The platform
Seven duties. One record.
The Act does not ask for seven products. It asks a Data Fiduciary to know what it processes, why, on whose consent, for how long, and who else touches it — and to be able to show the answer. These are the parts of that answer.
- Modules
- 7
- M1–M7
- Record they share
- 1
- Sec. 8(1)
- Scheduled languages
- 22
- Eighth Schedule
- Cross-border by default
- 0
- Sec. 16 · Rule 15
How the modules meet
A processing activity
Everything in the platform hangs off one row. These define it:
- RoPAone row per activity
- DPIAassesses the row
And these act on it:
- Consent Managerattaches to its purposes
- Cookie Consentthe browser surface
- Rights & Grievanceanswers against it
- Breach Notificationreports on it
- Vendor Riskwho else touches it
Suites fail at the join
Most compliance tooling is a set of registers that do not know about each other. The consent tool holds purposes. The spreadsheet holds processing activities. Nothing connects a withdrawal to the activity it should stop, so the connecting is done by a person, once a quarter, from memory.
Sec. 8(1) makes the Data Fiduciary answerable for processing carried out on its behalf, irrespective of any agreement to the contrary. That is a duty you discharge with a join, not with a folder. Every module here writes to the same activity row, so a withdrawal, an erasure request and a breach report all resolve to the same place.
3 modules are available today. The rest say early access or roadmap on their own tile, because a platform page that reads as finished when it is not is the same failure in a different register.
The seven
Each with its provisionBreach Notification
Intimation to every affected principal, and the Board report, on a 72-hour clock.
Vendor Risk
Every processor you engage, the contract that permits it, and what it may process.
Next step
Start from the register
Most teams arrive wanting a consent banner and leave having discovered they cannot say what they process. The register is the cheapest place to find that out.