Association of Digital Trust Practitioners

Be part of building excellence in digital trust practice.

The Association brings together the people who keep organizations' data, systems and AI trustworthy, across privacy, security, risk, compliance and AI governance.

Associate Membership is free and open to anyone. Whether you already work in privacy, security, risk, compliance or AI governance, or you are building the skills to move into it, it is how you join the Association.

  • Privacy
  • Security
  • Risk
  • Compliance
  • Third-party oversight
  • AI governance
  • Trust & assurance

Become an Associate Member

By joining you accept the terms and privacy notice. You can add the rest of your profile later.

Already a member? Sign in

Organizations now run on data and AI. Keeping them trustworthy is a profession.

The work sits across security, privacy, audit, legal, IT and now AI, and rarely has a home of its own. The standing people build inside one employer does not travel with them. The Association exists to change that.

A shared standard of practice

A code of ethics and the Digital Trust Common Framework: one control language across the standards and obligations practitioners meet.

Recognition earned on real work

Course certificates and ADTP credentials examined on real work, each with an ID anyone can verify.

A professional home

A community of people who do this work, and a standing that stays yours when roles and employers change.

Practice for the age of AI

Governing AI so it stays accountable, and using it well in the trust work itself.

What Associate Membership includes

What you can use from your first day as a member.

Prepare

Exam preparation

Getting ready for an industry certification? Each one has a readiness check, flashcards and explained practice questions, for 27 certifications, including CISSP, CISM, CISA, CIPP/E, CIPP/US, AIGP and ISO 27001.

Find your exam

Stay current

Regulation and threats, explained

  • The regulations library: 75 privacy, AI and security laws in plain words, from GDPR and HIPAA to every US state privacy law.
  • Regulatory Watch: new laws, rules, enforcement actions and court rulings as they happen.
  • Threat intelligence: reported breaches, ransomware activity and security advisories.
  • The Regulatory and Breach Digests: the developments and incidents that matter, if you want them by email.
Belong

Your place in the Association

  • Your own member number.
  • A verifiable member profile, and a wallet for the certificates and badges you earn.
  • Membership under the Association's Code of Ethics.
Use at work

Templates you can adopt

Policy and standard templates

Complete documents for your organization. Add your organization's name, adjust what you need, and adopt them as your own.

Policy
Acceptable Use Policy

What people may and may not do with your organization's systems, devices and data.

Policy
Artificial Intelligence Acceptable Use Policy

How staff may use AI tools at work, including what information must never go into them.

Policy
Code of Conduct

The behavior your organization expects, conflicts of interest, and how to raise a concern.

Standard
Password Standard

The rules for passwords and signing in to your systems.

Standard
Email and Instant Messaging Standard

How to use email and chat safely: what to share, what to keep, and what to do with suspicious messages.

Working templates

The checklists, records and registers practitioners use day to day, ready to fill in.

Record
Data Sharing Decision Record

One page per share: what data, with whom, channel, purpose, end date, how access is revoked and what copies remain afterwards.

Checklist
Data Room Setup and Close-Out Checklist

Preparing a diligence or vendor data room, watermarking and permissions, and the close-out that removes access, exports and cached copies.

Checklist
Offboarding Data Recovery Checklist

Everything a departing person or contractor may hold: devices, personal cloud, shared links, mailboxes, backups and analytics extracts.

Register
Obligation Register (starter)

The obligations your role touches, who owns each, and the evidence that proves it. You build your first one in DTF-120, Reading a Regulation Without a Lawyer.

Reference

  • The DTCF framework: one set of control objectives mapped to SOC 2, ISO 27001, NIST, HIPAA, GDPR and more.
  • DeepDive: long reads on how the work is actually done.
  • The glossary: the terms of the field, explained plainly.

Join the Association

Joining with colleagues? Set up your organization for seats, assignments and completion evidence.