Risk Management
Managing personal data without proper risk management is putting every organization in a precarious position. The risks we are identifying are not the risks for the organization, rather the risk from the Data Subjects’ point of view

Challenge

Usually, there are three sources of risk:
The first is Third Parties – DPO needs to asses all Data Processors which have access or to which personal data is disclosed. It requires contractual protections with Data Processors and their Sub-Processors. Awareness what is the risk score of our Third Parties and acting to mitigate the risk is essential in avoiding the potential fines.
The second is IT (and non-IT) Systems, where personal data is stored. Organization needs to be aware of which kinds of security measures were undertaken. If it is a Cloud system, the location of the data center can affect the risk score.
The third source of risk is, of course, Data Privacy Impact Assessment (DPIA) which needs to be conducted when there is a systematic and extensive evaluation of the personal aspects of an individual, including profiling; or processing of sensitive data on a large scale; or systematic monitoring of public areas on a large scale. Out of DIPA, many risks can rise and we need to be able to properly manage them.
Solution

The Risk Management module empowers your DPO with a high-level overview of risks associated with each processing activity, and to allow for a more detailed insight into residual risks behind a particular processing activity by means of linking it to a relevant data protection impact assessment.
Before assigning the risk to a processing activity, third party, or a system you will have to (re)define the risk methodology your organization is currently using. It is possible to adjust the risk matrix both by impact and probability. As well as define risk scores.
By having risk methodology in place and assigning risks to the key entities, the solution creates a Risk Register, which acts as a guideline for the management. It shows where the organization is vulnerable and what should be the next key steps in order to provide compliant personal data processing.
DPIA register allows business process owners to download the DPIA template, to do assessments, and upload the results back to Data Privacy Manager.
Benefits
CENTRALIZATION
The Risk Register and DPIA register in one place within the Data Privacy Manager together with other essential GDPR processes
CUSTOM RISK METHODOLOGY
Adjust the risk methodology to the one your organization is already using and keep risk management comprehensive
DPIA REGISTER
Collaborate and create DPIAs, use available templates and upload the results
Personal Data Lifecycle
Collection
Interaction with Data Subjects
- Contract
- Consent
Lawfull Processing
Everyday Business
- Data monetization
- Services delivery
- Marketing
Archiving
Lawful Basis Expiration
- Contract Expiration
- RTBF
- Opt-out
Destruction
Data Destruction
- Anonymization
- Deletion
Business Process
(Original Purposes)
Data Retention
(Purpose change)
No Purpose

Learn how this solution helps your industry
While Organizations have been busy collecting consents and putting together compliant Records of processing activities, the data removal remained overlooked, or maybe postponed? Most of the Organizations have by now documented data retention policies and have a good idea about how long they can keep the data. Data retention starts when one of the following scenarios happen: The initial purpose for data collection and processing has expired. Usually, a product or services contract with an individual has expired, an insurance policy has expired or individual stopped using a product or a service…
Would you like to continue reading?

“We have approached the process of GDPR compliance very seriously and methodically, and we wanted to have a software that will allow us to manage GDPR processes from one central point, which we managed to accomplish with Data Privacy Manager.”
Nikola Murk, Head of IT operations & infrastructure

“Data Privacy Manager automated our compliance process. It took the pressure off the IT department, allowing me as DPO to have complete control over all processing activities from one point.”
Davor Namjestnik, DPO @ Sberbank Hrvatska

“Instead of assigning IT resources to in-house development, we opted for a professional solution. Data Privacy Manager offered flexibility in integration with our other systems. During the project, we realized the solution was designed with such a deep understanding of GDPR and data management which would be very difficult to reach with only internal resources.“
Bojan Brodar, CISO @ Telemach

“Our customers are our top priority! Data Privacy Manager is an investment in that relationship, enabling us to timely respond to their requests and to tailor marketing communications based on their preferences.“
Mario Marković, DPO @ Optima Telekom
Data Privacy Manager is available in flexible pricing options for your growing business needs

Records of Processing Activities
Harbor cooperation between DPO, Legal Services, IT and Marketing, divide their responsibilities and conquer GDPR!
DISCOVER MORE
Data Flow
Establish a business and operational control over complete personal Data Flow within your organization.
DISCOVER MORE
Third Party Management
Centrally manage Third Party and guide your partners trough vendor management process workflow.
DISCOVER MORE
Privacy 360
Clear 360 overview of all data and information regarding the individual data subject.
DISCOVER MORE
Data Inventory
Discover personal data across multiple systems in the cloud or on-premise.
DISCOVER MORE
Data Removal
Introducing end-to end automation of personal data removal.
DISCOVER MORE
Data Subjects Request
Turn data subjects request into an automated workflow with a clear insight into data every step of the way!
DISCOVER MORE
Consent and Preference Management
Consolidate your data and prioritize your relationship with customers by centralizing collected consents and aligning your marketing communication with data privacy regulations
DISCOVER MORE
Privacy Portal
Privacy portal allows customers to communicate their requests and preferences at any time. By giving them the control, you gain their trust!
DISCOVER MORE