Privacy begins with visibility
Module · Privacy and Data Protection
Privacy teams are asked to prove control over data they cannot see, against deadlines set by regulation rather than by capability.
Prophesee Privacy keeps the record current, turns assessments into minutes, and runs the seventy-two hour clock with the notices already drafted.
Privacy: a day in the life
One working day inside Privacy, from the morning forecast to the evidence that the intervention worked.
You have seventy-two hours to notify. It takes 241 days to find out.
Privacy teams are asked to prove control over data they cannot see, against deadlines set by regulation rather than by capability. The record is maintained by hand, assessments are rationed by specialist time, and the mandate keeps growing.
Sources: DLA Piper GDPR Fines and Data Breach Survey, Jan and Feb 2026 · IBM and Ponemon, Cost of a Data Breach 2025 · CMS GDPR Enforcement Tracker, Mar 2026 · Verizon DBIR 2025 · IAPP and FTI Privacy Governance Report.
Building a living privacy programme
The Article 30 record, the data map and the transfer register are built from questionnaires and workshops, so they are stale the day they are signed off.
The RoPA builds itself from connected systems: purposes, categories, Article 9 flags, lawful basis, retention, recipients and every cross-border flow with its transfer mechanism.
A subject request means finding one person across forty systems where they are spelled five ways, and being certain enough to hand over the data.
Threshold pre-screen against Article 35 triggers, questionnaire that raises risks as they are answered, and a pre-filled DPIA report. FRIA under the EU AI Act bolts onto the same flow.
Sub-processor additions and transfer route changes are discovered at the next review, or in a footnote of a renewal email.
Intake, auto-severity, the Article 33 clock, a notify decision tree by jurisdiction and pre-drafted Article 33 and 34 notices. Separate rules catch risk drift that is not yet a breach.
Subject request volume, breach notifiability and the workload of a market entry are not forecast, so the team is permanently behind the clock.
Model a market entry, a works council negotiation or an EU AI Act milestone and see how many assessments, transfers and approvals it creates before you commit.
Turning privacy obligations into decisions
The Article 30 record, the data map and the transfer register are built from questionnaires and workshops, so they are stale the day they are signed off.
A subject request means finding one person across forty systems where they are spelled five ways, and being certain enough to hand over the data.
Processing activities are mapped to legal basis, special category and Article 35 triggers by a specialist reading, so assessments are rationed to whoever asks.
Sub-processor additions and transfer route changes are discovered at the next review, or in a footnote of a renewal email.
Subject request volume, breach notifiability and the workload of a market entry are not forecast, so the team is permanently behind the clock.
12 AI applications that could be relevant
A sample of what becomes possible on the decision layer, not a fixed list: each application draws on the same data foundation and audit trail, and new ones are configured on the engines, not built from scratch.
The record of processing builds itself from connected systems and stays current.
Architecture docs, DPAs and retention schedules become a drafted assessment.
Finds the subject across every system and assembles the response pack.
Predicts which projects trip an Article 35 trigger and how high the risk lands.
Forecast of subject request volume by type and jurisdiction, weeks ahead.
Scores severity and likely notifiability the moment a breach is reported.
Finds personal data still held beyond the retention schedule that governs it.
The Article 33 clock, the notify decision by jurisdiction, notices pre-drafted.
Catches the vendor that added a sub-processor without telling anyone.
Alerts when data starts moving to a country with no transfer mechanism.
Model a market entry or an AI Act milestone and see the work it creates.
Shorten a retention period and watch exposure and request effort update live.
Today: The Article 30 record is a spreadsheet, last updated for the audit.
The Article 30 record is current. Two new processing activities detected, lawful basis flagged for review.
Today: A DPIA takes days of specialist time, so it is rationed to who asks.
Threshold screen, risks raised as they are answered, report pre-filled before the project call ends.
Today: Hour one is spent working out who to call.
Severity auto-scored, the Article 33 clock running, notify decision by jurisdiction, notices drafted.
Today: A sub-processor change surfaces at the next annual review, if at all.
Sub-processor drift caught and the file reopened, without anyone remembering to go and check.
Confidence comes from knowing where data moves and why.
Find the breach inside the deadline
We agree the metric and the baseline in week one, and measure the result on your data.