Incident Management

Delivering an efficient digital platform to manage and handle any data breaches, data subjects rights, complaints and information requests directed to your organisation.

Data Breach Management

The data breach management module allows any ProvePrivacy user to raise an incident relating to a suspected data breach.  Once raised ProvePrivacy will notify the DPO of the breach and allow them to establish an investigation team. 

ProvePrivacy guides the team through the circumstances and the consequences of the incident allowing them to build the supervisor breach report.  All incidents are logged so that your organisation can demonstrate both reported breaches and near misses.

Staff can report a breach instantly through an embeddable form on your SharePoint intranet, and investigators can also raise incidents directly within the ProvePrivacy platform, so nothing depends on the person who spots it first knowing the right process.

Once an incident is logged your lead investigator can manage the breach step by step, including reporting to the supervisory authority or, other interested parties, receiving notifications so that reporting deadlines don’t get missed.

Breach findings can be added directly into your risk register, capturing the root cause and turning lessons learned into tracked corrective actions rather than a closed case file, so your board sees the resulting trends and can see the same incident type is prevented from recurring.

If a breach is reportable, ProvePrivacy will generate the supervisor breach report so that it can be emailed to the relevant regulatory authority.  This means that that there is no need to re-enter information already collected by ProvePrivacy.

Data Subject Rights Management | ProvePrivacy

Data Subject Rights Management

The data subject rights module lets colleagues and data subjects raise any request in one place, whether it is a DSAR, a complaint, a right to be forgotten or any other data subjects right, so nothing gets missed or handled off the record.

With every UK exemption built into the ProvePrivacy platform, your investigators can quickly identify which ones apply, cutting the time and effort spent on each case while keeping your response consistent and defensible.

Colleagues can raise a rights request or complaint instantly through an embeddable form on your SharePoint intranet, and investigators can also log cases directly within the ProvePrivacy platform, so nothing depends on the person who spots it first knowing the right process.

An optional public facing form is also available, giving data subjects a direct route to submit their own request or complaint.

Once logged, your investigator manages the case step by step within the ProvePrivacy platform, and any complaint can be converted into a full rights incident in a single step.

This automatically applies the stricter statutory response deadline, so a case that starts as a general complaint is never left to drift once it becomes a formal data subject request, protecting you from missing a deadline you did not know was running.

There are a large number of complex exemptions available when dealing with data subjects rights, and not all can be applied to all requests.  ProvePrivacy only allows the relevant exemptions to be selected and recorded, meaning your investigation teams can focus on responding to relevant parts of the request.

Real time dashboards within the ProvePrivacy platform give every stakeholder, from investigators to the board, visibility of every open rights request, its stage and its deadline.

This turns rights request reporting from a manual chase into a single source of truth, so your DPO can walk into any board meeting confident they can answer questions on volumes, response times and risk on the spot.

DSAR Redaction

DSAR Redaction

Preparing a subject access response often means manually blacking out third-party names, special category data, or other information that shouldn’t be disclosed — slow, easy to get wrong, and hard to evidence afterwards.

ProvePrivacy’s DSAR Redaction Tool is included as standard for every client, letting your investigators redact personal and third-party data directly within the case, without exporting files to separate redaction software or losing the audit trail of what was withheld and why.

The DSAR Redaction Tool uses AI to scan each document and highlight the personal data it finds, giving your team a starting point instead of a blank page to search through line by line.

So your investigator reviews and confirms every redaction before it is applied, keeping a human decision behind each one while cutting the hours normally spent on manual review. The AI works only on the document in front of it and is never trained on client data.

Available To Every Client: The redaction tool is included as standard across the platform, not sold as a separate add-on.

DSAR Redaction generates a full audit trail, producing a single PDF record of every redaction made and the exemption relied upon for it.

So if a decision is ever challenged, by the data subject, the ICO or an internal reviewer, you have clear evidence of what was withheld and why, rather than trying to reconstruct the reasoning once the case is already closed.

Information Request Management

The Information Request module allows a request for information to be recorded.  Typically this would be a request for non-personal information such as a Freedom of Information Request, Environment Information Regulations request or a request from other bodies.

ProvePrivacy informs the appropriate teams that a request has been raised, notifies them of the progress of the request and when further actions are required.

Reporting a request is simple, with colleagues able to log an incident instantly through an embeddable form on your SharePoint intranet and an optional public facing form available for external reporting, so fewer obstacles stand between an incident happening and you finding out about it.

Once logged, your lead investigator manages the incident step by step within the ProvePrivacy platform, and the information captured throughout the process is retained automatically, so management information can be pulled together later without anyone having to reconstruct the case from scratch.

As with every module in the ProvePrivacy platform, FOI cases include the ability to record findings against each request. This means a case can be closed off whilst the root cause behind it has actually been resolved.

So the same request is far less likely to land back on your desk in six months because the underlying issue was never fixed.

Testimonials

What our clients say

Scroll to Top

Contact us

If you would like to ask more questions or to arrange training, complete the form below and we will respond shortly.

Prefer to schedule a 15 minute call? Schedule call today >>

See our Privacy Statement for more details.