1 / 5 · acuna.io / privacy / ropa
Processing Activities
One register for every PA. Status, frameworks, and references stay on one row.
- 142 PAs in the mock list
- GDPR, FADP, and UK on the same record
- Article 30 columns ready to export
·Alexis Hirschhorn · ISO 42001 Lead Auditor
ROPA, DPIAs, DSARs, and breach response on one connected record, audit-ready by default.
Acuna Data Privacy is the privacy management module of the Acuna GRC platform, built for the people who understand what most tools miss: that ROPA, DPA, DPIA, TIA, breach response, and DSARs are one connected workflow, not six modules in separate workspaces.
· the architecture is in the UI ·
Five product views that share one graph. On mobile we show a short summary for each. The stacked desktop collage with full UI detail appears when you widen the screen.
1 / 5 · acuna.io / privacy / ropa
One register for every PA. Status, frameworks, and references stay on one row.
2 / 5 · acuna.io / pa / PA-2026-042 / frameworks
Each framework keeps its own legal basis without duplicating the operational record.
3 / 5 · acuna.io / privacy / breach-simulator
Pick a vendor and see cascade counts for PAs, assets, and data elements.
4 / 5 · acuna.io / privacy / questionnaire
Business owners get a one-time token link tied to the PA they own.
5 / 5 · acuna.io / pa / PA-2026-042 / data-flow
Subjects, assets, systems, and third parties on one screen for the regulator questions.
Employee payroll processing
Customer support data
Marketing analytics
FRAMEWORKS
basis: Legitimate interest Art. 6(1)(f)
basis: Consent Art. 6 FADP
AWS Frankfurt
eu-central-1 · processor
▲ if compromised
from: privacy@acuna.io
Please confirm PA-2026-043 data
You have been sent a scoped link to review and confirm the processing activity you own.
acuna.io/privacy/questionnaire/3f7a8c19b2…d8e
Subjects
Assets
Systems
Third Parties
Four product facts that matter to privacy teams. Each row is the same credential you see in the desktop layout, stacked so nothing is squeezed into a narrow column.
Multi-framework on one record
GDPR and Swiss FADP govern the same processing activity with independent legal bases on one operational record.
Country TIA lookup
Transfer Impact Assessment pre-populates destination jurisdictions from a 226-country dataset.
Seeded data elements
GDPR Article 9 special-category mapping included. Your team adds from a curated base instead of building the ontology first.
EDPB WP248 criteria
The DPIA threshold screener applies all nine criteria. Two or more met triggers the requirement under Article 35.
The shape of the work
01 · the shape of the work
The ROPA is current the day you approve it and slightly out of date by the time the meeting ends. Business owners answer questionnaires in their own time, in their own words. Sub-processor chains drift. Cross-border transfers get a new safeguard every time a court ruling lands.
02 · the shape of the tooling
The platform you bought was sold as one suite and configured as six. Implementation took longer than the timeline you were given. Pricing grew on a schedule nobody warned you about. The Article 30 export comes out as a flat table, and the relationships, the data flows that are the actual point of Article 30, live in your head.
03 · what you are actually looking for
You are not looking for a tool that promises to make privacy easy. You are looking for a tool that respects the real shape of the job.
The architecture
Open any Processing Activity. This is what you see. ↓
Everything in privacy operations is a relationship. A processing activity collects from a data subject, stores in an asset, sends to a third party. The third party has sub-processors. Sub-processors create transfer obligations. Transfer obligations require safeguards. A breach on any node cascades through the graph.
Most platforms model this as six tables and a series of forms that ask you to re-enter the same information into each one. Acuna models it as one graph. The DPA wizard reads the sub-processor chain from your third-party configuration. The Breach Simulator reads affected PAs from the asset and third-party links. The Article 30 export ships with the relationship columns, because the relationships are the record.
This is what people mean when they say a privacy program should be operational, not documentary.
The view buyers fall in love with
Open a PA, click Data Flow, and the answer to every regulator’s first four questions renders itself: who the subjects are, what data is involved, where it lives, and who else touches it. Article 30 logic, rendered as architecture.
One PA, four stages. Who the data is about, where it is collected and stored, and who receives it. Widen the screen for the full canvas with connectors and data elements.
Data subjects
originates with
Collects from
data assets
Stores in
system assets
Sends to
third parties
Amber = cross-border or special-category signal in the product
Data Subjects
data originates with
Employees
10K–20K subjects
Collects From
data assets
ERP System (SAP)
RESIDENCY · Dublin Data Center
Badge Access System
RESIDENCY · CH Switzerland
Stores In
system assets
Azure Blob Storage
RESIDENCY · DE Germany
Active Directory
RESIDENCY · DE Germany
Sends To
third parties
Microsoft
JURISDICTION · US United States
TalentHub HR
JURISDICTION · US United States
01 · article 30 in a glance
Flow direction, residency, and data elements are visible without opening a single file. The diagram is the Article 30 register, rendered.
02 · cross-border surfaces itself
The diagram tells you which Processing Activity has US transfers without you having to ask. Warning treatment fires automatically on cross-border third parties.
03 · special-category flagged for you
Biometric, health, and other special categories render in warning treatment automatically. The flag fires before you have to look for it.
“This is the diagram your auditor keeps asking for. It’s also the answer.”
Export columns
Capability 01 · ROPA
GDPR Article 30 is usually requested first, and usually hardest to produce fast when relationships are spread across spreadsheets and disconnected tools.
In Acuna, a processing activity is a graph object carrying data subjects, assets, third parties, legal bases, and personal data mappings together. Exports include relationship columns by default: Collects From, Stores In, Sends To, Controllers, Joint Controllers, Processors, Sub-Processors. Workflow states stay object-level: Draft, In Review, Approved, Needs Update.
When the authority asks and the timeline is short, you export. The flows are already in the columns.
PA-2026-042 · Article 30 export with relationship columns selected.
Capability 02 · Multi-framework
Multi-framework governance often becomes duplicate workspaces and duplicate records that drift apart over time.
Acuna runs framework governance on one processing activity. Each framework carries its own legal basis selection, review cycle, and export trail. GDPR and Swiss FADP are seeded; UK GDPR or regional overlays attach to the same PA without migration into a second tenant.
You don't run separate workspaces. You don't migrate when a new framework enters scope. You add it to the PA.
Same PA: GDPR and FADP assigned with independent legal bases.
Customer support data
+ Add framework: UK GDPR, BDSG...
DPIA · Threshold
WP248 screener
DPA · Scope
Art. 28 wizard
TIA · Schrems II
Transfer analysis
Capability 03 · Assessments
Privacy teams should not retype the same context into three different wizards just to complete linked assessments.
DPIA uses EDPB WP248 threshold logic from the PA context. DPA reads third-party and sub-processor attributes for Article 28 scope. TIA starts from the linked third party and destination context, then computes risk based on mechanism and questionnaire answers. Shared PA context stays consistent across all three.
Three assessments. One graph. Information you've already captured doesn't get retyped into three more wizards.
DPIA, DPA, and TIA wizards sharing the same PA-2026-042 context strip.
Capability 04 · The graph, reversed
Pick a third party. The same graph that draws your Data Flow walks itself in reverse, surfacing every Processing Activity that depends on the compromised node, every data asset they touch, and every data element at risk. In a click, not a quarter.
On mobile you see the cascade in order: impact numbers first, then the selected vendor, then when teams use the simulator. The full two-panel layout returns on wider screens.
affected processing activities
directly linked to the compromised vendor
data assets at risk
storing personal data processed via the vendor
data elements impacted
including 6 classified as special category
Selected third party
Microsoft
Linked processing activities
When to use it
Board exposure reviews. Show which vendor would cascade furthest.
Active incident. Scope article 33 obligations in real time, under pressure.
DPA or audit debrief. Demonstrate structured assessment with traceable output.
72 hours, GDPR Article 33. The supervisory authority clock starts on awareness. Scoping shouldn't take days.
When the question comes up in the next board meeting, you don’t need a quarter. You need a click.
Capability 05 · Privacy Portal
Intake workflows consume disproportionate privacy effort when DSAR and questionnaire channels are split into separate systems.
Public DSAR intake runs at /privacy/request/[tenantSlug] with tenant branding, honeypot protection, and per-IP and per-tenant rate limiting. Submissions are tracked with a SHA256-hashed token. Business owner questionnaires use one-time cryptographic token links. The state machine (Stub → Questionnaire Sent → Questionnaire Received → Approved) makes approval explicit.
The chase doesn't scale. The approval does.
Split intake: DSAR public form and scoped PA questionnaire editor.
/privacy/request/yourcompany
Request your data
Full name
Request type
→ 30-day clock starts
/privacy/questionnaire/3f7a8c…d8e
Confirm: PA-2026-042
Data categories
Data elements
Retention
→ Token invalidates
Part of the platform
Privacy is not a silo. The third parties you process data through are the same vendors your TPRM program assesses. DPIA risks should roll up to enterprise risk. Security measures on processing activities should map to controls in your ISMS.
Also connects to: Policy · Controls · full platform overview →
DPIA risks roll up to the enterprise risk register
Privacy third parties share the same vendor record as TPRM assessments
Security measures on processing activities map to controls in the ISMS
Personal data breaches flow through the same incident model used elsewhere in governance
Alexis Hirschhorn
ISO 42001 Lead Auditor · Acuna GRC
Acuna Data Privacy is led by Alexis Hirschhorn, ISO 42001 Lead Auditor and Acuna's spokesperson on AI governance and privacy operations. The perspective is operational: privacy programs break at the seams between tools, and the durable answer is one connected graph, not six modules.
The decisions behind the product (the graph model, the multi-framework approach, the token-scoped questionnaires, the Breach Simulator) come from close observation of where real privacy operations lose time.
About Alexis →Is this for you?
Your ROPA lives in a tool that doesn't export relationship columns, so the data flows live in your head.
You run GDPR and Swiss FADP (or UK GDPR) and you've accepted duplicate records as the cost of multi-framework.
DSARs arrive by email and live in a shared inbox or a standalone tool with no link to your processing activities.
DPIAs, DPAs, and TIAs share no context and are filled in separately each time a new processing activity is added.
When your board or auditor asks what would be exposed if a particular vendor had an incident, the answer takes days.
Bring a real PA, a real vendor chain, or a real audit scenario.
Before you choose
Answers to the operational questions. No sales copy.
A ROPA is the inventory of processing operations required by GDPR Article 30. It should capture purposes, categories of data subjects and personal data, recipients, transfers, retention periods, and safeguards. In audits, relationship fields, who you collect from, where you store, and who you send to, are usually the first request.
↑ each answer is the atomic version; links to canonical articles coming
A DPIA is mandatory under GDPR Article 35 when processing is likely to create high risk to rights and freedoms. WP248 guidance uses nine criteria; meeting two often triggers a DPIA, while one criterion may still require one depending on context and severity.
↑ each answer is the atomic version; links to canonical articles coming
A TIA evaluates whether transfer safeguards remain effective for personal data transferred outside the EU without adequacy. After Schrems II, this assessment became case-specific for each destination and mechanism, often SCCs, including supplementary measures and surveillance exposure.
↑ each answer is the atomic version; links to canonical articles coming
Where a personal data breach is likely to risk rights and freedoms, controllers must notify the supervisory authority without undue delay and, where feasible, within 72 hours of awareness. If notification is late, reasons should be documented and submitted.
↑ each answer is the atomic version; links to canonical articles coming
Under GDPR Article 12, responses should be provided without undue delay and within one month. The period may be extended by two additional months for complex or numerous requests, with timely notice to the requester.
↑ each answer is the atomic version; links to canonical articles coming
A DPA should define subject matter, duration, nature, purpose, data categories, and data subject categories, plus controller instructions, confidentiality, sub-processor conditions, security measures, assistance obligations, return or deletion, and audit rights.
↑ each answer is the atomic version; links to canonical articles coming
A single processing activity can carry framework-specific legal bases and review workflows in parallel. The operational record remains one object, while each framework preserves its own governance trail and evidence output.
↑ each answer is the atomic version; links to canonical articles coming
Keep updates tied to operational workflows: scoped questionnaires with one-time tokens, state transitions for review, and object-level drift indicators for data mappings and third-party changes. This shifts privacy teams from chasing to approval and control.
↑ each answer is the atomic version; links to canonical articles coming
See it live
Bring a real processing activity, a real vendor chain, or a real audit scenario. We will show how the graph handles it in one live model.
Book a demoacuna data privacy · one graph, not six modules · gdpr · swiss fadp · uk gdpr