Privacy subjects & controls directory — reusable privacy subjects with a configurable subject-type taxonomy, GDPR Art.30 ROPA records, and the vendor/processor register

Last updated: August 06, 2026 by Steve

Privacy Subjects & Controls

Open Privacy subjects & controls from the top toolbar (needs assessment-view) to browse the searchable directory of reusable privacy subjects — the durable programs, systems, initiatives, data-sharing arrangements, process changes, and technology adoptions your assessments and incidents run against. It is used by the privacy and security office to keep one shared record per subject, including the Controls, AI/ADM register, and compliance profile now tracked on each one — see Privacy Subject Details. The workspace has two tabs: Subjects — the directory described here — and Vendors, the vendor/processor register below.

Subject Types

Subject types are a configurable taxonomy — Settings → Privacy subject choice fields → Subject types, seeded by the Universal Baseline pack with types such as Program, Business process, IT system, and AI system. A type flagged as an automated decision-making (ADM) system unlocks the AI/ADM system register section on every subject of that type. The same grouped Privacy subject choice fields panel also manages the other subject taxonomies used across the directory and its records: categories of personal data (shared with incident reporting), categories of data subjects, and categories of recipients.

Browsing the Directory

Subjects are shown as cards. Each card shows:

  • The subject type
  • The subject's own status
  • Assessment and incident counts
  • The next-review date

Click a card to open the subject detail — see Privacy Subject Details.

Privacy subjects & controls directory

Creating a Subject

  1. Click New subject (needs create permission).
  2. Capture the identity — name, type, status, business owner, lead program manager, and description.
  3. Complete the full ROPA record.

You can also inline-create a subject by typing a new name in the subject box while creating an assessment.

New subject dialog

Exporting the ROPA Register

Click Export ROPA to produce the PDF Record-of-Processing register across all subjects.

The Vendor Register

The Vendors tab is the register of third parties that process personal information for your institution — the list a privacy office is asked for in every audit. Each vendor card shows its role (processor, sub-processor, controller, joint controller, or service provider — hover for the definition), risk level, and at-a-glance compliance chips: DPA in place, DPA expires (date) when expiry is within 90 days, DPA expired, No DPA (escalating to a red No DPA — in use when the vendor is linked to a subject without any agreement recorded), Contract ended / Contract ends (date), and Review overdue when the next-review date has passed. A vendor linked to processing activities shows Used by N subjects — click it to expand the list of subjects, each with the vendor's role in that processing.

New vendor (needs assessment-create; editing needs assessment-modify) captures:

  • The vendor's identity and contacts
  • The data-processing-agreement facts — in place, signed, expiry
  • Contract start and end dates, and last/next review dates
  • Processing jurisdiction, risk level, and notes
  • An optional link to a ROPA recipient category, so the register lines up with your Article 30 taxonomy

Retiring a vendor keeps it on the register greyed out rather than deleting history, and a vendor still linked to privacy subjects cannot be deleted — remove the links or retire it instead, so ROPA records never point at a vanished processor.

Vendor register