ResilientX
Module 2 · Privacy

Automated workflows for GDPR privacy operations

Manage Article 30 records, conduct Article 35 DPIAs, handle data subject requests, track sub-processors and maintain evidence of consent within a single operational stack.

Overview

One workspace for GDPR execution

Records of processing activities, DPIAs, data subject requests, retention rules and consent are operational work, not documents. The Privacy module runs them as workflows with owners, deadlines and a full history.

Every privacy record is linked to the systems, vendors and controls it depends on, so the register stays current when the rest of the organisation changes.

Challenge and solution

Privacy operations are fragmented

RoPA records, DPIAs, DSRs, retention rules and consent are often managed across separate tools, spreadsheets and inboxes. This makes privacy records harder to update, audit and export.

One workspace for GDPR execution

Manage Article 30 records, conduct Article 35 DPIAs, handle data subject requests, track sub-processors and maintain evidence of consent within a single operational stack.

Features

What the Privacy module includes

Records of processing (Article 30)

Maintain the RoPA with purposes, legal bases, data categories, recipients and retention, exportable on request.

DPIAs (Article 35)

Run data protection impact assessments as guided workflows, linked to the processing activities and risks they cover.

Data subject requests

Intake, assign and resolve access, erasure and portability requests against statutory deadlines.

Retention rules

Define retention schedules per data category and system, with evidence of enforcement.

Sub-processor tracking

Keep the Article 28 sub-processor register current, shared with the Third Parties module.

Consent evidence

Maintain proof of consent alongside the processing activities that rely on it.

See ResilientX GRC in action

Privacy module FAQ

Does the module cover the Article 30 register?

Yes. The record of processing activities is maintained as structured data — purposes, legal bases, categories, recipients and retention — and can be exported when a supervisory authority asks for it.

How are data subject requests tracked?

Each request is logged with its type, requester and receipt date, assigned to an owner and tracked against the statutory deadline, with the full history of actions kept for audit.

Is the sub-processor register shared with vendor management?

Yes. Sub-processors are third parties, so the Article 28 register lives in the Third Parties module and is visible from privacy records without duplication.