2026.05-privacy2026-05-05
Privacy / DPO Module (MVP)
Privacy / DPO Module (MVP)
Feature flag: privacy_operations (contact your account manager to enable)
What’s new
Personal Data Inventory
- Tag assets and suppliers with personal data categories, lawful basis, and retention periods
- Assets with special-category data (Art. 9) are automatically flagged as requiring a DPIA
- Supplier records now capture DPA status, transfer mechanism (SCC / Adequacy Decision / DPF / BCR), and a sub-processor list
Privacy Register (RoPA)
- Create and manage Records of Processing Activities per GDPR Art. 30
- Link processing activities to assets, suppliers, data categories, and data subjects
- AI-powered suggestions to bootstrap your register from existing assets and suppliers
- PDF export for regulatory submissions
- Retire discontinued activities while preserving the record for audit purposes
DPIA Lite
- 7-step AI-guided Data Protection Impact Assessment wizard
- Severity × likelihood risk matrix for each identified risk
- Identified risks are automatically created in the Risk Register, linked back to the processing activity
- Finalized records are immutable; re-running a DPIA creates a new record that supersedes the previous one with full supersession history
- Processing activity DPIA status updated automatically on finalization
DSAR Readiness Check
- Identify which systems and suppliers hold data for a given subject type
- Subject identifier is processed in memory only — never stored or logged
- Audit trail records a cryptographic hash of the identifier only, never the raw value
- Rate-limited to 30 checks per hour per user
DPO Cockpit
- Privacy posture score aggregating six compliance dimensions
- Six action cards surfacing gaps: missing DPAs, missing transfer mechanisms, overdue retention reviews, open DPIAs, incomplete records, and unlawful processing
- Each card links directly to the filtered list of items requiring attention
Supplier Privacy Extension
- DPA status, transfer mechanism, and sub-processor list fields on supplier records
- “Missing DPA” warning displayed on supplier assessment and review panels when the supplier processes personal data without a signed DPA
Out of scope (this release)
- Full DSAR ticketing and subject response workflow
- Cookie consent management
- Art. 33/34 breach notification workflow
- Dedicated DPO role (planned for next release — requires
tenant:dpoclaim and role management UI) - Automated data subject identification (readiness check identifies candidate systems; manual verification in each system is required)
Last reviewed: 2026-05-26
Was this page helpful?