Privacy Operations
The operator GDPR workspace — handle Data Subject Requests (Article 12, 30-day SLA) and manage personal-data Breach Incidents (Articles 33 & 34, 72-hour SLA) from two SLA-driven queues.
Privacy Operations
Privacy Operations (Governance → Privacy Operations) is where operators run the two time-critical GDPR workflows. It has two tabs, each with its own SLA clock: a 30-day window for Subject Requests (Article 12) and a 72-hour window for Breach Incidents (Article 33).
Subject Requests (Articles 12–22)
Handle Data Subject Requests submitted from the storefront, email, or API.
Requests move through PENDING → IN_PROGRESS → COMPLETED (or REJECTED). The 30-day Article 12 window is tracked from the request date: the queue shows each request's SLA due time and flags any request past its window as overdue, and an operator marks it EXPIRED when closing out a request that lapsed. The detail drawer captures assignment, notes, and an audit-preserved rejection reason. Rejecting requires a reason.
Breach Incidents (Articles 33 & 34)
File and manage personal-data breaches against the Article 33 72-hour authority-notification deadline.
Incidents record source (MANUAL, AUTOMATED, EXTERNAL_REPORT, SUBPROCESSOR), affected data categories and subject counts, root cause, mitigation, and notification timestamps (DPO, authority, subjects). The queue shows a 72-hour countdown and flags overdue incidents. Notify Authority and Notify Subjects stamp the corresponding timestamps for audit.
Privacy Operations is the operational GDPR surface — the queues an operator works. It does not cover the conceptual framework (lawful bases, the data-subject rights catalog, or the compliance registers); ask your account team for that reference.