Incident Management
Delivering an efficient digital platform to manage and handle any data breaches, data subjects rights, complaints and information requests directed to your organisation.
Data Breach Management
The data breach management module allows any ProvePrivacy user to raise an incident relating to a suspected data breach. Once raised ProvePrivacy will notify the DPO of the breach and allow them to establish an investigation team.
ProvePrivacy guides the team through the circumstances and the consequences of the incident allowing them to build the supervisor breach report. All incidents are logged so that your organisation can demonstrate both reported breaches and near misses.
- Breach Reporting
Staff can report a breach instantly through an embeddable form on your SharePoint intranet, and investigators can also raise incidents directly within the ProvePrivacy platform, so nothing depends on the person who spots it first knowing the right process.
- Breach Management
Once an incident is logged your lead investigator can manage the breach step by step, including reporting to the supervisory authority or, other interested parties, receiving notifications so that reporting deadlines don’t get missed.
- Breach Findings
Breach findings can be added directly into your risk register, capturing the root cause and turning lessons learned into tracked corrective actions rather than a closed case file, so your board sees the resulting trends and can see the same incident type is prevented from recurring.
- Stakeholder Management
If a breach is reportable, ProvePrivacy will generate the supervisor breach report so that it can be emailed to the relevant regulatory authority. This means that that there is no need to re-enter information already collected by ProvePrivacy.

Data Subject Rights Management
The data subject rights module lets colleagues and data subjects raise any request in one place, whether it is a DSAR, a complaint, a right to be forgotten or any other data subjects right, so nothing gets missed or handled off the record.
With every UK exemption built into the ProvePrivacy platform, your investigators can quickly identify which ones apply, cutting the time and effort spent on each case while keeping your response consistent and defensible.
- Data Subject Rights Incidents
Colleagues can raise a rights request or complaint instantly through an embeddable form on your SharePoint intranet, and investigators can also log cases directly within the ProvePrivacy platform, so nothing depends on the person who spots it first knowing the right process.
An optional public facing form is also available, giving data subjects a direct route to submit their own request or complaint.
- Investigation
Once logged, your investigator manages the case step by step within the ProvePrivacy platform, and any complaint can be converted into a full rights incident in a single step.
This automatically applies the stricter statutory response deadline, so a case that starts as a general complaint is never left to drift once it becomes a formal data subject request, protecting you from missing a deadline you did not know was running.
- Exemptions
There are a large number of complex exemptions available when dealing with data subjects rights, and not all can be applied to all requests. ProvePrivacy only allows the relevant exemptions to be selected and recorded, meaning your investigation teams can focus on responding to relevant parts of the request.
- Stakeholder Management
Real time dashboards within the ProvePrivacy platform give every stakeholder, from investigators to the board, visibility of every open rights request, its stage and its deadline.
This turns rights request reporting from a manual chase into a single source of truth, so your DPO can walk into any board meeting confident they can answer questions on volumes, response times and risk on the spot.

DSAR Redaction
Preparing a subject access response often means manually blacking out third-party names, special category data, or other information that shouldn’t be disclosed — slow, easy to get wrong, and hard to evidence afterwards.
ProvePrivacy’s DSAR Redaction Tool is included as standard for every client, letting your investigators redact personal and third-party data directly within the case, without exporting files to separate redaction software or losing the audit trail of what was withheld and why.
- AI-Assisted Highlighting
The DSAR Redaction Tool uses AI to scan each document and highlight the personal data it finds, giving your team a starting point instead of a blank page to search through line by line.
So your investigator reviews and confirms every redaction before it is applied, keeping a human decision behind each one while cutting the hours normally spent on manual review. The AI works only on the document in front of it and is never trained on client data.
Available To Every Client: The redaction tool is included as standard across the platform, not sold as a separate add-on.
- Audit Trail
DSAR Redaction generates a full audit trail, producing a single PDF record of every redaction made and the exemption relied upon for it.
So if a decision is ever challenged, by the data subject, the ICO or an internal reviewer, you have clear evidence of what was withheld and why, rather than trying to reconstruct the reasoning once the case is already closed.
Information Request Management
The Information Request module allows a request for information to be recorded. Typically this would be a request for non-personal information such as a Freedom of Information Request, Environment Information Regulations request or a request from other bodies.
ProvePrivacy informs the appropriate teams that a request has been raised, notifies them of the progress of the request and when further actions are required.
- Incident Reporting
Reporting a request is simple, with colleagues able to log an incident instantly through an embeddable form on your SharePoint intranet and an optional public facing form available for external reporting, so fewer obstacles stand between an incident happening and you finding out about it.
Once logged, your lead investigator manages the incident step by step within the ProvePrivacy platform, and the information captured throughout the process is retained automatically, so management information can be pulled together later without anyone having to reconstruct the case from scratch.
- FOI Findings
As with every module in the ProvePrivacy platform, FOI cases include the ability to record findings against each request. This means a case can be closed off whilst the root cause behind it has actually been resolved.
So the same request is far less likely to land back on your desk in six months because the underlying issue was never fixed.
Testimonials
What our clients say

We began our journey with ProvePrivacy in January 2025. At Navitas we have a complex organisation structure at a Global level and Privacy/Data Protection is paramount throughout.
We’ve found the experience with ProvePrivacy to be logical and straightforward; which can often be rare in privacy platforms. ProvePrivacy is a pleasure to use; Mark and the team are efficient, pragmatic and always happy to help.
Navitas Pty Ltd
Kristie Marshman - Global Head of Data Privacy, UPE Data Protection Officer, UPNA Privacy Officer, Office of the CEO

Data, Data, Data. Mark is the man. Every time I have a question about data in either a business or IT scenario Mark is my first port of call. If you need help or advice with Data Protection or compliance with data regulation. This is where you go.
David Gemmell
Programme Manager

ProvePrivacy is an easy to use system and I think the work you’ve done by implementing the data retention schedule a great advantage point for the Higher Education sector.
Anglia Ruskin University
David Humphreys - Information Governance Manager

ProvePrivacy is a very intuitive and user-friendly tool, which will be really helpful for fundraisers who might have limited data protection experience or be engaging with information governance for the first time. The fact that it was so thorough seemed like it could be really beneficial in terms of ensuring all data protection information about a given product or activity is held in one place.
International Aid Charity

Just completed the GDPR Foundation Course , which gave me a big uplift in knowledge on the new standard. The course was thorough and delivered very professionally but they key benefit for me was Mark’s ability to bring the material to life by providing and discussing examples. I would definitely recommend this training.
John Pikett
Managing Partner

I’ve just completed GDPR Foundation training and thoroughly recommend it. I went in with a good working knowledge of the Data Protection Act, but not much real knowledge of how if differs to new legislation such as GDPR. By the end of the session I felt I had a really good understanding of the key aspects of GDPR, and what it will mean in practice – invaluable – and what made it even better was that I also passed the exam at the end !
David Grant
Executive Director

Having worked with the principal director Mark, I can say that it is good to see that a courteous, professional and client dedicated experience with the end client goals always in the sights for delivery, being offered within the UK market. Having used their consulting services on a number of fronts and most recently for some training for my business on GDPR I can thoroughly recommend this team.
Casey Thomas
IT Director

I attended the GDPR Foundation Course and prior to attending the course the team took the time to discuss the course content and who it was aimed at. The course itself was run at a good speed in a small manageable group which allowed the group more of the tutor’s time allowing us all and go over anything we were unsure of. The pace of the course was good with open discussion on each of the modules. The theory was brought to life with real examples where you could use it in the workplace.
Shakil S
Operations Manger, KPMG

I attended one of the Foundation courses and would recommend it to anyone wanting to learn more about the organisational impact of GDPR. Mark is a very engaging presenter with an extensive knowledge of the regulation and is able to summarise effectively the practical implications of the regulation on businesses of all sizes.
Matthew Page
Senior Product Owner, Jaguar Land Rover

I wholeheartedly recommend Mark’s services around GDPR consultancy and training. He understands the regulations, how they impact companies and how firms can succeed on the journey to compliance and beyond. Moreover, given his programme management and compliance background, Mark is ideally placed to accompany organisations on that route.


