Product tour

See how DPDPA work moves from data to evidence.

The tour follows a practical operating sequence. Each step connects the responsible team, the required record, the action to be completed, and the evidence retained.

Stage 1 of 6

Map personal data and processing

Begin with the organisation's real data environment.

Record business areas, systems, databases, files, processors, data categories, responsible owners, and processing activities. Use discovery workflows to identify information that requires review and classification.

Key functions

  • Business domain and system inventory
  • Personal data categories and locations
  • Processor and data movement records
  • Discovery findings and review status
  • Ownership and validation workflow

Stage 1. Map personal data and processing

Begin with the organisation's real data environment.

Record business areas, systems, databases, files, processors, data categories, responsible owners, and processing activities. Use discovery workflows to identify information that requires review and classification.

  • Business domain and system inventory
  • Personal data categories and locations
  • Processor and data movement records
  • Discovery findings and review status
  • Ownership and validation workflow
Open Personal Data Inventory

Stage 2. Define purposes, grounds, and retention

Document why personal data is processed and how that processing is governed.

Connect each purpose with the relevant personal data, applicable processing ground, responsible function, processors, retention requirement, and current status.

  • Purpose registry
  • Personal data mapping
  • Processing ground record
  • Retention requirement
  • Version and approval history
Open Purpose Registry

Stage 3. Publish notices and manage consent

Prepare clear notices and consent experiences for the relevant service or processing activity.

Record the notice version shown to the Data Principal, the consent decision, the time of the decision, and any later withdrawal. Make the withdrawal process accessible through the configured channel.

  • Notice drafting and version control
  • Language configuration
  • Consent experience configuration
  • Grant and withdrawal records
  • Privacy Centre preferences
Open Consent Management

Stage 4. Receive rights requests and grievances

Give Data Principals a clear service channel and give internal teams a controlled work process.

Verify the request, assign responsibility, coordinate the response, communicate status, record the outcome, and preserve the closure evidence.

  • Request and grievance intake
  • Identity verification workflow
  • Assignment and status tracking
  • Internal review and approval
  • Communication and closure record
Open Rights and Grievances

Stage 5. Carry out retention, erasure, and suppression

Convert an approved decision into accountable operational work.

Create actions for configured systems, monitor execution, manage exceptions, retry failed work, and retain the verification information available from each system.

  • Connected system configuration
  • Data and field mapping
  • Action queue
  • Exception and retry handling
  • Completion and verification record
Open Operational Actions

Stage 6. Review incidents, risk, and evidence

Bring together the records needed for breach response, governance review, management oversight, and audit preparation.

Document incident facts, affected individuals, communications, remediation, processor oversight, impact assessments, processing records, and approved evidence packages.

  • Personal data breach workflow
  • Data Principal communication record
  • Data Protection Board information record
  • Processor and governance records
  • Impact assessment and remediation
  • Evidence and management reporting
Open Risk and Evidence

Continue inside the demonstration workspace.

The demonstration environment allows evaluators to review how the workflows, records, permissions, and operating screens are organised.