Assessments that cannot go stale quietly
Because a DPIA is bound to a processing activity, a change to that activity marks the assessment as out of date instead of leaving a signed PDF that describes a system you no longer run.
Impact assessments that sit on real data flows, a vendor register that knows which contract clauses are missing, and incident management that produces a notification decision you can defend. Runs standalone, and shares onboarding data with every other module.
Templates or custom drafts, each linked to the underlying processing activity in Module 3 so an assessment sits on a real data flow rather than on someone's recollection of one. A DPIA is mandatory only for those notified as Significant Data Fiduciaries, not for every business, and we will not tell you otherwise to sell a module.
Records the entities you share personal data with, the purposes they serve, the data categories involved and the contract terms in force. A Data Fiduciary stays answerable for a processor's handling, so the register exists to answer who has this, under what terms, and since when.
Assessment questionnaires produce a score per vendor, and missing DPDP-required contract clauses are flagged against the register rather than discovered during diligence. Reassessment triggers on schedule, or on a change of scope. A vendor that starts receiving a new data category is a new assessment rather than an amendment.
Breaches are logged from first report with a running clock, an owner, and the systems and data categories involved drawn from the map. Reconstructing a timeline weeks later from inboxes is how organisations discover that their record of an incident is worse than the incident.
Assesses impact and determines whether the Data Protection Board and the affected Data Principals must be notified. Penalties of up to ₹200 crore attach to failing to notify, so the decision (including a decision not to notify) is recorded with the reasoning and the facts it rested on at the time.
Remediation actions are tracked to completion and the incident closes with what was done, by whom, and what changed as a result. An incident that closes without changing a safeguard is an incident you have agreed to have again.
Scope comes from the map and the vendor register rather than from a round of emails, which is what makes it possible to answer how many people and which vendors on the day it happens instead of the week after.
A decision not to notify is recorded as carefully as a decision to notify. That is the one people regret leaving undocumented.
Because a DPIA is bound to a processing activity, a change to that activity marks the assessment as out of date instead of leaving a signed PDF that describes a system you no longer run.
The register knows which clauses a processor agreement is required to carry, and shows which of yours do not. Most organisations find this out during an incident, when the contract is the first thing anyone reads.
If you are notified as an SDF, additional duties attach: a Data Protection Officer, independent audits, and DPIAs. The module tracks them as obligations with owners and dates rather than as a page in a policy.