TrustOS workspace
Used by authorised organisational teams to configure the programme, manage work, coordinate actions, and review evidence.
TrustOS connects the records, workflows, people, and system actions involved in a DPDPA programme.
The platform is designed to help an organisation understand its personal data processing, communicate clearly with Data Principals, manage requests, coordinate operational actions, and retain evidence of the work completed.
Create an organised view of business domains, applications, databases, files, processors, data categories, and processing activities.
Use discovery and review workflows to identify where personal data is processed and where further validation is required.
Record the purpose, relevant personal data, applicable processing ground, responsible team, processor involvement, and retention requirement.
Keep changes versioned so that the organisation can review what applied at a particular time.
Draft clear notices that describe the personal data involved, the purpose of processing, the service being provided, available rights, and the organisation's contact channel.
Manage notice versions and the languages selected for the implementation.
Configure the consent experience, record the decision, preserve the related notice version, and provide an accessible withdrawal process.
Use the Privacy Centre to give the Data Principal a clear place to review preferences and available service channels.
Receive requests through a controlled intake process. Verify the request, assign responsibility, track the response period, coordinate work, communicate with the Data Principal, and record closure.
Supported workflows can cover access to information about personal data, correction, completion, updating, erasure, grievance redressal, and nomination.
Create controlled jobs for erasure, suppression, retention, or another configured action across relevant connected systems.
Track execution, exceptions, retries, and available verification so that the operational record reflects what was actually completed.
Record the incident, affected data, likely impact, affected Data Principals, response decisions, communications, remediation, and reporting activity.
Support immediate response and intimation requirements while tracking the information required for detailed reporting.
Maintain processor records, impact assessments, processing records, remediation work, audit material, and management reporting.
Prepare evidence packages from approved records without changing the underlying operating history.
Review current obligations, assigned work, pending requests, incidents, evidence, and programme status.
Maintain business domains, systems, stores, data categories, ownership, processing activities, and data movement records.
Manage processing purposes, data categories, applicable grounds, retention, notice content, versions, and publication status.
Configure consent experiences, record decisions, support withdrawal, review history, and maintain tamper evident records.
Give Data Principals a dedicated place to manage consent, submit requests, raise grievances, and review available information.
Manage intake, verification, assignment, status, communication, response work, approval, and closure evidence.
Define retention rules, review expiry conditions, create actions, manage exceptions, and record completion.
Connect selected business systems, map relevant data, carry out configured actions, and retain available verification details.
Manage incident records, response steps, communication, reporting information, remediation, and review evidence.
Maintain processor details, service relationships, responsibilities, review records, contractual references, and oversight activity.
Document higher risk processing, assess potential impact on Data Principals, assign remediation, and retain review decisions.
Generate approved operational reports and evidence packages for management, legal review, audit, or regulatory response.
Manage tenants, users, roles, permissions, configuration, activity records, and implementation settings.
Used by authorised organisational teams to configure the programme, manage work, coordinate actions, and review evidence.
Used by Data Principals to review available information, manage consent, submit requests, raise grievances, and use other configured service channels.
The product tour follows the sequence from personal data mapping and purpose definition through consent, rights handling, system action, risk review, and evidence.