Stage 1 of 8
Understand the data environment
Create an organised view of business domains, applications, databases, files, processors, data categories, and processing activities.
Use discovery and review workflows to identify where personal data is processed and where further validation is required.
Business service
Application
Data store
Processor
Personal data
Owner
Stage 1. Understand the data environment
Create an organised view of business domains, applications, databases, files, processors, data categories, and processing activities.
Use discovery and review workflows to identify where personal data is processed and where further validation is required.
Stage 2. Define the processing purpose
Record the purpose, relevant personal data, applicable processing ground, responsible team, processor involvement, and retention requirement.
Keep changes versioned so that the organisation can review what applied at a particular time.
Stage 3. Prepare and publish notices
Draft clear notices that describe the personal data involved, the purpose of processing, the service being provided, available rights, and the organisation's contact channel.
Manage notice versions and the languages selected for the implementation.
Stage 4. Manage consent where it is required
Configure the consent experience, record the decision, preserve the related notice version, and provide an accessible withdrawal process.
Use the Privacy Centre to give the Data Principal a clear place to review preferences and available service channels.
Stage 5. Handle rights and grievances
Receive requests through a controlled intake process. Verify the request, assign responsibility, track the response period, coordinate work, communicate with the Data Principal, and record closure.
Supported workflows can cover access to information about personal data, correction, completion, updating, erasure, grievance redressal, and nomination.
Stage 6. Carry out required system actions
Create controlled jobs for erasure, suppression, retention, or another configured action across relevant connected systems.
Track execution, exceptions, retries, and available verification so that the operational record reflects what was actually completed.
Stage 7. Respond to personal data breaches
Record the incident, affected data, likely impact, affected Data Principals, response decisions, communications, remediation, and reporting activity.
Support immediate response and intimation requirements while tracking the information required for detailed reporting.
Stage 8. Maintain governance and evidence
Maintain processor records, impact assessments, processing records, remediation work, audit material, and management reporting.
Prepare evidence packages from approved records without changing the underlying operating history.