GRC SaaS

Privacy Management

Understand and govern how personal data is processed.

Maintain structured processing records, assess high-risk activities, map data flows and connect privacy risks to controls, policies, systems and vendors.

Overview

Privacy processing activities are logged per department — what data, whose, why, and where it goes — with high-risk activities assessed through a DPIA and a full Record of Processing Activities generated from the same structured records.

The business problem

  • No one has a complete, current picture of what personal data is processed, by whom, or why.
  • High-risk processing activities aren't consistently assessed before they start.
  • Data flows to vendors and other systems aren't mapped, so a transfer risk can go unnoticed.
  • Producing a Record of Processing Activities for a regulator means assembling it from scratch each time.

Key capabilities

Department-based privacy records

  • Processing activity, system, application, and vendor
  • Data category, data subject, purpose, and legal basis
  • Retention, location, and transfer
  • Linked security control, risk, and review status

DPIA

  • Log and describe high-risk processing activity
  • Assess necessity and proportionality
  • Identify privacy risks and linked controls
  • DPO review, comments, recommendations, approval or rejection, and scheduled reassessment

ROPA and data mapping

  • Generate a Record of Processing Activities covering staff, customer, supplier, and stakeholder data
  • Identify recipients, systems, vendors, locations, transfers, retention, and security measures
  • Data inventory and flow mapping by category, source, department, system, and vendor
  • Assign an owner and review date, then generate the report

How it works

  1. 1A department logs a new processing activity — what data, why, and where it's stored.
  2. 2If the activity is high-risk, a DPIA is opened, assessed, and reviewed by the DPO.
  3. 3Identified privacy risks are linked to controls and, where relevant, to the risk register.
  4. 4The activity feeds into the organisation's Record of Processing Activities automatically.
  5. 5The record is reviewed on schedule, and any change — a new vendor, a new system — updates it.

How this works by department

The same module, applied to how each department actually uses it.

Finance

Finance-held data — payroll, banking details, payment records — is logged in the processing record with its legal basis and retention period.

HR

HR processing activities — recruitment, payroll, performance records — are the most common source of high-risk activity, routed to a DPIA when they qualify.

Legal/Compliance

Legal and the DPO review every DPIA and confirm the processing record's legal basis is current.

Procurement/Vendor Management

Any vendor handling personal data is linked to the relevant processing activity, so a vendor change is reflected in the data-flow map.

IT/Security

IT records which systems store or transmit personal data, feeding the data inventory and transfer mapping directly.

Risk & Audit

Privacy risks identified during a DPIA are linked into the enterprise risk register instead of living only in the privacy record.

See it in the platform

Product screenshots for Privacy Management are available in a live walkthrough with a specialist.

View Product Demo →

Dashboards and reports

Record of Processing Activities (ROPA)
DPIA status
High-risk processing activities
Activities by department
Data transfers
Retention review
Vendor processing
Overdue reviews

Typical users

Data Protection OfficerPrivacy ManagerDepartment HeadLegal CounselRisk Manager

Business outcomes

  • One current, structured picture of what personal data is processed and why
  • High-risk activities assessed through a DPIA before processing begins
  • Data flows to vendors and systems mapped, not assumed
  • A Record of Processing Activities generated from real records, not assembled under deadline

Frequently asked questions

Where does ROPA generation live — Privacy or Business Continuity?
Privacy Management, since it's a data-processing record rather than a continuity artifact. The Business Continuity module links to it where processing activities support a critical service.
Does every processing activity require a DPIA?
No — a DPIA applies to processing identified as high-risk. Lower-risk activities are still logged in the structured privacy record but don't require the full DPIA workflow.

Build a more connected privacy management programme.