PricorisTechnologies

DPDP: the tools do the work, the GRC keeps the proof

Four operational tools share one data map: discover what you hold, take consent on it, govern the website and the app, and answer the person who asks about it, with every step timestamped. PIMS GRC sits on top and is filled by what the tools did.

1. Discover

PII Discovery scans the estate as it is, not as it was declared: databases, shares, mailboxes, drives, APIs, endpoints. Every finding carries a masked sample, a category and a location.

2. Record

The Record of Processing Activities and the DPIA are pre filled from discovery. The processor register in PIMS GRC lists who else touches the data.

3. Consent

Consent and Rights takes purpose specific consent in the person's language, records the notice version, and gives a preference centre where withdrawal is one action.

4. Answer

A correction or erasure filed in the rights portal opens as a request in PII Discovery under a CONSENT-DSR reference, is discharged across every source, verified by rescan, and closed back to the person.

The loop, on screen

My rights: access, correction, erasure and grievance, each with a reference, filed and due dates, and a resolution.
My rights: access, correction, erasure and grievance, each with a reference, filed and due dates, and a resolution.
The same request in PII Discovery: opened by the consent platform, matched across sources, quarantined or tracked as a manual action.
The same request in PII Discovery: opened by the consent platform, matched across sources, quarantined or tracked as a manual action.
Who holds personal data: one row per person and per machine, with an erasure worklist as CSV.
Who holds personal data: one row per person and per machine, with an erasure worklist as CSV.
Incidents: affected sources chosen from the data map, so the breach is scoped from evidence.
Incidents: affected sources chosen from the data map, so the breach is scoped from evidence.

The GRC layer: PIMS GRC

An ISO/IEC 27701 privacy management system workspace with the DPDP obligations cross walked to the controls. It does not ask for uploads: consent artefacts, processor acknowledgements, rescan verifications and DPIAs arrive from the tools as evidence against the controls that need them. PIMS GRC.

Editions

DPDP Starter for startups, MSMEs and D2C brands: Consent and Rights, Cookie Consent and the Breach Register, hosted, at a fixed annual price, with notice templates and a one off discovery scan. DPDP Enterprise for regulated organisations: the full stack self hosted with sector packs, SSO and PIMS GRC. Pricing.

Why one data map matters

A rights platform that does not know where the data is can only route a ticket. A discovery tool that does not connect to consent can only draw a map. Joined, they answer the two questions every DPDP obligation reduces to: what do we hold about this person, and can we prove what we did with it.

The Cookie Consent platform runs on the same principle for the website and the app: what is actually set and sent, not what the tag manager says.

Run the loop on your estate

A demo starts with one of your sources and ends with an erasure verified by rescan.