Process management
Describe purposes, data subjects, data categories, systems, companies and transfers as parts of the same processing activity.
A process model used by connected registers, assessments and documents.
CAPABILITIES
Maintain a connected account of processing activities, participants and requirements. Collect changes through forms, revisit risks and measures, and update records and documents as part of ongoing work across teams and organisations.
Describe what happens to personal data, who takes part and where the information is used.
Describe purposes, data subjects, data categories, systems, companies and transfers as parts of the same processing activity.
A process model used by connected registers, assessments and documents.
Create and update records in forms and nested tables. Reuse related entries and constrain selections to the relevant context.
Connected records instead of repeated manual descriptions.
Link retention periods or criteria to data and activities. Revisit them when purposes, requirements or internal standards change.
A connected description of retention rules for specialist review.
Maintain recipients and transfers between departments, companies and third parties. Update the related records when a supplier, relationship or transfer arrangement changes.
Transfer information kept in its processing context.
Keep risks and measures linked to current facts; review them again when the process or its requirements change.
Configured scenarios create or update risks from process facts. Select applicable measures, then review them again when the process, requirements or relationships change.
Connected risks and measures that can be reviewed as work changes.
Work through the questions and checks of the configured legal context. Record missing information and nonconformities alongside the processing description.
A factual basis for deciding what needs further work.
Participants supply the facts; prepared forms and configured rules support the repeated steps.
Collect structured answers through configurable forms, required fields, reference values and event-driven scenarios.
Information prepared for use across the project.
Work with structured fields and linked choices. Configured rules fill values, check entries and update related records; an administrator manages the configuration.
Less repeated entry and connected, consistent records.
Use shared reference materials in forms and rules. When requirements or internal standards change, specialists review the content and an administrator updates the relevant configuration.
Expert material available in the context where it is needed.
Keep participants, records and documents aligned as processes and requirements evolve. Documents reflect the work; maintaining that work continues.
Review process changes with the relevant departments and companies. Update the facts, revisit risks and measures, and have an administrator adapt forms and rules when requirements change.
A working context that can evolve with the business.
Generate documents from reviewed project information. When a process or requirement changes, review the affected data and templates and generate an updated version.
Documents that reflect reviewed process information and can be regenerated after changes.
Review section completion and items needing attention. Use project roles, comments and an audit trail to organise collaboration.
Visibility into missing information and changes.
Work with several projects and participants. The configured legal context determines the available forms, menu and assessment structure.
A repeatable approach with project-specific context.
Bring departments, company representatives and client participants into the project with appropriate roles. Use comments to clarify changes in responsibilities, data sharing and working arrangements.
Clarifications remain in the working context of the project.
Forms, registers, reference materials and rules are configured for the project’s processes and legal context, including GDPR work. Localised forms and interface elements support multilingual work.
When a team changes a purpose, system, participant or data flow, it updates the process facts. Configured rules use those facts to create or update linked records. The specialist reviews the risk and selected measures, and the team updates the affected registers and documents. For example, a new shared HR service calls for a review of participating companies, access and transfers.
Configured rules populate values, check entries and create or update related records. Participants supply and clarify the facts; specialists assess requirements and consequences and select suitable measures. Administrators maintain the forms, reference content and rules that support this work.
Project records connect processes with the companies, departments, systems and recipients involved. Participants contribute through project roles and comments. When a provider or shared service changes, the affected teams review their part of the process and update the relevant records within their access rights.
An in-house DPO works with process owners and departments to keep the organisation’s information, risks and measures current. External DPOs and consultants use separate client projects for an assignment or ongoing support. Both use structured forms, connected records, comments and action history to maintain the working context.
The management cycle continues. Teams collect changes in business, requirements, internal standards and third-party relationships, then review their impact on the process. They revisit risks and measures, update connected records and generate revised documents from reviewed information. Documents remain part of ongoing process management.