Governance & Accountability
Privacy program charter, roles (DPO/Privacy Lead), policies, accountability structures, and board reporting.
- Privacy program charter and scope
- DPO / Privacy Lead appointment
- Privacy policy framework
- +2 more
4 controls · Open module →
Data Inventory & RoPA
Records of Processing Activities, data flow mapping, system inventory, and data categorization.
- Records of Processing Activities (RoPA)
- Data flow and lineage mapping
- Personal data categories and fields
- +2 more
4 controls · Open module →
Data Discovery
Automated and manual discovery of personal data across databases, file shares, SaaS, and cloud — feeding RoPA and classification.
- Discovery scope and data source registry
- Structured database and warehouse scanning
- Unstructured files, email, and cloud SaaS discovery
- +2 more
4 controls · Open module →
Data Classification
Taxonomy, labeling, and handling rules for personal and sensitive data — manual and automated classification with accuracy review.
- Classification taxonomy (public, internal, confidential, restricted)
- PII / sensitive data labels and handling rules
- Automated classification rules and DLP integration
- +2 more
4 controls · Open module →
Privacy Risk & DPIA
Privacy risk assessments, Data Protection Impact Assessments, Legitimate Interest Assessments, and risk treatment.
- Privacy risk register
- DPIA / PIA workflow and templates
- Legitimate Interest Assessment (LIA)
- +2 more
3 controls · Open module →
Consent & Legal Basis
Lawful basis determination, consent capture and withdrawal, preference management, and legitimate use documentation.
- Lawful basis per processing activity
- Consent management platform integration
- Granular consent and preference center
- +2 more
4 controls · Open module →
Transparency & Notices
Privacy notices, layered notices, cookie policies, employee privacy notices, and transparency at collection points.
- External privacy notice management
- Layered / just-in-time notices
- Cookie and tracking disclosures
- +2 more
3 controls · Open module →
Data Subject Rights
Data Subject Access Requests and rights fulfillment — access, rectification, erasure, portability, objection, and restriction.
- DSAR intake and identity verification
- Access, rectification, erasure workflows
- Data portability export
- +2 more
5 controls · Open module →
Privacy by Design & Default
Privacy embedded in SDLC, product reviews, default settings, minimization, and pseudonymization controls.
- Privacy review in SDLC gates
- Data minimization checklist
- Default privacy settings validation
- +2 more
4 controls · Open module →
Processors & Vendors
Data Processing Agreements, sub-processor management, vendor privacy assessments, and processor oversight.
- Processor and sub-processor register
- DPA template and execution tracking
- Vendor privacy assessment questionnaires
- +2 more
4 controls · Open module →
Third-Party Risk Management
Enterprise vendor risk program — assessments, questionnaires, continuous monitoring, and remediation on ComplAI, aligned with PrivyCore processor privacy obligations.
- Vendor portfolio and tiering (ComplAI)
- Security & privacy questionnaire automation
- Continuous external intelligence and monitoring
- +3 more
Open ComplAI bridge →
Cross-Border Transfers
International data transfer mechanisms — SCCs, adequacy, BCRs, Transfer Impact Assessments, and localization.
- Transfer register and destination mapping
- Standard Contractual Clauses (SCCs)
- Transfer Impact Assessment (TIA)
- +2 more
3 controls · Open module →
Breach Response & Notification
Personal data breach detection, assessment, containment, regulatory notification, and data principal communication.
- Breach detection and triage playbook
- 72-hour / DPDP notification timelines
- Breach severity and risk assessment
- +2 more
4 controls · Open module →
Retention & Disposal
Retention schedules, automated deletion, secure disposal, and archival policies for personal data.
- Retention schedule by data category
- Automated deletion and expiry jobs
- Secure disposal and media sanitization
- +2 more
3 controls · Open module →
Training & Awareness
Privacy awareness training, role-based curricula, phishing simulations, and workforce attestation.
- Annual privacy training program
- Role-based training (engineering, HR, sales)
- New hire privacy onboarding
- +2 more
2 controls · Open module →
Monitoring & Audit
Continuous compliance monitoring, internal audits, metrics and KPIs, and external certification readiness.
- Privacy program KPIs and dashboards
- Internal privacy audit schedule
- Control effectiveness testing
- +2 more
4 controls · Open module →
Grievance Redressal
Data Principal grievance intake, tracking, resolution, and regulatory timeline alignment under the DPDP Act.
- Grievance intake channels
- Acknowledgement and SLA tracking
- Resolution and escalation
- +2 more
0 controls · Open module →
Program operations
Integrations
Connect CMP, IDAM, HRMS, discovery tools, and ticketing — sync identities and processing activities into your privacy program.
Privacy Intelligence
Gap analysis, DPIA assistance, RoPA reconciliation hints, and DSAR triage — AI-assisted workflows scoped to privacy controls.
Program Cycles
Annual privacy review milestones, framework refresh cycles, and board reporting checkpoints aligned to DPDP and ISO 27701.
Browse all controls in the control catalog.