Privacy Documents
by Formiti's Global DPO Team
A centralised document library for privacy policies, notices, procedures, and governance documentation with version control, access permissions, and stakeholder review workflows.
Who uses this module?
DPOs, Legal Counsel, Policy Owners, Compliance Managers.
What governance problem does it solve?
Privacy documentation is often scattered across shared drives, outdated, and lacking formal review cycles. Privacy Documents provides a governed repository ensuring the right version is always accessible and review obligations are met.
What are the key workflows?
- Upload and categorise documents by type (policy, notice, procedure, template)
- Set access permissions by role and entity
- Track document versions with change history
- Schedule review dates and flag overdue documents
- Invite external stakeholders for document review via secure token-based access
Upload and categorise documents by type (policy, notice, procedure, template)
Set access permissions by role and entity
Track document versions with change history
Schedule review dates and flag overdue documents
Invite external stakeholders for document review via secure token-based access
What evidence and reporting does it produce?
Built-in outputs for accountability and regulatory readiness
Document inventory by type and status
Review compliance dashboard (overdue, upcoming, completed)
Version history and change audit trail
Stakeholder review records with ratings and comments
How does it connect to other Privacy360 modules?
- Policies referenced by ROPA processing activities
- Privacy notices linked to Assessment records
- Breach response procedures referenced during incident management
- Training materials can link to source policy documents
What are some example use cases?
A DPO uploads a revised privacy notice, sets a 12-month review cycle, and invites legal counsel for formal review — all tracked with timestamps and comments.
During a regulatory audit, the compliance team produces a complete document inventory showing all policies are within their review cycles.
An entity controller restricts access to entity-specific procedures while maintaining group-level policy visibility.
Related modules
ROPA Records
Maintain records of processing activities with clear ownership, data mapping, review controls and AI Processor disclosure — and let the record automatically open and pre-fill the DPIA, LIA, transfer and AI assessments it triggers.
Privacy Assessments
Run global privacy gap assessments, DPIAs, LIAs, transfer reviews and vendor assessments against 150+ controls — with structured rationale, evidence and AI-assisted review.
Privacy & AI Training LMS
A full SCORM-compliant LMS built into Privacy360 — fresh 2026 privacy, security and AI courses out of the box, new content every week, and unlimited custom SCORM uploads at no extra per-user cost.
Breach Management
Log, assess, and manage data breaches with incident workflows, notification tracking, and AI-assisted Breach Guidance.