Lawful basis and purpose
Why personal data is processed, on what grounds, and whether that reasoning is written down anywhere.
- Stated purpose
- Lawful grounds
- Documented decisions
Privacy obligations overlap heavily with the security controls you already run, and separating them is what causes the same evidence to be collected twice. In Sentinel Unity a privacy requirement is a control in the same library, mapped to the security control that satisfies it.
Saudi Arabia's Personal Data Protection Law, held as an example of a privacy regime. Any equivalent is loaded and mapped the same way.
Every level links out to risks, controls, policies, findings, assessments, and assets
One
Control library, not two
0 to 5
Maturity scored
Graded
Mapping to security controls
Data
Applicability tag
Obligation areas
These are the areas the regime covers. Each becomes a set of controls in the library, assessed and evidenced like any other.
Why personal data is processed, on what grounds, and whether that reasoning is written down anywhere.
What categories are held, where, and for how long, which is usually the first request an authority makes.
Data leaving one jurisdiction for another, and the safeguards that permit it.
Obligations that begin at discovery and run against a clock, involving both an authority and affected individuals.
Access, correction, deletion, and portability, with responses that have to be evidenced later.
Personal data handled on your behalf remains your obligation, which puts it in the vendor register.
Platform mapping
Plainly stated: there is no separate privacy module. These are the platform mechanics a privacy programme runs on.
Loaded into the same library, under their own jurisdiction and authority, and mapped to the security controls that already satisfy them.
Controls tagged Data can be filtered as a set, which is how a privacy view is assembled without a second library.
A privacy notice or handling standard maps to controls by section and bullet, so which policy covers this obligation has a precise answer.
A privacy gap raises the same kind of finding as a security gap, with severity, an owner, and a plan.
Anyone processing personal data for you is assessed and monitored as a third party, with obligations tracked against the contract.
Platform activity is written to an append-only log, which matters most in the one conversation where your record is the only account of what happened.
Maturity
Every privacy control is scored on the platform's six-level scale, each level carrying a written descriptor so a score means the same thing in two different business units.
Level 0
Not Performed
The practice does not happen. Recorded as an explicit level rather than a blank.
Level 1
Performed Informally
It happens, but it depends on individuals and is neither planned nor tracked.
Level 2
Planned & Tracked
Planned, resourced, and monitored, though practice still varies between teams.
Level 3
Well Defined
A defined standard process, applied consistently across the organisation.
Level 4
Quantitatively Controlled
Measured against targets, with deviation detected from the measurements themselves.
Level 5
Continuously Improving
Improvement is fed by the measurements, changing the process rather than the reporting.
Book a walkthrough with our GRC specialists and see the platform run against the frameworks you are held to.
No commitment required. A typical demo runs 45 minutes.