Skip to content
TruPriv
Module 04

Privacy Governance

Impact assessments that sit on real data flows, a vendor register that knows which contract clauses are missing, and incident management that produces a notification decision you can defend. Runs standalone, and shares onboarding data with every other module.

The lifecycle

Six stages, from the assessment to the closed incident.

  1. 01

    DPIA

    Sec 10

    Templates or custom drafts, each linked to the underlying processing activity in Module 3 so an assessment sits on a real data flow rather than on someone's recollection of one. A DPIA is mandatory only for those notified as Significant Data Fiduciaries, not for every business, and we will not tell you otherwise to sell a module.

  2. 02

    Vendor register

    Sec 8(2), Rule 6(1)(f)

    Records the entities you share personal data with, the purposes they serve, the data categories involved and the contract terms in force. A Data Fiduciary stays answerable for a processor's handling, so the register exists to answer who has this, under what terms, and since when.

  3. 03

    Risk scoring

    Sec 8(2)

    Assessment questionnaires produce a score per vendor, and missing DPDP-required contract clauses are flagged against the register rather than discovered during diligence. Reassessment triggers on schedule, or on a change of scope. A vendor that starts receiving a new data category is a new assessment rather than an amendment.

  4. 04

    Incident logging

    Sec 8(5)

    Breaches are logged from first report with a running clock, an owner, and the systems and data categories involved drawn from the map. Reconstructing a timeline weeks later from inboxes is how organisations discover that their record of an incident is worse than the incident.

  5. 05

    Notification assessment

    Sec 8(6)

    Assesses impact and determines whether the Data Protection Board and the affected Data Principals must be notified. Penalties of up to ₹200 crore attach to failing to notify, so the decision (including a decision not to notify) is recorded with the reasoning and the facts it rested on at the time.

  6. 06

    Closure and review

    Sec 8(5)

    Remediation actions are tracked to completion and the incident closes with what was done, by whom, and what changed as a result. An incident that closes without changing a safeguard is an incident you have agreed to have again.

The incident record

The document you will be asked for, assembled while it is still true.

Scope comes from the map and the vendor register rather than from a round of emails, which is what makes it possible to answer how many people and which vendors on the day it happens instead of the week after.

A decision not to notify is recorded as carefully as a decision to notify. That is the one people regret leaving undocumented.

incident_id
the breach, from first report to closure
detected_at
when it was found, and by whom
data_categories
what was involved, from the classification
principals_affected
scope, drawn from the mapped flows
vendors_involved
processors implicated, from the register
notification_decision
notify or not, with the reasoning recorded
notified_at
Board and Data Principals, separately timestamped
remediation
actions taken, owners, and completion state
Also inside Module 4

Governance is the part that has to survive staff turnover.

Sec 10

Assessments that cannot go stale quietly

Because a DPIA is bound to a processing activity, a change to that activity marks the assessment as out of date instead of leaving a signed PDF that describes a system you no longer run.

Sec 8(2)

Contract clauses, checked not assumed

The register knows which clauses a processor agreement is required to carry, and shows which of yours do not. Most organisations find this out during an incident, when the contract is the first thing anyone reads.

Sec 10

Significant Data Fiduciary obligations

If you are notified as an SDF, additional duties attach: a Data Protection Officer, independent audits, and DPIAs. The module tracks them as obligations with owners and dates rather than as a page in a policy.