Privacy Hub by Wrangu –
Solution for GDPR

Your go-to solution for Implementing the GDPR into your organisation

Three business people discussing about GDPR in front of a window
Women working together on tablet reading about GDPR

Quick Look: GDPR

The General Data Protection Regulation (GDPR) is a set of EU-wide data protection rules that places specific regulatory requirements on organisations operating in the European Union and organisations outside the union who process personal data of data subjects in the union. For most organisations, these requirements have led to the introduction of new processes, systems and personnel to enable them to meet their obligations. Privacy Hub by Wrangu, is a data privacy management solution that automates and harmonises the disparate activities of various teams into one seamless outcome ensuring ongoing compliance.

Delving into the GDPR articles immediately reveals several requirements of interest such as the rights of data subjects which organisations are required to fulfil within a one-month period with a possibility to extend the duration for a further two months. Organisations are also required to maintain a record of processing activities, send personal data breach notifications to supervisory authorities and impacted data subjects, conduct data protection impact assessment and process personal data with appropriate safeguards.

How to implement GDPR with the Privacy Hub by Wrangu

Automate GDPR processes in 4 modules:

The data subject rights module provides the ability for data privacy teams and data subjects to raise and manage data subject rights requests allowing organisations to:

  • Capture DSR request details
  • Validate the data subjects, agents and data subject rights requests
  • Manage one-month SLA duration including possibility of extensions
  • Have a consolidated view of all open and closed data subject requests received from a particular data subject over a given period of time to manage excessive request.
  • Indicate whether a DSR request should be fulfilled based on the lawful basis of processing the information
  • Request approval from a data controller to process a DSR request when actioning as a processor
  • Confirm with data subjects how they would like to receive information in response to right to access requests
  • Dynamically create tasks for the notification of third parties when fulfilling a right to erasure or right to rectification request

Relevant GDPR Articles:

  • Article 12: Transparent Information, Communication and Modalities for the Exercise of the Rights of the Data Subject
  • Article 13: Information to be Provided Where Personal Data are Collected from the Data Subject
  • Article 14: Information to be Provided where Personal Data have not been Obtained from the Data Subject
  • Article 15: Right of Access by the Data Subject
  • Article 16: Right to Rectification
  • Article 17: Right to Erasure
  • Article 18: Right to Restriction of Processing
  • Article 19: Notification Obligation Regarding Rectification or Erasure of Personal Data or Restriction of Processing
  • Article 20: Right to Data Portability
  • Article 21: Right to Object
  • Article 29: Processing under the authority of the controller or processor

The DPIA module leverages latest guidance from regulators and provides the ability to perform an initial DPIA screening questionnaire to determine if a new processing is likely to result in a high risk to the rights and freedoms of natural persons and, if required, conduct a full assessment for new projects, ensuring adherence to privacy by design principles. The DPIA module also provides:

  • Automatic evaluation of DPIA responses with possible concerns raised for consideration such as where automated processing including profiling is conducted, or a large-scale processing of personal data or personal data relating to criminal convictions and offences is processed.        .
  • Built-in configurable risk calculation engine with risk ratings displays based on responses and including safeguards and security measures to address risks.
  • Facilitate multiple users’ completion of a single DPIA assessment.
  • Configurable approval levels throughout the lifecycle of an assessment including facility to capture and monitor advice from data protection officers.
  • Indication of whether the views of impacted data subjects should be sought or supervisory authority consulted.

Relevant GDPR Articles:

  • Article 25: Data Protection by Design and by Default
  • Article 35: Data Protection Impact Assessments
  • Article 36: Prior Consultation
  • Article 39: Tasks of the data protection officer

Comprehensive engine enabling the robust documentation of processing activities with the ability to relate a ROPA directly to services, processes or configuration items within the ServiceNow CMDB. The ROPA module also supports:

  • Capture of all data sets as specified by Article 30 of GDPR to ensure the completeness and ongoing relevance of the ROPA record including indicating the lawful basis of personal data processing, controls for international data transfer and provision of sufficient guarantees from data processors.
  • Maintain version history for each ROPA record to support auditing and complaints management activities.
  • Flag changes in the CMDB and other sources that would suggest a need to update the ROPA including provision of adequate technical and organisational measures for the security of personal data.
  • Generate and update a ROPA from a DPIA utilising the same data set from the DPIA.
  • Automatically indicate what rights data subjects can exercise against the data collected as part of this processing.

Relevant GDPR Articles:

  • Article 6: Lawfulness of Processing
  • Article 28: Processor
  • Article 30: Records of Processing Activities
  • Article 32: Security of Processing
  • Article 45: Transfers on the basis of an adequacy decision
  • Article 46: Transfers subject to appropriate safeguards
  • Article 47: Binding corporate rules
  • Article 48: Transfers or disclosures not authorised by Union law
  • Article 49: Derogations for specific situations
  • Article 50: International cooperation for the protection of personal data

Acts as a register of all data breach incidents as they relate to personal data and facilitate the automatic determination of whether a report or notification should be sent to the supervisory authority or impacted data subjects. This module also provides:

  • Standard process to support data gathering to determine if the personal data breach is likely or very likely to result in a risk or high risk to the rights and freedoms of impacted data subjects.
  • Automated data breach SLA calculator to ensure regulatory stated reporting timelines are monitored and complied with.
  • Generate and assign dynamic tasks to relevant parties in addressing data breach reporting requirements.
  • Support report creation for notification to the supervisory authority or communication to impacted data subjects.
  • Ready integration with ServiceNow Security Incident Response module.

Relevant GDPR Articles:

  • Article 33: Notification of a Personal Data Breach to the Supervisory Authority
  • Article 34: Communication of Personal Data Breach to the Data Subject

Consent Management

Challenge: How do I know which Privacy statement was used, at which time, and on which system? The lack of knowledge on this creates significant complexity and high costs!

Solution: Privacy Hub Consent Management Centre (CMC) provides a centralised platform to create, propagate, aggregate and track consent notices, privacy notices and individual data subject consents.

An intuitive platform to create consent notices and privacy notices based on reusable templates, ensuring users always access the latest versions. The Consent Management Centre allows tracking of these notices and user preferences against appropriate versions. It’s built on the ServiceNow platform to ensure seamless integration with the Configuration Management Database and other applications.

Wrangu's Privacy Hub Consent Management Dashboard Interface

Key Features

  • Consent Notice – Compile, track and manage consent notices obtained through applications such as websites or mobile apps and paper forms. Provide auditability of what information was presented to the user at the time consent was obtained. Pre-defined workflow to ensure appropriate governance of consent notices with review and approval prior to publication.
  • Privacy Notice module – compile privacy notices for organisations using predefined templates. Pre-defined workflow to ensure the notice is taken through appropriate review and approval prior to publication.
  • Centralised Consent database – a centralised repository where all the consents are stored. This provides ease of management and tracking of consents.
  • Notice Versioning – The system supports versioning of all notices, to keep an accurate documentation of any changes that may have been made to the notices as well as proof of the information that was provided at the time of consent collection.
  • Notice to Asset tracking – provides transparency on consent and privacy notices currently and previously used by applications including duration and period of use.
  • Notice Export – Provides the ability to easily export notices to pdf for use in electronic and print channels.
  • Consent Aggregation – Various integration methods are available including REST API to intake consents obtained on other external systems.
  • Dashboard and reports – predefined reports and dashboards are provided to assist in management of consents and privacy notices.