- AI Service Data Policy & Quality Management Cycle — AI Governance; with Privacy · 5 steps
Review AI service input and output data policies, collect required customer acknowledgments, assess quality management and obligations, and track corrective actions with a retained cycle record.
- Data Governance Council Operations — Business Operations; with Privacy, IT · 6 steps
Run quarterly data governance and required integrity-board oversight: review charter standing, lifecycle policy, quality and integrity trends and sharing agreements, then approve minutes and report owned actions at the defined interval.
- Data Retention & Secure Disposal — IT; with Privacy · 4 steps
Enforce retention schedules each cycle: identify expired data, dispose of it verifiably, and protect and sanitize physical media with certificates of destruction.
- DPIA / Privacy Impact Assessment — Privacy · 7 steps
Screen a processing activity and, where required, run the full DPIA: necessity, privacy risks, mitigations, residual-risk decision, and sign-off.
- DSAR Fulfillment (Access & Deletion Requests) — Privacy · 6 steps
Fulfill a data-subject access or deletion request inside the statutory deadline: verify identity, locate data, apply exemptions, review, and deliver.
- Personal Data Quality & De-identification — Privacy · 7 steps
Run the recurring PII data-hygiene cycle: check personal data for accuracy, relevance, timeliness, and completeness, correct or delete failing records and notify recipients, execute individual correction requests, and de-identify data where full identifiers are not required.
- Privacy Breach Assessment & Notification — Privacy; with IT · 9 steps
Assess a personal-data breach handed off from incident response: scope the exposure, decide notifiability against GDPR, US state, and HIPAA clocks, notify regulators and affected individuals on time, and close with a defensible breach-register entry.
- Privacy Program Operations (Consent, Complaints & Sharing) — Privacy · 6 steps
Run the standing Privacy Program Operations process on a recurring cycle: reconcile consent and preferences against processing activities, resolve privacy complaints with an accounting of disclosures, and govern data-sharing agreements against actual flows — logging every exception, complaint, and agreement gap as a tracked Issue.
- Privacy Safeguards & Notice Management — Privacy · 7 steps
Run the privacy office's periodic program cycle against the standing Privacy Program process: refresh the inventory of statutory, regulatory, and contractual privacy requirements, confirm PII-protection accountability, verify that administrative, technical, and physical safeguards remain appropriate to the data held, remediate gaps, and keep external privacy notices and required registrations accurate to actual processing and delivered at the point of collection.
- Security & Privacy Architecture Review Board — IT; with Privacy · 9 steps
Operate the standing Security & Privacy Architecture Review Board: maintain the enterprise, security, and privacy architecture views that describe how systems, information flows, and protections align with mission and strategy, review solution designs and acquisition decisions for architectural alignment, and push approved updates into system security plans and acquisition requirements.
- Vendor Due Diligence & Contracting Gate — Procurement; with Privacy · 9 steps
For each new vendor engagement or contract renewal, this pre-contract gate runs on the vendor's register entry (the Vendor item — created for a net-new vendor, enriched for a renewal): tier the vendor by criticality, run proportionate due diligence across security posture, financial and operational risk, and supply-chain exposure, and document the acceptance decision before binding the contract to required security, privacy, and applicable regulatory clauses. It has no upstream workflow — the engagement trigger is its own entry point. Named deliverables: the vendor due-diligence report, the documented risk-acceptance decision, the executed contract bound to its security/privacy/regulatory clauses, and — where personal data is involved — the signed written privacy commitments obtained before access begins. On close it enrolls the Vendor in ongoing monitoring and hands the archived gate record to the third-party risk monitoring / vendor oversight lifecycle.