Section 01 of 11
Personal data inventory
Purpose. Maintain a structured view of where personal data is processed and who is responsible for it.
Operator workflow
- Create business domains and services.
- Add applications, databases, files, and other data stores.
- Record personal data categories and processing activities.
- Associate processors, owners, and system contacts.
- Run or import discovery findings where available.
- Review and approve the resulting record.
Expected records
- Data store inventory
- Processing activity record
- Personal data category record
- Processor relationship
- Ownership and review history
- Discovery finding and resolution
Section 02 of 11
Purposes and privacy notices
Purpose. Connect each processing activity with a clear purpose, applicable ground, relevant data, retention requirement, and notice.
Operator workflow
- Create the processing purpose.
- Select the relevant personal data.
- Record the applicable processing ground.
- Add the responsible business function.
- Set the retention requirement.
- Draft and review the notice.
- Publish an approved version.
Expected records
- Purpose version
- Data category mapping
- Processing ground record
- Retention requirement
- Notice version
- Approval and publication history
Section 03 of 11
Consent management
Purpose. Manage consent requests, decisions, withdrawal, and supporting records where consent is the basis of processing.
Operator workflow
- Select the approved purpose and notice.
- Configure the consent experience.
- Review language and accessibility.
- Publish the approved version.
- Record grant or withdrawal decisions.
- Review history and exceptions.
- Confirm that connected actions are created where required.
Expected records
- Consent experience version
- Notice association
- Grant record
- Withdrawal record
- Decision history
- Downstream action status
- Integrity verification result
Section 04 of 11
Privacy Centre
Purpose. Provide Data Principals with a dedicated service channel.
Available services
- Review and manage consent preferences
- Submit requests for access information
- Submit correction, completion, updating, or erasure requests
- Raise a grievance
- Submit nomination details
- Review request status where configured
- Access published privacy information and contact details
Section 05 of 11
Rights requests and grievances
Purpose. Manage requests through a controlled process from intake to closure.
Operator workflow
- Receive the request.
- Verify identity and authority.
- Classify the request.
- Assign the responsible team.
- Gather the required information or complete the required action.
- Review the response.
- Communicate with the Data Principal.
- Record the outcome and closure evidence.
Expected records
- Request record
- Verification record
- Assignment history
- Communication history
- Internal task record
- Approval record
- Outcome and closure evidence
Section 06 of 11
Retention, erasure, and operational actions
Purpose. Translate an approved retention or rights decision into controlled work across configured systems.
Operator workflow
- Select the relevant processing record or request.
- Confirm the required action.
- Review legal and operational exceptions.
- Create the action for connected systems.
- Monitor execution.
- Resolve failures or exceptions.
- Record completion and available verification.
Expected records
- Action request
- Connected system response
- Exception record
- Retry history
- Completion status
- Verification information
Section 07 of 11
Personal data breach response
Purpose. Coordinate the organisational response to a personal data breach and preserve the required information.
Operator workflow
- Open the incident record.
- Record the nature, timing, location, extent, and likely impact.
- Identify affected Data Principals.
- Record immediate containment and remediation.
- Prepare and record communications to affected Data Principals.
- Record the information provided to the Data Protection Board of India.
- Track additional information and detailed reporting.
- Record findings, corrective action, and closure review.
Expected records
- Incident chronology
- Affected data and system record
- Data Principal communication record
- Board intimation record
- Detailed reporting information
- Remediation action
- Closure review and evidence
Section 08 of 11
Processors and governance
Purpose. Maintain the records used to oversee processors and the organisation's privacy governance activity.
Available records
- Processor details
- Service and processing description
- Data categories involved
- Contractual reference
- Security and compliance review
- Responsible owner
- Issue and remediation record
- Review and renewal history
Section 09 of 11
Impact assessments and risk
Purpose. Document processing that requires structured risk review and record the resulting decisions and remediation.
Operator workflow
- Describe the proposed or existing processing.
- Identify the personal data and affected Data Principals.
- Assess potential impact on Data Principal rights.
- Record existing safeguards.
- Assign further remediation.
- Review and approve the assessment.
- Schedule periodic review where required.
Section 10 of 11
Evidence and reporting
Purpose. Prepare approved records for management review, legal review, audit, or regulatory response.
Available outputs
- Processing records
- Consent and notice history
- Rights and grievance records
- Retention and erasure records
- Personal data breach records
- Processor oversight records
- Impact assessments
- Remediation status
- Approved evidence packages
Section 11 of 11
Administration and access
Purpose. Control who can access the system and what each authorised user can do.
Administration areas
- Tenant configuration
- User accounts
- Roles and permissions
- Authentication settings
- Activity records
- Organisation details
- Branding and language settings
- Notification settings
- Environment and deployment configuration