Privacy & Data Protection
Multi-jurisdiction privacy compliance, from gap assessment through to audit-ready documentation.
◈
Assessment
Regulatory TraceabilityAnswer structured questions across the assessment areas your organisational context activates. Maturity is indicated by Priventia from your responses, never self-declared, and stated in bounded language rather than as a score.
GDPR Art. 24 · POPIA s.19
Key capabilities
◆Structured questions across activated assessment areas
◆Bounded maturity indications per area
◆Cross-jurisdiction delta analysis
◆Generates roadmap actions automatically
◉
Compliance Roadmap
Prioritised RemediationRemediation actions drawn from the obligations indicated for your organisation, each citing the obligation it addresses. The Compliance Intelligence Report carries the roadmap today; the workspace roadmap is being rebuilt from Gap Assessment findings.
GDPR Art. 24 · Accountability principle
Key capabilities
◆Drawn from indicated obligations
◆Each action cites its source obligation
◆Delivered in the Compliance Intelligence Report
⬡
Impact Assessments
DPIA · LIA · TIA · PIADPIA, LIA, TIA, and PIA with structured question frameworks and risk-scored outcomes. Residual risk is assessed using likelihood and severity matrices, never declared by the user. DPO sign-off workflow built in.
GDPR Art. 35–36 · GDPR Art. 6(1)(f)
Key capabilities
◆DPIA, LIA, TIA, PIA workflows
◆Likelihood × severity risk matrices
◆Residual risk assessment
◆DPO sign-off and attestation
◎
Records of Processing (RoPA)
GDPR Art. 30Full RoPA lifecycle with Article 30 compliant record structure, DPIA screening triggers, transfer impact assessment flags, and jurisdiction-specific fields for POPIA and Kenya DPA requirements.
GDPR Art. 30 · POPIA s.18
Key capabilities
◆GDPR Art. 30 compliant structure
◆DPIA trigger screening
◆Cross-border transfer flags
◆Multi-jurisdiction field support
▣
Data Subject Rights (DSR)
Intake to responseReceive, verify and respond to data subject requests through a managed lifecycle: public intake with configurable settings, identity verification, jurisdiction-specific deadline rules, and documented responses. Reporting shows request volumes, timeliness and outcomes across all active jurisdictions.
GDPR Art. 12–23 · CCPA/CPRA · POPIA
Key capabilities
◆Public intake channel with configurable settings
◆Jurisdiction-specific deadline and extension rules
◆Case lifecycle with verification and response records
◆Volume and timeliness reporting
◐
Monitoring & Audit
ContinuousSchedule monitoring activities against specific controls. Log findings. Track remediation. Evidence accumulates automatically into your compliance record, building an auditable chain from obligation to corrective action.
GDPR Art. 24 · POPIA s.19 · ISO 27001
Key capabilities
◆Scheduled control monitoring
◆Findings and remediation log
◆Automated evidence accumulation
◆Frequency escalation rules
▦
Dashboard & Reporting
Live analyticsA current view of obligations, controls, evidence and open findings across all active jurisdictions, with maturity indications over time, open roadmap items and overdue monitoring activities.
Accountability · Art. 5(2) GDPR
Key capabilities
◆Cross-jurisdiction posture view
◆Maturity trajectory charts
◆Enforcement exposure quantification
◆Board-ready export formats
▲
Regulatory Impact Capability
Intelligence layerThe platform’s regulatory ontology functions as a queryable knowledge graph. The Regulatory Impact Capability surfaces six analytical scenarios: regulatory alerts with due-date tracking, enforcement cascade analysis tracing how a single ruling ripples through obligations and controls, control reuse intelligence showing which controls satisfy multiple regulations simultaneously, jurisdiction impact queries showing the full regulatory burden of entering a new market, and an instruments overview across all supported regimes.
Cross-regime · GDPR · POPIA · EU AI Act · CSDDD
Key capabilities
◆Enforcement cascade analysis (e.g. Schrems II impact trace)
◆Control reuse: one control → multiple legal obligations
◆Jurisdiction impact: “What breaks if we enter Germany?”
◆Regulatory alerts with OVERDUE / DUE SOON indicators
◆Cross-regulation instruments overview
◆Enforcement action tracking with severity and fine data
One-click export of your complete compliance record with full regulatory traceability. Every control links to a legal obligation. Every obligation links to a source law. Every conclusion is supported by evidence. Structured for supervisory authority review.
GDPR Art. 5(2) · Accountability principle
Key capabilities
◆Full evidence chain export
◆Regulatory traceability index
◆DPO-review-ready documentation
◆Regulator-formatted structure
Structured AI governance through inventory, risk classification, conformity assessment readiness, and lifecycle monitoring.
⬡
AI Governance
EU AI Act · ISO 42001 · NIST AI RMFStructured AI governance through inventory, risk classification, conformity assessment readiness, and ongoing monitoring aligned with global AI governance frameworks. Register all AI systems, classify by risk tier (prohibited, high-risk, limited, minimal), apply governance controls per tier, prepare high-risk systems for conformity assessment (self-assessment or notified body) and track its completion and certificate expiry, and monitor throughout the AI lifecycle.
EU AI Act Art. 5, 9, 13, 26 · NIST AI RMF · ISO/IEC 42001
Key capabilities
◆AI systems inventory with ownership and deployment context
◆Risk classification wizard (EU AI Act risk tiers)
◆Conformity assessment readiness and tracking for high-risk systems (Art. 8–15, 43)
◆Multi-framework controls: NIST AI RMF, ISO 42001, OECD AI Principles
End-to-end supply chain due diligence following the full compliance lifecycle. Typically governed by Compliance, ESG, and Procurement leads.
⬢
Supplier Intake & Registry
Organisation ContextCreate and maintain a centralised supplier registry. Capture supplier name, country, industry, supplier tier, and products supplied. The registry forms the foundation for risk-based due diligence across your supply chain, traced to obligations under CSDDD, LkSG, UK MSA, and UNGPs.
CSDDD Art. 5–11 · LkSG §§3–6 · UK MSA §54 · UNGP Pillar II · Norway Transparency Act §4–5
Key capabilities
◆Centralised supplier inventory
◆Capture: name, country, industry, tier, products supplied
◆Revenue-band activation trigger (CSDDD EUR 450M+)
◆Obligation mapping to CSDDD, LkSG, UK MSA, UNGPs, Norway Transparency Act
◉
Risk Classification
ApplicabilityPriventia assesses supplier risk based on geography, sector, commodity, and labour risk indicators. Each supplier is assigned a risk tier (Low, Medium, High) that determines the intensity of due diligence required. Risk classification drives the controls applied downstream.
CSDDD Art. 7–8 · LkSG §5 · OECD Due Diligence Guidance Step 2
Key capabilities
◆Risk assessment by geography, sector, and commodity
◆Labour risk indicator assessment
◆Supplier risk tier output: Low, Medium, High
◆Risk tier determines due diligence intensity
◎
Human Rights Risk Assessment
ObligationsStructured risk assessment covering forced labour, child labour, environmental harm, indigenous land rights, and worker safety. Each supplier receives a risk profile based on assessment outcomes. Assessment questions map to specific obligations under CSDDD, LkSG, and UNGPs.
CSDDD Art. 8 · LkSG §5 · UNGP Principle 17–18 · OECD Step 3
Key capabilities
◆Structured assessment: forced labour, child labour, environmental harm
◆Indigenous land rights and worker safety coverage
◆Risk profile generated per supplier
◆Mapped to CSDDD Art. 8, LkSG §5, UNGP Principle 17–18
◈
Control Implementation
ControlsImplement operational controls traced to legal obligations: supplier code of conduct, contractual due diligence clauses, audit rights, and corrective action procedures. Each control is linked to the specific obligation it addresses and the regulation that imposes it.
CSDDD Art. 10–11 · LkSG §6–7 · UNGP Principle 15–17 · OECD Step 3–4
Key capabilities
◆Supplier code of conduct
◆Contractual due diligence clauses with audit rights
◆Corrective action procedures
◆Control register linked to source obligations
Schedule and track monitoring activities: supplier audits, compliance questionnaires, and site inspections. Findings are logged, categorised by severity, and linked to the controls and obligations they relate to. Frequency escalation rules apply to high-risk suppliers.
CSDDD Art. 11 · LkSG §7 · UNGP Principle 20 · OECD Step 4
Key capabilities
◆Scheduled supplier audits and site inspections
◆Compliance questionnaires for ongoing monitoring
◆Findings log with severity categorisation
◆Frequency escalation for high-risk suppliers
▦
Grievance Mechanism
Complaint → Investigation → Remediation → MonitoringTrack the full grievance lifecycle: complaint submitted, case opened, investigation, remediation plan, closure. Accessible to workers, NGOs, unions, and community members. Required by CSDDD (complaint procedure for affected stakeholders), UNGPs (operational grievance mechanisms), LkSG (complaint procedure), and OECD guidelines (remediation process).
CSDDD Art. 9 · LkSG §8 · UNGP Principle 29–31 · OECD Due Diligence Guidance
Key capabilities
◆Complaint intake from workers, NGOs, unions, community members
◆Full lifecycle: complaint → investigation → remediation → closure
◆Case file with evidence documentation
◆Accessible to affected stakeholders across the supply chain
◒
Remediation Tracking
Prioritised RemediationWhere adverse impacts are identified through monitoring or grievance mechanisms, remediation measures are documented and tracked: supplier corrective action plans, termination of relationship, or compensation and remedy. Supplier disengagement as a last resort follows responsible exit procedures.
CSDDD Art. 12 · LkSG §7 · UNGP Principle 22, 31 · OECD Step 5–6
Key capabilities
◆Supplier corrective action plan tracking
◆Compensation and remedy documentation
◆Responsible supplier disengagement procedures
◆Remediation register with outcome evidence
Export your complete CDG compliance record with full regulatory traceability. Includes: supplier risk register, due diligence process, monitoring records, grievances received, remediation actions, and evidence. Annual due diligence reports and modern slavery statements generated from platform evidence. Structured for supervisory authority review.
CSDDD Art. 11 · LkSG §10 · UK MSA §54 · Norway Transparency Act §5 · OECD Step 5
Key capabilities
◆Supplier risk register and due diligence process export
◆Monitoring records and grievance case files
◆Remediation actions and evidence documentation
◆Regulator-formatted structure for CSDDD, LkSG, UK MSA, Norway Transparency Act
Cybersecurity & Operational Resilience
Priventia governs and evidences compliance with cybersecurity and operational resilience obligations under NIS2, DORA, and CER, using ISO 27001 controls to meet regulatory requirements. The platform tracks controls, evidence, and regulatory reporting obligations across critical systems.
◈
Cybersecurity Governance & Risk Oversight
NIS2 Art. 21 · DORA Art. 5–16Govern cybersecurity risk management through structured control frameworks, regulatory obligation mapping, and continuous assurance monitoring aligned to NIS2 and DORA. Track board-level accountability, control implementation status, and evidence of risk treatment across all critical systems.
NIS2 Art. 20–21 · DORA Art. 5–16 · ISO/IEC 27001 Clause 6
Key capabilities
◆Obligation mapping to NIS2 Art. 21 minimum measures
◆ICT risk governance framework (DORA Art. 5–16)
◆Board accountability and management body approval tracking (NIS2 Art. 20)
◆Cross-walk to ISO/IEC 27001 and NIST CSF 2.0 controls
◎
Incident Reporting Governance
NIS2 Art. 23 · DORA Art. 17–23Track and evidence incident reporting obligations under NIS2 and DORA, including regulatory notification timelines, incident classification documentation, and supervisory authority reporting records. Governs the multi-stage reporting lifecycle from early warning through final report submission.
NIS2 Art. 23 · DORA Art. 17–23 · CER Art. 14
Key capabilities
◆Regulatory notification timeline tracking (NIS2 24h/72h/1-month)
◆DORA ICT incident classification and severity documentation
◆Authority notification register and acknowledgement tracking
◆Evidence chain for incident reporting compliance
◐
Resilience Testing Oversight
DORA Art. 24–27 · NIS2 Art. 21(2)Govern and evidence operational resilience testing obligations under DORA, including TLPT programme requirements. Track test schedules, findings, remediation actions, and evidence of testing completion for supervisory review.
DORA Art. 24–27 · NIS2 Art. 21(2)(e)
Key capabilities
◆TLPT programme governance and documentation (DORA Art. 26)
◆Testing register: track vulnerability assessment and penetration test schedules and findings
◆Findings and remediation tracking with evidence linkage
◆Resilience validation evidence for supervisory review
⬢
ICT Third-Party Oversight
DORA Art. 28–44 · NIS2 Art. 21(2)(d)Maintain an ICT third-party oversight register aligned to DORA and NIS2 supply-chain obligations, including contractual clause tracking, concentration risk visibility, and monitoring evidence. Governs the compliance lifecycle for critical ICT service providers.
DORA Art. 28–44 · NIS2 Art. 21(2)(d) · ISO/IEC 27001 A.5.19–23
Key capabilities
◆ICT third-party service provider oversight register
◆Contractual clause compliance tracking (DORA Art. 30)
◆Concentration risk assessment and exit strategy documentation
◆Supply chain security obligation mapping (NIS2 Art. 21(2)(d))
▦
Business Continuity Governance
NIS2 Art. 21(2)(c) · CER Art. 13Evidence compliance with resilience and recovery obligations under NIS2, DORA, and CER through structured documentation, testing records, and monitoring of continuity controls. Tracks business continuity plans, disaster recovery procedures, and crisis communication evidence.
NIS2 Art. 21(2)(c) · CER Art. 12–13 · DORA Art. 11–12
Key capabilities
◆Business continuity and disaster recovery plan tracking
◆Crisis management and communication plan documentation
◆Recovery testing records and evidence management
◆Integrated cyber-physical resilience governance (NIS2 + CER)
Platform governance under the EU Digital Services Act, the UK Online Safety Act, NetzDG, and COPPA. Its assessment areas activate for platform, marketplace, and user-generated-content sectors, covering the full moderation, transparency, and accountability lifecycle.
◈
Content Moderation & Notice Handling
DSA Art. 16 · Notice and actionGovernance of content moderation policies, illegal-content notice mechanisms, and user complaint handling. Moderation decisions are logged with traceable reasoning, notices are triaged within defined timeframes, and complaint outcomes are recorded for audit.
EU DSA Art. 16, 20 · UK OSA 2023 · NetzDG
Key capabilities
◆Documented moderation policies aligned to terms of service
◆Illegal-content reporting mechanism with triage timeframes
◆Complaint handling with recorded outcomes
◆Moderation decision log with traceable reasoning
◈
Transparency & Authority Cooperation
DSA Art. 15 · ReportingTransparency reporting on moderation activity, cooperation with supervisory authorities, and researcher data access governance. Reporting evidence accumulates on the platform so the annual obligations are compiled from records, not reconstructed.
EU DSA Art. 15, 22, 40 · UK OSA 2023
Key capabilities
◆Transparency report evidence compilation
◆Authority cooperation and order-response records
◆Researcher access request governance
◆Trusted flagger programme documentation
◈
Marketplace & Interface Integrity
DSA Art. 25, 30Trader traceability for marketplaces and protection against manipulative interface design. Covers know-your-business-customer verification, and the design review that keeps choice architecture free of dark patterns.
EU DSA Art. 25, 30 · COPPA 16 CFR 312
Key capabilities
◆Trader traceability (know-your-business-customer)
◆Interface design review against manipulative patterns
◆Marketplace compliance information duties
◆Child-directed service assessment (COPPA)
◈
Algorithmic & Platform Risk
DSA Art. 27, 34–35Recommender system transparency and, for very large platforms, systemic risk assessment and mitigation governance. Algorithm transparency obligations are evidenced alongside the risk assessments that supervisory review expects.
EU DSA Art. 27, 34–35
Key capabilities
◆Recommender system transparency documentation
◆Systemic risk assessment governance (VLOP scope)
◆Risk mitigation measure tracking
◆Assessment evidence for supervisory review
Cross-Module Capabilities
Capabilities that span every governance domain and keep the compliance record one record.
◆
Unified Risk Register
Cross-domainRisks surfaced anywhere on the platform converge into one register: gap assessments, impact assessments, monitoring findings and supplier due diligence all feed it. Each risk links to the controls that treat it and the monitoring that watches it, with likelihood and severity ratings and tracked actions.
GDPR Art. 24 · NIS2 Art. 21 · Accountability principle
Key capabilities
◆One register across all governance domains
◆Likelihood and severity ratings
◆Links to treating controls and monitoring
◆Action tracking with ownership
The assessment adapts to your declared profile. Your sector determines which questions you answer, never what the law says: domain groups activate when your profile indicates the underlying regime governs organisations like yours.
◆Payment card data sectors activate the PCI DSS v4.0 assessment domains.
◆NIS2 essential and important entity sectors activate the Cybersecurity & Operational Resilience assessment domains.
◆Platform, marketplace and user-generated-content sectors activate the Trust & Safety assessment domains (EU DSA, UK Online Safety Act, NetzDG, COPPA).
◆A declared revenue band above the CSDDD threshold activates the Corporate Due Diligence domain group.
Domain groups outside your profile stay dormant rather than diluting your record with questions that do not govern you.