Skip to content

Privacy overview

The Privacy section is CyberGuard’s register of personal-data processing activities: the record GDPR Article 30 asks you to keep, modelled as a graph of typed objects rather than a spreadsheet. Because every entry is a real object in the platform, the register is filterable, exportable, permission-scoped like everything else, and it connects straight to the assets, applied controls and evidences that already document your environment.

Privacy → Overview in the sidebar. It opens the GDPR / Privacy dashboard for the domains you can see.

The register is built around one central object, the processing, with everything else hanging off it:

ObjectWhat it records
ProcessingAn activity that operates on personal data — the anchor for everything below
PurposeThe lawful reason the processing exists, with its Article 6 legal basis
Personal dataThe categories of data involved, their retention and deletion policy
Data subjectThe kind of individual the data refers to — employee, customer, prospect, minor
Data recipientInternal teams or external parties that receive the data
Data contractorThird parties processing on your behalf, linked to the third-party register
Data transferFlows to entities outside the original jurisdiction, with their safeguard mechanism

Two more objects record events rather than structure: right requests (what data subjects ask for and how you answered) and data breaches (what happened, who was notified and when).

Purposes, personal data, data subjects, recipients, contractors and transfers are all children of a processing — you create them from the processing’s detail page, and they inherit its domain. Right requests and data breaches are standalone objects that reference one or more processings.

The overview page opens with five counters — Documented processings, Personal data categories identified, Data Recipients, Open Requests and Data breaches open — so you can see at a glance whether the register is being maintained and whether anything is waiting on you.

Below them, Data breaches by type and Requests by type break the two event registers down by category, and Data flow overview visualises where personal data travels: from the processings that collect it, through the recipients and contractors that handle it, to the countries it is transferred to.

Create one processing per activity you can name in business terms — “payroll”, “customer support ticketing”, “marketing newsletter” — then fill in its purposes and personal data before worrying about recipients and transfers. A processing with a purpose and a personal-data category is already a usable Article 30 entry; the rest can be layered on.