Department Landscape¶
Where the actual discovery work happens: what each department does with personal data, which vendors they use, and the evidence backing it all up. Almost everything here is populated by your Dutient consultant working session by session with the relevant department — your job is mostly to read the result and upload supporting evidence when asked.
Discovery¶
The sidebar lists one entry per department (Admin, Finance, HR, Operations, etc. — matching what's set up in Company Profile → Departments). Each department page has the same five tabs.
Department Overview¶
A "Privacy Questionnaire" for the department — a set of discovery questions (what activities the department performs, whether a privacy notice is shown, what forms collect personal data, whether the department handles data subject requests, retention schedule, etc.), answered by your consultant through AI-assisted discovery conversations with your team. A progress bar shows how much is answered. Read this to understand what your consultant has learned about the department so far — flag anything that looks off in Workspace.
Control Framework¶
The same control table as Global Framework, pre-filtered to controls tagged to this department — a quick way to see this department's compliance status specifically.
Business Process¶
The department's Record of Processing Activities (RoPA) — the core compliance record, one entry per activity that touches personal data (e.g. payroll processing, vendor onboarding). The list shows Name, Owner, Status, Risk, and Revalidation date.
Each record is built through a 6-step wizard, which your consultant fills in with the department over the course of discovery:
- Details — Business Process Name, Owner, Description, Data Subjects (a volume band, e.g. "500–999"), AI Usage (Yes/No)
- Controllers & Processors — which laws apply, and which of your legal entities are involved (with their role, e.g. Data Fiduciary)
- Data Subjects and Personal Data Elements — who the data is about, what data categories/elements are collected, why (purpose), where it comes from, how it's collected, and the legal basis
- Data Retention & Deletion — where it's stored, how long it's kept, why, whether/how it's deleted
- Personal Data Transfer — whether data moves between departments, to third-party vendors, or across borders
- Data Security Measures — encryption at rest/in transit, training, policies, access governance, vendor security management
As a customer, this is your best single view of exactly what a department does with personal data — read through it to sanity-check accuracy, and use Download PDF (ROPA) when you need to hand a finished record to someone outside Dutro (e.g. an auditor).
Personal Data Inventory¶
A flattened, exportable (CSV) table of every personal data element captured across the department's processes — Department, Element, Process, Purpose, Legal Basis, Source, Collection Mode, Transfers, Retention. Useful when you need a flat list rather than process-by-process detail, e.g. for a data mapping exercise or a DSAR. Hover any cell to copy its value.
DFD (Data Flow Diagram)¶
In development
DFD is still in active development and is not yet generally available. What follows is a preview of what's coming, based on the current build — screens and workflows may change before release.
An auto-generated visual data-flow diagram built from the department's discovery data. Toggle between Process and Department view, pick a business process from the dropdown, and use the zoom presets (Small / Focus / Full) to read it.
Vendors¶
Third-party vendor management. The list shows Vendor, Department, Linked business processes, whether the vendor uses AI, computed Risk level, and when it was last updated.
Each vendor record is a 6-tab wizard, populated by your consultant as part of vendor due diligence:
- Vendor Profile — name, website, service provided, industry, geography, employee count, vendor role (e.g. Data Processor), and whether they have a DPO
- Data Processing Details — what processing activities involve this vendor, what data categories/elements, purpose, volume, sharing frequency and mechanism
- Certifications & Controls — certifications held (e.g. ISO 27001, ISO 27701), policy-based controls in place (grouped Organizational / People / Technological), incident response plan, any breach in the last 12 months
- Legal & Compliance — whether a DPA is in place, legal safeguards, breach notification clause, indemnity clause
- Sub-Processor Management — whether the vendor uses sub-processors, and details of each (services, location, data categories/elements, safeguards)
- Risk Assessment — an auto-computed overall risk score (0–3 scale: Low 1.0–1.5 / Medium 1.6–2.2 / High 2.3–3.0), broken down into five weighted factors — Data Risk (25%), Exposure Risk (20%), Transfer Risk (25%), Control Risk (20%), Legal Risk (10%) — each with its own Low/Medium/High badge and the reason behind it (e.g. a missing DPA drives Legal Risk to High)
Read the Risk Assessment tab to understand why a vendor is scored the way it is.
What you can do here
Use the document-upload action on a vendor row to attach the actual DPA (Data Processing Agreement) or MSA (Master Service Agreement) once it's signed — that's evidence your consultant can't produce on your behalf.
Evidence Bank¶
The central file repository for compliance evidence — the proof behind your controls (policies, signed agreements, screenshots, training records, and so on). Files are organized in folders per department. Top stats: Total Items, Verified, Pending Verification, Expiring Soon, Expired.
Opening a file shows:
- File Information — Evidence ID, Type, filename, size, uploaded by/when, department, expiry date, verification status
- Linked Controls & Records — which framework controls this evidence supports
- Version History — every uploaded version, with download links
What you can do here
This is one of your primary hands-on responsibilities. When your consultant or a control needs supporting documentation, use + Upload at the relevant folder to add it. Once uploaded, your consultant reviews and marks it Verified; if a document is replaced (e.g. a policy gets updated), use Upload New Version on the same evidence item rather than creating a new one, so the version history stays intact.