Skip to content
Sentinel Unity
Privacy

PDPL: Personal Data Protection

Privacy obligations overlap heavily with the security controls you already run, and separating them is what causes the same evidence to be collected twice. In Sentinel Unity a privacy requirement is a control in the same library, mapped to the security control that satisfies it.

Saudi Arabia's Personal Data Protection Law, held as an example of a privacy regime. Any equivalent is loaded and mapped the same way.

  • PaymentsDomain
    • Card acquiringCapability3 risks2 policies
      • Merchant settlementService4 controls2 assets
        • Daily reconciliationProcess1 risk2 controls1 finding

Every level links out to risks, controls, policies, findings, assessments, and assets

One

Control library, not two

0 to 5

Maturity scored

Graded

Mapping to security controls

Data

Applicability tag

Obligation areas

What a privacy programme has to evidence

These are the areas the regime covers. Each becomes a set of controls in the library, assessed and evidenced like any other.

Lawful basis and purpose

Why personal data is processed, on what grounds, and whether that reasoning is written down anywhere.

  • Stated purpose
  • Lawful grounds
  • Documented decisions

Data inventory and retention

What categories are held, where, and for how long, which is usually the first request an authority makes.

  • Categories held
  • Location
  • Retention periods

Cross-border transfer

Data leaving one jurisdiction for another, and the safeguards that permit it.

  • Transfer records
  • Safeguards
  • Approvals

Breach notification

Obligations that begin at discovery and run against a clock, involving both an authority and affected individuals.

  • Discovery
  • Authority notice
  • Individual notice

Individual rights

Access, correction, deletion, and portability, with responses that have to be evidenced later.

  • Access
  • Correction
  • Deletion
  • Portability

Processors and suppliers

Personal data handled on your behalf remains your obligation, which puts it in the vendor register.

  • Processor assurance
  • Contract obligations
  • Sub-processors

Platform mapping

How privacy work is carried

Plainly stated: there is no separate privacy module. These are the platform mechanics a privacy programme runs on.

Privacy requirements as controls

Loaded into the same library, under their own jurisdiction and authority, and mapped to the security controls that already satisfy them.

The Data applicability tag

Controls tagged Data can be filtered as a set, which is how a privacy view is assembled without a second library.

Policies mapped at clause level

A privacy notice or handling standard maps to controls by section and bullet, so which policy covers this obligation has a precise answer.

Findings and remediation

A privacy gap raises the same kind of finding as a security gap, with severity, an owner, and a plan.

Processors in the vendor register

Anyone processing personal data for you is assessed and monitored as a third party, with obligations tracked against the contract.

An audit trail that holds

Platform activity is written to an append-only log, which matters most in the one conversation where your record is the only account of what happened.

Maturity

How maturity is scored

Every privacy control is scored on the platform's six-level scale, each level carrying a written descriptor so a score means the same thing in two different business units.

Level 0

Not Performed

The practice does not happen. Recorded as an explicit level rather than a blank.

Level 1

Performed Informally

It happens, but it depends on individuals and is neither planned nor tracked.

Level 2

Planned & Tracked

Planned, resourced, and monitored, though practice still varies between teams.

Level 3

Well Defined

A defined standard process, applied consistently across the organisation.

Level 4

Quantitatively Controlled

Measured against targets, with deviation detected from the measurements themselves.

Level 5

Continuously Improving

Improvement is fed by the measurements, changing the process rather than the reporting.

Stop running privacy and security as two evidence programmes

Book a walkthrough with our GRC specialists and see the platform run against the frameworks you are held to.

No commitment required. A typical demo runs 45 minutes.