Sign in →

Privacy Operations

The operator GDPR workspace — handle Data Subject Requests (Article 12, 30-day SLA) and manage personal-data Breach Incidents (Articles 33 & 34, 72-hour SLA) from two SLA-driven queues.

Updated 2026-07-29Suggest edits

Privacy Operations

Privacy Operations (Governance → Privacy Operations) is where operators run the two time-critical GDPR workflows. It has two tabs, each with its own SLA clock: a 30-day window for Subject Requests (Article 12) and a 72-hour window for Breach Incidents (Article 33).

Subject Requests (Articles 12–22)

Handle Data Subject Requests submitted from the storefront, email, or API.

Request typeArticle
ACCESS15
RECTIFICATION16
ERASURE17
RESTRICTION18
PORTABILITY20
OBJECTION21

Requests move through PENDING → IN_PROGRESS → COMPLETED (or REJECTED). The 30-day Article 12 window is tracked from the request date: the queue shows each request's SLA due time and flags any request past its window as overdue, and an operator marks it EXPIRED when closing out a request that lapsed. The detail drawer captures assignment, notes, and an audit-preserved rejection reason. Rejecting requires a reason.

Breach Incidents (Articles 33 & 34)

File and manage personal-data breaches against the Article 33 72-hour authority-notification deadline.

SeverityStatus lifecycle
LOW · MEDIUM · HIGH · CRITICALPENDING_TRIAGE → INVESTIGATING → CONTAINED → RESOLVED (or FALSE_POSITIVE)

Incidents record source (MANUAL, AUTOMATED, EXTERNAL_REPORT, SUBPROCESSOR), affected data categories and subject counts, root cause, mitigation, and notification timestamps (DPO, authority, subjects). The queue shows a 72-hour countdown and flags overdue incidents. Notify Authority and Notify Subjects stamp the corresponding timestamps for audit.

ℹ

Privacy Operations is the operational GDPR surface — the queues an operator works. It does not cover the conceptual framework (lawful bases, the data-subject rights catalog, or the compliance registers); ask your account team for that reference.