TrustPoint

Privacy

Oman PDPL and GDPR operations, not a policy document.

What it does

Privacy programmes in the region are usually a RoPA spreadsheet, a DPIA template and a mailbox for data subject requests. That works until the first request with a statutory deadline attached.

This module runs records of processing, impact assessments, subject requests and breach notification as connected operations on the same asset and process records the rest of the platform uses.

The data model is built for Oman's PDPL rather than a GDPR model with the labels changed, which matters when a regulator asks about lawful basis in local terms.

RoPA

Records of processing activities, linked to the assets, processes, data categories and vendors already held in the platform.

A RoPA that references real asset records stays true when a system is decommissioned. A spreadsheet does not.

ROP-0044

DPIA

Data protection impact assessments with an integrated view of the risks they raise.

A DPIA that raises a risk which never reaches the risk register has not achieved anything. Here it lands in the same register as everything else.

DSAR

Data subject access request intake and case handling against the statutory deadline for each request.

Subject requests arrive unpredictably and expire on a fixed clock. Case handling with the deadline visible is the difference between compliant and late.

Privacy breach

A breach register with the notification clock running and regulator reporting handled on the record.

The privacy breach and the security incident are usually the same event. Linking them means the DPO and the SOC are looking at one timeline.

Data subjects and categories

The reference data that makes a RoPA meaningful: who the subjects are and which categories of data are held about them.

Without a controlled category list, two teams describe the same data three ways and no report reconciles.

Roles that live here

  • Data Protection Officer
  • Privacy Analyst
  • Legal Counsel
  • Process Owner

Drawn from sixteen built-in roles, each scoped along the org tree. Access control

Related frameworks

See Privacy on your processing records.

A 45-minute working session focused on the frameworks and requirements that matter to your organization.