Skip to main content
Version: 1.0.0

Privacy and Awareness

Privacy and Awareness support two governance needs: privacy program execution and user awareness. Some tenants may use both; others may enable only one area.

Privacy and Surveys are available by default. Training is an optional area that is turned off by default, because most customers run awareness training in a separate learning management system (LMS). A tenant can opt in to the built-in Training area by enabling its feature flag.

1. Background and Business Purpose

Privacy records explain how personal data is processed, protected, transferred, and handled when data subjects make requests. Surveys collect awareness, feedback, or control-understanding responses from users. Training records, when the area is enabled, prove that users receive required courses.

Main outcomes:

  • maintain processing activity records
  • manage DSARs and privacy impact assessments
  • track consent records, cross-border transfers, and data flows
  • assess PDPL readiness and run privacy automation
  • maintain a data governance register
  • create, assign, and analyze surveys
  • optionally create, assign, and monitor training when the Training area is enabled

2. Privacy Records

RecordPurpose
Processing ActivityDocuments personal-data processing purpose, owner, systems, data categories, and legal/business context.
DSARTracks data subject access or privacy rights requests.
Privacy Impact AssessmentReviews privacy risk and controls for processing or projects.
Consent RecordTracks consent basis and status where consent is used.
Cross-Border TransferDocuments data movement between jurisdictions or external processors.
Data Flow MapShows how data moves between systems, owners, vendors, and locations.

3. Privacy Operating Flow

  1. Open Privacy.
  2. Create or update the relevant privacy record.
  3. Assign owner and department.
  4. Link related asset, third party, policy, risk, or evidence.
  5. Complete required fields such as purpose, data categories, retention, transfer, and control context.
  6. Route through workflow when review or approval is required.
  7. Create issues or risks for gaps.
  8. Review records periodically.

4. DSAR Flow

  1. Create DSAR record.
  2. Enter requester, request type, received date, due date, and scope.
  3. Assign owner.
  4. Verify identity and request validity where required.
  5. Coordinate search, review, and response.
  6. Record response date and evidence.
  7. Close the request.

DSAR statuses:

StatusMeaning
NewRequest received.
ValidatingIdentity or request validity is being confirmed.
In ProgressResponse work is underway.
Pending ApprovalResponse is awaiting review.
CompletedResponse sent and documented.
Rejected / CancelledRequest not processed with rationale.

5. Privacy Impact Assessment Flow

  1. Create PIA.
  2. Describe processing/project and owner.
  3. Link assets, third parties, data flows, and policies.
  4. Identify privacy risks and controls.
  5. Set the privacy risk rating using likelihood and impact.
  6. Record recommendations and required actions.
  7. Submit for review if workflow is enabled.
  8. Close when actions are complete or accepted.

A PIA carries a privacy risk score calculated as Likelihood × Impact, producing a value from 1 to 25. Use the score to prioritize which assessments and required actions need attention first. Each PIA also follows a full lifecycle from draft, through review and approval, to completion or acceptance, so the assessment workload and unresolved exposure stay visible in reporting.

Each of these is a dedicated register page under Privacy.

Use the consent register to record the lawful basis and consent status where processing relies on consent. For each record, capture the data subject or audience, purpose, consent basis, the date consent was given, and its current status (such as granted, withdrawn, or expired). Update the record when consent is withdrawn so downstream processing activities can be reviewed.

Cross-Border Transfers

Use the transfers register to document personal data moving between jurisdictions or to external processors. For each transfer, record the source and destination countries, the receiving party, the transfer mechanism or safeguard relied upon, the data categories involved, and the related processing activity. Link transfers to the relevant vendor and asset so cross-border exposure is visible in reporting.

Data Flow Maps

Use the data flow map to show how personal data moves between systems, owners, vendors, and locations. Build the flow from source to destination, attach the systems and assets involved, and link the related processing activities and transfers. Keep flows current when systems or processors change so PIAs and transfer reviews stay accurate.

7. Data Governance Register

The Data Governance register (Privacy → Data Governance) maintains accountable ownership and control over the organization's data categories.

RecordPurpose
Data CategoryA defined category of data with assigned steward and custodian, classification, and retention/disposal rules.
Data-Sharing AgreementRecords an agreement governing how a data category is shared internally or externally.
Quality MetricCaptures data quality metrics and scores for a category.
Data-Discovery ScanRecords a scan used to discover where data resides.

Operating flow:

  1. Open Privacy → Data Governance.
  2. Create a data category with its steward, custodian, and classification.
  3. Set retention and disposal rules.
  4. Add any data-sharing agreements that apply.
  5. Record quality metrics and scores, and run data-discovery scans.
  6. Submit the record for review.
  7. The reviewer approves or rejects the record.

Each record follows a submit → approve/reject lifecycle so ownership, classification, and retention decisions are reviewed before they become authoritative.

8. PDPL Readiness and Automation

Readiness Dashboard

The readiness dashboard (Privacy → Readiness) gives a scored view of PDPL preparedness, broken down by area and individual check. For each check it shows:

  • the mapped PDPL article
  • the evidence required to satisfy the check
  • automation actions that can help close the gap
  • the current readiness score for the area and overall

Use the dashboard to see where the program stands, what evidence is missing, and which checks can be advanced through automation.

PDPL Automation

The automation page (Privacy → Automation) runs actions that accelerate readiness. Available actions:

ActionOutcome
Generate policy packProduces a set of PDPL-aligned policies.
Generate remediation tasksCreates tasks for the gaps identified in readiness.
Bootstrap documentsCreates the starter privacy documents the program needs.
Export evidence/document packPackages the privacy evidence and documents for review or audit.

Each run is tracked with run and status information so you can confirm what was generated and when.

Monitoring and Gap Deadlines

PDPL monitoring gap-deadlines are suppressed for tenants that have no privacy footprint. Deadlines are only created once the tenant has at least one processing activity, DSAR, consent record, or privacy evidence record, so tenants that do not yet use the privacy area are not flagged with deadlines that do not apply to them.

9. Awareness and Training

Surveys are available by default; the Training area is optional and turned off by default. Enable the Training area only when the organization wants to run courses inside the platform instead of, or alongside, a separate LMS.

RecordPurposeAvailability
SurveyQuestionnaire used to measure awareness, feedback, or control understanding.Available by default.
Training CourseTraining content, quiz, file, or lesson record.Requires the Training area to be enabled.
Training CampaignAssignment of training to users or groups.Requires the Training area to be enabled.
Role RequirementDefines required courses for a role or job position.Requires the Training area to be enabled.
My TrainingUser-facing list of assigned training.Requires the Training area to be enabled.

Training operating flow (when the Training area is enabled):

  1. Open Training.
  2. Create a training course with title, description, content, and completion rules.
  3. Publish the course when ready.
  4. Create role requirements or a training campaign.
  5. Assign users, roles, or departments.
  6. Monitor completion and overdue users.
  7. Review quiz results.
  8. Use reports for management follow-up.

Training statuses:

StatusMeaning
DraftCourse is being prepared.
PublishedCourse can be assigned.
AssignedUser has training to complete.
In ProgressUser started the course.
CompletedUser completed required activity.
OverdueDue date passed without completion.

10. Surveys

Surveys collect awareness, feedback, or control-understanding responses from users and are available by default. The Surveys area has its own feature flag.

Survey Lifecycle

StatusMeaning
DraftSurvey is being built and is not yet visible to respondents.
ActiveSurvey is published and assigned respondents can submit responses.
ClosedSurvey no longer accepts responses; results remain available for analysis.

Building and Assigning a Survey

  1. Open Surveys and create a survey while it is in Draft.
  2. Add questions, marking any that must be answered as required.
  3. Choose whether the survey is anonymous. An anonymous survey collects responses without attributing them to an individual respondent.
  4. Assign the survey to users.
  5. Move the survey to Active so assigned respondents can take it.
  6. Move the survey to Closed when collection is complete.

Responding to a Survey

Respondents see their assigned surveys on the My Surveys page, open an active survey, answer the questions, and submit. Required questions are enforced on submission: a response cannot be submitted until every required question is answered.

Analyzing Results

  • Export all responses to CSV for offline review or record-keeping.
  • Review per-question analytics, including the distribution of answers, the completion percentage, and the average time taken.

Anonymous surveys still produce aggregate analytics, but individual responses are not attributed to a respondent.

11. Roles and Permissions

RoleTypical Responsibility
Privacy ownerOwns privacy records, DSARs, PIA, transfers, data governance, and PDPL readiness.
Data steward / custodianOwns data categories, classification, retention, and quality in the data governance register.
Data/process ownerProvides processing context and evidence.
Survey coordinatorBuilds surveys, assigns respondents, and reviews analytics.
Training coordinatorCreates courses, campaigns, and role requirements when the Training area is enabled.
ManagerMonitors assigned user completion.
End userCompletes assigned surveys, training, or acknowledgements.

12. Cross-Module Behavior

Related ModuleOverlap
Assets and Third PartiesPrivacy records should link systems, data assets, processors, and transfer parties.
Risk ManagementPrivacy risks can be created from PIA gaps, incidents, or processing weaknesses.
OperationsDSAR delays, privacy gaps, and training overdue items can become issues/actions.
GovernancePrivacy policies and acknowledgements support privacy compliance.
IncidentsPrivacy incidents may require DSAR/context review and risk updates.
ReportsCompletion rates, overdue training, DSAR status, and PIA progress feed reporting.
Related PageWhy It Matters
Third Parties and AssetsProcessing activities, transfers, and privacy impact often depend on vendors, systems, and assets.
Risk ManagementPrivacy issues may create risks or change residual exposure.
GovernancePrivacy policies, notices, exceptions, and approvals provide governance traceability.
OperationsDSAR tasks, incidents, corrective actions, and training follow-up require operational tracking.
Reports and AnalyticsPrivacy records, awareness completion, overdue work, and incidents feed reporting.
Permissions and Roles MatrixUse this before granting access to sensitive privacy records.

14. Before You Start, Reporting Impact, and Common Mistakes

Before using privacy and awareness records, confirm privacy owner roles, data category taxonomy and stewardship, vendor and asset links, lawful basis expectations, DSAR ownership, survey audiences, and whether the optional Training area should be enabled.

Records that change reports and KPIs:

Record or FieldReporting Impact
Processing activity statusDrives privacy inventory completeness.
PIA status and Likelihood × Impact scoreShows privacy assessment workload and unresolved exposure.
DSAR status and due dateDrives request SLA and overdue reporting.
PDPL readiness scoreShows program preparedness by area and check.
Survey status and responsesDrives survey completion and per-question analytics.
Training assignment and completionChanges awareness completion and overdue training KPIs when the Training area is enabled.
Linked vendor, asset, or transferCreates privacy dependency and cross-border reporting context.

Common mistakes:

  • Recording processing activities without owner, purpose, data category, or vendor/asset context.
  • Leaving DSAR due dates unmanaged.
  • Treating survey assignment, or training assignment, as completion.
  • Granting broad privacy access without reviewing role need.
  • Not linking privacy risks or incidents to operational follow-up.
  • Leaving data governance records unsubmitted, so classification and retention are never approved.

Use this module page when training privacy owners on processing records, PIA review, DSAR follow-up, PDPL readiness, data governance, and survey checks. Screenshots and operating guidance should stay with the module rather than a separate screenshot menu.

15. Administrator Checklist

  • Assign privacy records to accountable owners.
  • Link processing activities to assets and third parties.
  • Track DSAR due dates carefully.
  • Use the PDPL readiness dashboard and automation to close gaps and gather evidence.
  • Submit data governance records for review so classification and retention are approved.
  • Create risks or issues for high-impact privacy gaps.
  • Mark required questions on surveys and review per-question analytics.
  • Enable the Training area only if courses are run inside the platform; publish courses only when content is ready.
  • Use role requirements for recurring mandatory training when the Training area is enabled.

16. Screenshot

Training