Privacy Risk overview
How the domain organizes around the processing activity, and what derives from it.
The processing activity is the center
The whole privacy domain revolves around the processing activity: what you do with personal data, for what purpose, and under which legal basis. From it derive the record of processing (ROPA), the reports the law requires, privacy risks, and the compliance view.
The activity does not appear in isolation: it derives from an already-mapped business process. That avoids the classic scenario of two parallel inventories — one operational, one for privacy — that diverge within three months with nobody knowing which is right.
What the platform computes on its own
You fill in the activity; the platform decides which reports it requires. DPIA, LIA, TIA, and DIA are not checklists someone has to remember to open — they are triggered by the activity's own criteria and surface as pending items in the register.
Silence is not compliance
One principle runs through this entire domain and is worth knowing before reading any number: an unfilled field is never displayed as a field in order. A rule that could not be evaluated shows as not evaluated, not as passed.
The reason is concrete. Before the rules engine could see activities created through the form, the platform showed 18 activities, 8 rules, and zero findings — while the undefined-retention rule was true for all 18. Silence read exactly like compliance, which is the worst possible defect in a privacy module.
Where it connects
The domain's consolidated result rises into the corporate register as the PR child risk, which carries the legal dimension. Suppliers processing data on your behalf link to the corresponding activities, so the question "who touches this data" crosses TPRM and privacy without needing a spreadsheet.