early avoids unnecessary cost, relationship damage, and procedural delay. This tool should be used at the point a dispute becomes apparent, before any formal steps are taken.
- Which type of NDA do I need — mutual, unilateral, or multilateral? — Guides the selection of the correct non-disclosure agreement structure for a given commercial relationship. Evaluates the direction of information flow, the number of parties involved, the anticipated relationship duration, and whether standard terms are acceptable to ensure the chosen NDA provides proportionate and enforceable protection. Complete this assessment before any confidential information is shared.
How to use these trees
- Run one to see how the questions are ordered and where each path ends.
- Copy the source. Every tree is plain text, so you can lift it and edit the wording for your own organisation. Syntax reference →
- Embed it in your wiki, help centre, or intranet with one snippet that stays current whenever you edit the tree. Embedding guide →