ACCOUNTABLE DATA GOVERNANCE 

GDPR Management Software for Accountable Data Governance

Control the Controls—not the Personal Data

Zebsoft helps organisations define, operate and review the controls surrounding personal-data processing. It does not take control of the personal data held in HR, CRM, finance, email or operational systems.

Instead, configured workflows give each privacy requirement an owner, a decision route, required evidence, follow-up actions and a review point. The result is a more accountable way to manage RoPA records, DPIAs, rights requests, processors, retention decisions and breach response. 

  • Define which privacy controls should apply and who owns them
  • Communicate decisions, tasks and deadlines to the responsible people
  • Retain evidence showing whether the control operated as intended
  • Review exceptions and changes before records become outdated
GDPR governance controls surrounding business data systems through accountable workflows

THE IMPORTANT DISTINC TION

Data Protection Depends on Controls That Continue to Work

A privacy register may describe what should happen, but accountability depends on whether the organisation keeps that description accurate, applies the required safeguards, acts within relevant timescales and records its decisions. This is where workflow matters. 

 

The data

Personal data remains within the organisation’s operational systems and approved repositories. Those systems must apply their own access, security, accuracy, retention and disposal measures.

 

The control

The control defines what people must do: identify a lawful basis, review retention, assess risk, approve sharing, respond to a request or evaluate a breach. 

 

The assurance workflow

ZAP records ownership, routes the required review, captures supporting evidence, assigns follow-up and retains the decision history so gaps remain visible. 

ZAP does not discover, secure or govern every item of personal data automatically. It helps the organisation control and evidence the human and procedural controls that should govern that data. 

FROM REQUIREMENT TO ASSURANCE 

The Privacy Control Chain

GDPR management software is useful when it turns a policy or legal requirement into a controlled operating route without pretending that the software makes the legal decision. 

 

Requirement

Identify the principle, obligation, policy, contract or risk that makes a control necessary. 

 

Control

Define the action, decision, safeguard, record or review expected from the respon sible role.

 

Operation

Use questions, logic, assignments and approvals to guide people through the required process. 

 

Evidence

Retain proportionate evidence of the assessment, action, approval, exception or completed review. 

 

Assurance

Review whether the control remains current, complete and effective; raise action when it does not. 

ZAP privacy workflow showing DPIA screening risk actions evidence and accountable approval

A REAL CON TROL WORKF LOW

From Proposed Processing to an Accountable Decision

Consider a proposed new service, surveillance activity, AI use, data-sharing arrangement or system change. The privacy task is not simply to upload a completed DPIA document. The organisation must screen the activity, examine the risks, decide what safeguards are required and retain the basis of the decision. 

  • Describe the nature, scope, context and purpose of the intended processing
  • Screen for indicators that a DPIA may be required
  • Identify affected individuals and potential harm to their rights and freedoms
  • Assess necessity, proportionality, existing controls and residual risk
  • Assign mitigation to named owners with evidence requirements
  • Route the proposal to the appropriate DPO, owner or approving authority
  • Record the outcome, conditions and planned review trigger

A configured route can make missing steps visible. The organisation remains responsible for deciding whether processing may proceed and whether consultation with the ICO is required. 

CONNECTED PRIVACY CONTROLS 

Six Areas Where Workflow Strengthens Accountability

The existing page intent is retained, but each capability is expressed as a control process rather than an unsupported promise to manage all personal data. 

 

RoPA and data mapping

Assign processing activities to accountable owners, record purposes, categories, recipients, transfers, retention and security measures, then schedule review when activity changes. 

 

Lawful basis and retention

Record the organisation’s selected basis and reasoning, connect applicable policy or assessment evidence and prompt review of retention decisions. 

 

DPIA and privacy risk

Screen proposed processing, assess risks to individuals, assign mitigation, approve the decision and revisit the assessment when material conditions change. 

 

Individual-rights requests

Log the request, confirm identity proportionately, assign searches and reviews, monitor the response route and retain the outcome without unnecessarily copying personal data into the work flow.

 

Processor oversight

Record processors, contract status, services, review dates and due-diligence actions, with links to the relevant processing activity and supplier record. 

 

Breach assessment and response

Capture the facts, assess risk to individuals, record the notification decision, assign mitigation and retain the response history for subsequent review. 

RIGHTS REQUESTS IN PRACTICE 

Control the SAR Response Without Treating It as a Ticket Alone

A subject access request can arrive through different channels and may require contributions from several systems and departments. The risk is not merely a missed diary date; it is an incomplete search, insecure disclosure, inconsistent redaction or a decision without an accountable basis.

  • Record how and when the request was received
  • Confirm identity or authority where reasonably necessary
  • Clarify the requested information only where the conditions allow
  • Assign proportionate searches to relevant data owners
  • Review third-party information, exemptions and response security
  • Approve and issue the response through the agreed route
  • Retain the decision and completion evidence

ICO guidance currently requires a response without undue delay and generally within one month, subject to the specific rules on identity, clarification, fees and permitted extensions. The configured workflow should reflect the organisation’s procedure and current guidance. 

What ZAP controls

  • Ownership and required contributors
  • Configured target dates and notifications
  • Search, review and approval steps
  • Exceptions and unresolved activity
  • Evidence that the response route was completed

What people still decide

  • The scope of a reasonable search
  • Whether an exemption or restriction applies
  • What must be redacted or disclosed
  • How identity and delivery will be handled securely

INCIDENT TO ACCOUNTABLE OUTCOME 

A Breach Workflow Must Support the Decision—Not Make It

Every known personal-data breach should be recorded. The organisation must assess the likely risk to individuals and determine whether notification is required. Where a breach is notifiable, current ICO guidance requires notification without undue delay and no later than 72 hours after awareness.

01 

Capture

Record the known facts, discovery time, affected processing and immediate containment. 

02 

Classify

Identify data categories, affected people, scale and the nature of the breach. 

03 

Assess

Evaluate likelihood and severity of possible harm to individuals. 

04 

Decide

Authorised people decide whether ICO and individual notification thresholds are met. 

05 

Act

Assign mitigation, communication, investigation and corrective action. 

06 

Review

Retain the rationale and revisit controls, risks, training or suppliers affected. 

A timer can prompt urgency. It cannot determine the legal threshold, the risk to individuals or the content of a regulatory notification.

CONTROLLED GOVERNANCE, LIVE ASSURANCE 

Apply the 70/30 Model to Privacy Management

Privacy governance contains a stable framework and a changing operational position. Both are required if a policy is to become an accountable system. 

70% — The controlled framework

Policies, responsibilities, RoPA structure, lawful-basis criteria, retention rules, processor requirements, assessment methods and escalation routes define how privacy should be managed. 

  • Approved policies and procedures
  • Defined control owners and authorities
  • Configured assessment and response routes
  • Review, retention and escalation requirements

30% — The live assurance position

Current requests, assessments, processor reviews, evidence, actions, breaches, overdue work and changed processing activities show whether those controls are operating. 

  • Current records and supporting evidence
  • Open decisions, risks and mitigations
  • Due, overdue and escalated activity
  • Completed reviews and verified outcomes
ZAP privacy assurance dashboard showing control owners reviews evidence and exceptions without personal data

EVIDENCE WITH PROPORTIONATE DATA 

Prove the Control Without Creating Another Privacy Risk

Privacy software should not become an uncontrolled copy of the personal data it is meant to help govern. The workflow should retain enough information to evidence the control while avoiding unnecessary duplication of identity documents, request bundles, investigation material or operational datasets. 

  • Use references or controlled links where the underlying evidence belongs elsewhere
  • Collect only the information necessary for the control decision
  • Restrict access according to role and purpose
  • Apply agreed retention and review arrangements to governance records
  • Separate management reporting from sensitive case detail
  • Confirm how exports and attachments will be handled before configuration

The appropriate boundary depends on the organisation’s purpose, systems, risk assessment and data-protection procedure. It should be designed deliberately rather than created by convenience. 

SOFTWARE SUPPORTS ACCOUNTABILITY 

Clear Responsibility Is Part of the Control

Zebsoft can provide structured records, permissions, tracked activity, tasks, checklists, notifications, approvals and evidence routes. This is the practical role of GDPR management software. These features support privacy governance; they do not guarantee compliance or replace the controller’s, processor’s, DPO’s or legal adviser’s responsibilities. 

 

Customer responsibility

The organisation decides its purposes, lawful bases, controls, retention, risk tolerance, response decisions and applicable legal obligations. 

 

Configured system responsibility

The agreed ZAP configuration records and routes the control process, surfaces incomplete activity and retains the permitted evidence. 

 

Zebsoft service responsibility

Zebsoft hosts and supports the platform as agreed, with customer data hosted in AWS London and information-security controls supported by Zebsoft’s ISO 27001-certified management system. 

The customer remains responsible for confirming that its configuration, procedures, permissions, training and use meet its own privacy obligati ons.

DEEPER GUIDANCE AND CONNECTED CONTROLS 

Connect Privacy Governance to the Wider Management System

Privacy controls often depend on document control, risk, audit, supplier oversight and information security. Use these pages and primary sources to build the operational context around the GDPR workflow. 

 

Risk management

Connect privacy risks, mitigation and review activity.

Explore risk management → 

 

Document control

Control privacy policies, procedures and review activity.

Explore document control → 

 

Audit management

Assess whether privacy controls are operating and retain findings.

Explore audit management → 

 

ISO 27001

Link privacy governance to information-security controls.

Explore ISO 27001 software → 

COMMON QUESTIONS 

GDPR Management Software FAQs

Does Zebsoft control our personal data?

No. Personal data remains within the organisation’s approved operational systems and repositories. ZAP controls the configured governance workflow around that data: ownership, assessment, actions, approvals, evidence and review. 

Can ZAP guarantee GDPR compliance?

No software can guarantee organisational compliance. ZAP can support accountability by structuring the controls and retaining permitted evidence, but the organisation remains responsible for its legal decisions and operating practices. 

Can we manage a RoPA in Zebsoft?

ZAP can structure processing activities, owners, purposes, categories, recipients, transfers, retention and security-control descriptions, with workflow for review and change. The organisation remains responsible for completeness and accuracy. 

Can ZAP manage SAR and breach workflows?

Configured workflows can allocate tasks, record decision points, prompt target dates and retain response evidence. Authorised people must still assess scope, exemptions, disclosure, breach risk and notification duties. 

Should privacy evidence be uploaded into ZAP?

Only where necessary and permitted by the organisation’s procedure. A reference or controlled link may be more appropriate when the underlying evidence contains personal or sensitive information. 

Can the privacy controls connect to other modules?

Yes. Privacy risks, policies, audits, training, incidents, suppliers and corrective actions can be related within the wider Zebsoft platform, subject to the agreed configuration and permiss ions.

ZAP IT. KNOW I T. FIX IT.

Make Privacy Controls Visible, Accountable and Reviewable

Bring one real privacy process to a demonstration—such as a DPIA, RoPA review, subject access request, processor assessment or breach response—and see how ZAP can control its workflow without pretending to control the personal data itself.