Privacy Management
Understand and govern how personal data is processed.
Maintain structured processing records, assess high-risk activities, map data flows and connect privacy risks to controls, policies, systems and vendors.
Overview
Privacy processing activities are logged per department — what data, whose, why, and where it goes — with high-risk activities assessed through a DPIA and a full Record of Processing Activities generated from the same structured records.
The business problem
- No one has a complete, current picture of what personal data is processed, by whom, or why.
- High-risk processing activities aren't consistently assessed before they start.
- Data flows to vendors and other systems aren't mapped, so a transfer risk can go unnoticed.
- Producing a Record of Processing Activities for a regulator means assembling it from scratch each time.
Key capabilities
Department-based privacy records
- Processing activity, system, application, and vendor
- Data category, data subject, purpose, and legal basis
- Retention, location, and transfer
- Linked security control, risk, and review status
DPIA
- Log and describe high-risk processing activity
- Assess necessity and proportionality
- Identify privacy risks and linked controls
- DPO review, comments, recommendations, approval or rejection, and scheduled reassessment
ROPA and data mapping
- Generate a Record of Processing Activities covering staff, customer, supplier, and stakeholder data
- Identify recipients, systems, vendors, locations, transfers, retention, and security measures
- Data inventory and flow mapping by category, source, department, system, and vendor
- Assign an owner and review date, then generate the report
How it works
- 1A department logs a new processing activity — what data, why, and where it's stored.
- 2If the activity is high-risk, a DPIA is opened, assessed, and reviewed by the DPO.
- 3Identified privacy risks are linked to controls and, where relevant, to the risk register.
- 4The activity feeds into the organisation's Record of Processing Activities automatically.
- 5The record is reviewed on schedule, and any change — a new vendor, a new system — updates it.
How this works by department
The same module, applied to how each department actually uses it.
Finance
Finance-held data — payroll, banking details, payment records — is logged in the processing record with its legal basis and retention period.
HR
HR processing activities — recruitment, payroll, performance records — are the most common source of high-risk activity, routed to a DPIA when they qualify.
Legal/Compliance
Legal and the DPO review every DPIA and confirm the processing record's legal basis is current.
Procurement/Vendor Management
Any vendor handling personal data is linked to the relevant processing activity, so a vendor change is reflected in the data-flow map.
IT/Security
IT records which systems store or transmit personal data, feeding the data inventory and transfer mapping directly.
Risk & Audit
Privacy risks identified during a DPIA are linked into the enterprise risk register instead of living only in the privacy record.
See it in the platform
Product screenshots for Privacy Management are available in a live walkthrough with a specialist.
View Product Demo →Dashboards and reports
Typical users
Business outcomes
- One current, structured picture of what personal data is processed and why
- High-risk activities assessed through a DPIA before processing begins
- Data flows to vendors and systems mapped, not assumed
- A Record of Processing Activities generated from real records, not assembled under deadline
Frequently asked questions
- Where does ROPA generation live — Privacy or Business Continuity?
- Privacy Management, since it's a data-processing record rather than a continuity artifact. The Business Continuity module links to it where processing activities support a critical service.
- Does every processing activity require a DPIA?
- No — a DPIA applies to processing identified as high-risk. Lower-risk activities are still logged in the structured privacy record but don't require the full DPIA workflow.
Part of the connected GRC platform