PrivyCoreProgram Modules

Program Modules

Sixteen integrated privacy modules — plus four DPDP capability centers aligned to Complynz-style readiness, consent, data intelligence, and rights

1 · Readiness & gap assessment2 · Consent, notices & cookies3 · Data intelligence (RoPA)4 · DSAR & grievance

Governance & Accountability

Govern-P

Privacy program charter, roles (DPO/Privacy Lead), policies, accountability structures, and board reporting.

  • Privacy program charter and scope
  • DPO / Privacy Lead appointment
  • Privacy policy framework
  • +2 more

4 controls · Open module →

Data Inventory & RoPA

Identify-P

Records of Processing Activities, data flow mapping, system inventory, and data categorization.

  • Records of Processing Activities (RoPA)
  • Data flow and lineage mapping
  • Personal data categories and fields
  • +2 more

4 controls · Open module →

Data Discovery

Identify-P

Automated and manual discovery of personal data across databases, file shares, SaaS, and cloud — feeding RoPA and classification.

  • Discovery scope and data source registry
  • Structured database and warehouse scanning
  • Unstructured files, email, and cloud SaaS discovery
  • +2 more

4 controls · Open module →

Data Classification

Identify-P

Taxonomy, labeling, and handling rules for personal and sensitive data — manual and automated classification with accuracy review.

  • Classification taxonomy (public, internal, confidential, restricted)
  • PII / sensitive data labels and handling rules
  • Automated classification rules and DLP integration
  • +2 more

4 controls · Open module →

Privacy Risk & DPIA

Identify-P

Privacy risk assessments, Data Protection Impact Assessments, Legitimate Interest Assessments, and risk treatment.

  • Privacy risk register
  • DPIA / PIA workflow and templates
  • Legitimate Interest Assessment (LIA)
  • +2 more

3 controls · Open module →

Consent & Legal Basis

Control-P

Lawful basis determination, consent capture and withdrawal, preference management, and legitimate use documentation.

  • Lawful basis per processing activity
  • Consent management platform integration
  • Granular consent and preference center
  • +2 more

4 controls · Open module →

Transparency & Notices

Communicate-P

Privacy notices, layered notices, cookie policies, employee privacy notices, and transparency at collection points.

  • External privacy notice management
  • Layered / just-in-time notices
  • Cookie and tracking disclosures
  • +2 more

3 controls · Open module →

Data Subject Rights

Control-P

Data Subject Access Requests and rights fulfillment — access, rectification, erasure, portability, objection, and restriction.

  • DSAR intake and identity verification
  • Access, rectification, erasure workflows
  • Data portability export
  • +2 more

5 controls · Open module →

Privacy by Design & Default

Control-P

Privacy embedded in SDLC, product reviews, default settings, minimization, and pseudonymization controls.

  • Privacy review in SDLC gates
  • Data minimization checklist
  • Default privacy settings validation
  • +2 more

4 controls · Open module →

Processors & Vendors

Govern-P

Data Processing Agreements, sub-processor management, vendor privacy assessments, and processor oversight.

  • Processor and sub-processor register
  • DPA template and execution tracking
  • Vendor privacy assessment questionnaires
  • +2 more

4 controls · Open module →

Third-Party Risk Management

ComplAIGovern-P

Enterprise vendor risk program — assessments, questionnaires, continuous monitoring, and remediation on ComplAI, aligned with PrivyCore processor privacy obligations.

  • Vendor portfolio and tiering (ComplAI)
  • Security & privacy questionnaire automation
  • Continuous external intelligence and monitoring
  • +3 more

Open ComplAI bridge →

Cross-Border Transfers

Control-P

International data transfer mechanisms — SCCs, adequacy, BCRs, Transfer Impact Assessments, and localization.

  • Transfer register and destination mapping
  • Standard Contractual Clauses (SCCs)
  • Transfer Impact Assessment (TIA)
  • +2 more

3 controls · Open module →

Breach Response & Notification

Protect-P

Personal data breach detection, assessment, containment, regulatory notification, and data principal communication.

  • Breach detection and triage playbook
  • 72-hour / DPDP notification timelines
  • Breach severity and risk assessment
  • +2 more

4 controls · Open module →

Retention & Disposal

Control-P

Retention schedules, automated deletion, secure disposal, and archival policies for personal data.

  • Retention schedule by data category
  • Automated deletion and expiry jobs
  • Secure disposal and media sanitization
  • +2 more

3 controls · Open module →

Training & Awareness

Govern-P

Privacy awareness training, role-based curricula, phishing simulations, and workforce attestation.

  • Annual privacy training program
  • Role-based training (engineering, HR, sales)
  • New hire privacy onboarding
  • +2 more

2 controls · Open module →

Monitoring & Audit

Govern-P

Continuous compliance monitoring, internal audits, metrics and KPIs, and external certification readiness.

  • Privacy program KPIs and dashboards
  • Internal privacy audit schedule
  • Control effectiveness testing
  • +2 more

4 controls · Open module →

Grievance Redressal

Communicate-P

Data Principal grievance intake, tracking, resolution, and regulatory timeline alignment under the DPDP Act.

  • Grievance intake channels
  • Acknowledgement and SLA tracking
  • Resolution and escalation
  • +2 more

0 controls · Open module →

Program operations

Browse all controls in the control catalog.