Skip to content

Products

Compliance Officer Service Expert-led compliance, end to end Compliance Portal Share security documents securely Open-source platform Deploy Probo on your own infrastructure

Resources

Probo stories How teams get compliant with Probo Blog Ideas and guidance from the Probo team Guides & tools Practical compliance guides and free tools Love from Customers What customers say about working with Probo Changelog Latest product updates Download Get the Probo Agent

Company

About The people and vision powering Probo Careers Join the team building Probo Brand assets Official logos and visual resources Security Review our security and compliance posture
Overview Understand Probo and its core concepts Product Explore Probo's GRC capabilities Developers Explore GraphQL, CLI, MCP, n8n, and webhooks Deployment Probo Cloud, self-hosting, and configuration

Explore

GitHub Explore our open-source compliance tools

Privacy management

Document data, processing activities, impact assessments, transfers, and rights requests

View as Markdown

Probo keeps privacy records connected to the same controls, measures, risks, vendors, and evidence used by the wider compliance program.

A data record describes information handled by the organization, including its sensitivity and business impact. A processing activity explains why and how data is processed, the parties involved, and the safeguards that apply.

Publish processing activities only after the purpose, scope, legal context, recipients, and retention assumptions have been reviewed. Update the record when the actual processing changes.

  • A Data Protection Impact Assessment (DPIA) evaluates processing that may create a high risk to individuals.
  • A Transfer Impact Assessment (TIA) evaluates an international transfer and the legal and practical safeguards around it.

These assessments are first-class records rather than attachments. Link them to the relevant processing, data, vendors, risks, and measures so reviewers can follow the decision.

Rights requests track requests such as access or erasure through their operational lifecycle. Limit access to the people who need to process the request, avoid placing unnecessary personal data in free-text fields, and use tasks to coordinate work with accountable owners.

Probo organizes privacy work; it does not determine which law applies or replace legal advice.