2026.05-privacy2026-05-05

Privacy / DPO Module (MVP)

Privacy / DPO Module (MVP)

Feature flag: privacy_operations (contact your account manager to enable)

What’s new

Personal Data Inventory

  • Tag assets and suppliers with personal data categories, lawful basis, and retention periods
  • Assets with special-category data (Art. 9) are automatically flagged as requiring a DPIA
  • Supplier records now capture DPA status, transfer mechanism (SCC / Adequacy Decision / DPF / BCR), and a sub-processor list

Privacy Register (RoPA)

  • Create and manage Records of Processing Activities per GDPR Art. 30
  • Link processing activities to assets, suppliers, data categories, and data subjects
  • AI-powered suggestions to bootstrap your register from existing assets and suppliers
  • PDF export for regulatory submissions
  • Retire discontinued activities while preserving the record for audit purposes

DPIA Lite

  • 7-step AI-guided Data Protection Impact Assessment wizard
  • Severity × likelihood risk matrix for each identified risk
  • Identified risks are automatically created in the Risk Register, linked back to the processing activity
  • Finalized records are immutable; re-running a DPIA creates a new record that supersedes the previous one with full supersession history
  • Processing activity DPIA status updated automatically on finalization

DSAR Readiness Check

  • Identify which systems and suppliers hold data for a given subject type
  • Subject identifier is processed in memory only — never stored or logged
  • Audit trail records a cryptographic hash of the identifier only, never the raw value
  • Rate-limited to 30 checks per hour per user

DPO Cockpit

  • Privacy posture score aggregating six compliance dimensions
  • Six action cards surfacing gaps: missing DPAs, missing transfer mechanisms, overdue retention reviews, open DPIAs, incomplete records, and unlawful processing
  • Each card links directly to the filtered list of items requiring attention

Supplier Privacy Extension

  • DPA status, transfer mechanism, and sub-processor list fields on supplier records
  • “Missing DPA” warning displayed on supplier assessment and review panels when the supplier processes personal data without a signed DPA

Out of scope (this release)

  • Full DSAR ticketing and subject response workflow
  • Cookie consent management
  • Art. 33/34 breach notification workflow
  • Dedicated DPO role (planned for next release — requires tenant:dpo claim and role management UI)
  • Automated data subject identification (readiness check identifies candidate systems; manual verification in each system is required)
Last reviewed: 2026-05-26

Was this page helpful?

Esc