Automated workflows for GDPR privacy operations
Manage Article 30 records, conduct Article 35 DPIAs, handle data subject requests, track sub-processors and maintain evidence of consent within a single operational stack.
Overview
One workspace for GDPR execution
Records of processing activities, DPIAs, data subject requests, retention rules and consent are operational work, not documents. The Privacy module runs them as workflows with owners, deadlines and a full history.
Every privacy record is linked to the systems, vendors and controls it depends on, so the register stays current when the rest of the organisation changes.
Challenge and solution
RoPA records, DPIAs, DSRs, retention rules and consent are often managed across separate tools, spreadsheets and inboxes. This makes privacy records harder to update, audit and export.
Manage Article 30 records, conduct Article 35 DPIAs, handle data subject requests, track sub-processors and maintain evidence of consent within a single operational stack.
Features
What the Privacy module includes
Records of processing (Article 30)
Maintain the RoPA with purposes, legal bases, data categories, recipients and retention, exportable on request.
DPIAs (Article 35)
Run data protection impact assessments as guided workflows, linked to the processing activities and risks they cover.
Data subject requests
Intake, assign and resolve access, erasure and portability requests against statutory deadlines.
Retention rules
Define retention schedules per data category and system, with evidence of enforcement.
Sub-processor tracking
Keep the Article 28 sub-processor register current, shared with the Third Parties module.
Consent evidence
Maintain proof of consent alongside the processing activities that rely on it.
See ResilientX GRC in action
Privacy module FAQ
Does the module cover the Article 30 register?
Yes. The record of processing activities is maintained as structured data — purposes, legal bases, categories, recipients and retention — and can be exported when a supervisory authority asks for it.
How are data subject requests tracked?
Each request is logged with its type, requester and receipt date, assigned to an owner and tracked against the statutory deadline, with the full history of actions kept for audit.
Is the sub-processor register shared with vendor management?
Yes. Sub-processors are third parties, so the Article 28 register lives in the Third Parties module and is visible from privacy records without duplication.