Privacy
Oman PDPL and GDPR operations, not a policy document.
Works with
What it does
Privacy programmes in the region are usually a RoPA spreadsheet, a DPIA template and a mailbox for data subject requests. That works until the first request with a statutory deadline attached.
This module runs records of processing, impact assessments, subject requests and breach notification as connected operations on the same asset and process records the rest of the platform uses.
The data model is built for Oman's PDPL rather than a GDPR model with the labels changed, which matters when a regulator asks about lawful basis in local terms.
RoPA
Records of processing activities, linked to the assets, processes, data categories and vendors already held in the platform.
A RoPA that references real asset records stays true when a system is decommissioned. A spreadsheet does not.
ROP-0044
DPIA
Data protection impact assessments with an integrated view of the risks they raise.
A DPIA that raises a risk which never reaches the risk register has not achieved anything. Here it lands in the same register as everything else.
DSAR
Data subject access request intake and case handling against the statutory deadline for each request.
Subject requests arrive unpredictably and expire on a fixed clock. Case handling with the deadline visible is the difference between compliant and late.
Privacy breach
A breach register with the notification clock running and regulator reporting handled on the record.
The privacy breach and the security incident are usually the same event. Linking them means the DPO and the SOC are looking at one timeline.
Data subjects and categories
The reference data that makes a RoPA meaningful: who the subjects are and which categories of data are held about them.
Without a controlled category list, two teams describe the same data three ways and no report reconciles.
Roles that live here
- Data Protection Officer
- Privacy Analyst
- Legal Counsel
- Process Owner
Drawn from sixteen built-in roles, each scoped along the org tree. Access control
Related frameworks
See Privacy on your processing records.
A 45-minute working session focused on the frameworks and requirements that matter to your organization.