Privacy begins with visibility

Module · Privacy and Data Protection

Privacy teams are asked to prove control over data they cannot see, against deadlines set by regulation rather than by capability.

Prophesee Privacy keeps the record current, turns assessments into minutes, and runs the seventy-two hour clock with the notices already drafted.

Evidence and lineageEntity resolutionClassification and mappingContinuous monitoringForecasting
See it running

Privacy: a day in the life

One working day inside Privacy, from the morning forecast to the evidence that the intervention worked.

Privacy: a day in the life
The shift

You have seventy-two hours to notify. It takes 241 days to find out.

Privacy teams are asked to prove control over data they cannot see, against deadlines set by regulation rather than by capability. The record is maintained by hand, assessments are rationed by specialist time, and the mandate keeps growing.

443
Personal data breach notifications per day in Europe, up 22%
241
Days to identify and contain a breach, global mean
€6.11bn
GDPR fines across 2,685 decisions to March 2026

Sources: DLA Piper GDPR Fines and Data Breach Survey, Jan and Feb 2026 · IBM and Ponemon, Cost of a Data Breach 2025 · CMS GDPR Enforcement Tracker, Mar 2026 · Verizon DBIR 2025 · IAPP and FTI Privacy Governance Report.

A new approach

Building a living privacy programme

nexus iconNexus
Today · OneTrust, populated by interview

The Article 30 record, the data map and the transfer register are built from questionnaires and workshops, so they are stale the day they are signed off.

A living record of processing

The RoPA builds itself from connected systems: purposes, categories, Article 9 flags, lawful basis, retention, recipients and every cross-border flow with its transfer mechanism.

foresight iconForesight
Today · Manual discovery per system

A subject request means finding one person across forty systems where they are spelled five ways, and being certain enough to hand over the data.

Assessments in minutes, not weeks

Threshold pre-screen against Article 35 triggers, questionnaire that raises risks as they are answered, and a pre-filled DPIA report. FRIA under the EU AI Act bolts onto the same flow.

pulse iconPulse
Today · Annual vendor review

Sub-processor additions and transfer route changes are discovered at the next review, or in a footnote of a renewal email.

The 72-hour console and the drift watch

Intake, auto-severity, the Article 33 clock, a notify decision tree by jurisdiction and pre-drafted Article 33 and 34 notices. Separate rules catch risk drift that is not yet a breach.

horizon iconHorizon
Today · No model at all

Subject request volume, breach notifiability and the workload of a market entry are not forecast, so the team is permanently behind the clock.

Plan the regulatory step change

Model a market entry, a works council negotiation or an EU AI Act milestone and see how many assessments, transfers and approvals it creates before you commit.

From challenge to decision

Turning privacy obligations into decisions

Problem: Evidence and lineage
What produces it today: OneTrust, populated by interview

The Article 30 record, the data map and the transfer register are built from questionnaires and workshops, so they are stale the day they are signed off.

Engine: nexus icon Nexus
The applications that replace it: Living Article 30DPIA From Your Documents
Problem: Entity resolution
What produces it today: Manual discovery per system

A subject request means finding one person across forty systems where they are spelled five ways, and being certain enough to hand over the data.

Engine: nexus icon Nexusforesight icon Foresight
The applications that replace it: Subject Request AssemblyRetention Past Due
Problem: Classification and mapping
What produces it today: DPO reading documents

Processing activities are mapped to legal basis, special category and Article 35 triggers by a specialist reading, so assessments are rationed to whoever asks.

Engine: foresight icon Foresightnexus icon Nexus
The applications that replace it: DPIA Threshold ScreenBreach Severity At Intake
Problem: Continuous monitoring
What produces it today: Annual vendor review

Sub-processor additions and transfer route changes are discovered at the next review, or in a footnote of a renewal email.

Engine: pulse icon Pulse
The applications that replace it: Sub-Processor DriftTransfer Drift Watch
Problem: Forecasting
What produces it today: No model at all

Subject request volume, breach notifiability and the workload of a market entry are not forecast, so the team is permanently behind the clock.

Engine: foresight icon Foresighthorizon icon Horizon
The applications that replace it: Request Volume ForecastStep Change Planning
What becomes possible

12 AI applications that could be relevant

A sample of what becomes possible on the decision layer, not a fixed list: each application draws on the same data foundation and audit trail, and new ones are configured on the engines, not built from scratch.

Nexus
Living Article 30

The record of processing builds itself from connected systems and stays current.

Nexus
DPIA From Your Documents

Architecture docs, DPAs and retention schedules become a drafted assessment.

Nexus
Subject Request Assembly

Finds the subject across every system and assembles the response pack.

Foresight
DPIA Threshold Screen

Predicts which projects trip an Article 35 trigger and how high the risk lands.

Foresight
Request Volume Forecast

Forecast of subject request volume by type and jurisdiction, weeks ahead.

Foresight
Breach Severity At Intake

Scores severity and likely notifiability the moment a breach is reported.

Foresight
Retention Past Due

Finds personal data still held beyond the retention schedule that governs it.

Pulse
Seventy-Two Hour Console

The Article 33 clock, the notify decision by jurisdiction, notices pre-drafted.

Pulse
Sub-Processor Drift

Catches the vendor that added a sub-processor without telling anyone.

Pulse
Transfer Drift Watch

Alerts when data starts moving to a country with no transfer mechanism.

Horizon
Step Change Planning

Model a market entry or an AI Act milestone and see the work it creates.

Horizon
Retention Scenarios

Shorten a retention period and watch exposure and request effort update live.

How work changes

A day in a data-aware organisation

Or watch this day as a film.

Today: The Article 30 record is a spreadsheet, last updated for the audit.

With Prophesee:
08:30nexus icon Nexus
The record maintained itself

The Article 30 record is current. Two new processing activities detected, lawful basis flagged for review.

Today: A DPIA takes days of specialist time, so it is rationed to who asks.

With Prophesee:
11:00foresight icon Foresight
A DPIA inside the meeting, not after it

Threshold screen, risks raised as they are answered, report pre-filled before the project call ends.

Today: Hour one is spent working out who to call.

With Prophesee:
14:15pulse icon Pulse
Hour one of a breach

Severity auto-scored, the Article 33 clock running, notify decision by jurisdiction, notices drafted.

Today: A sub-processor change surfaces at the next annual review, if at all.

With Prophesee:
17:00pulse icon Pulse
The vendor that quietly changed

Sub-processor drift caught and the file reopened, without anyone remembering to go and check.

Confidence comes from knowing where data moves and why.

Find the breach inside the deadline

We agree the metric and the baseline in week one, and measure the result on your data.