Privacy Governance

Manage personal data, data subject access requests, data subject requests, consent and data retention with defensible, audit-ready records — in line with the GDPR and ISO 27701.

Standards & legislation covered

Shared controls: a retention or access control complies with the GDPR, ISO 27701 and ISO 27001 — all at once.

What’s included

A privacy check. All frameworks that require it.

Everything a privacy programme needs — records, assessments, requests and evidence — all within the same platform as the rest of your governance.

Records of processing (ROPA)

Keep records relating to Article 30 in connection with systems, data and suppliers.

DPIA & risk

Run and version control impact assessments on data protection with approval.

DSAR workflows

Receipt, verification of identity and a response within the statutory time limits.

Consent governance

Record, specify and highlight the grounds for lawfulness and consent.

Retention & deletion

Retention periods, legal holds and disposal workflows.

Privacy incidents & breach

Assessment and notification of breaches within 72 hours.

Vendor privacy assessments

DPA, data transfer mechanisms and due diligence on subcontractors.

International transfers

SCC, transfer impact assessments and transfer mapping.

Designed for multi-framework use

One privacy control. For all frameworks that needs it.

Keep your processing records in one place and iComply will highlight them in all the regulations and laws that refer to them — without any duplication of effort.

Implementation

From scope to continuous assurance.
01

Scope & diagnosis
Define the scope and carry out a GAP analysis against the selected standards.

02

Map controls
Select controls; iComply automatically maps them to each relevant framework.

03

Collect evidence
Assign tasks, upload evidence once and reuse it across all requirements.

04

Audit & monitor
Carry out audits, track CAPA and monitor compliance on an ongoing basis.

Bring privacy governance onto a single platform.