Privacy

Privacy settings

Set controller details, covered regulations, data-subject regions, and the security-measure catalog.

RolesAdminRoute/settings?tab=privacyShown toPrivacy organizations

What it is

The Privacy tab of organization settings holds what the rest of Privacy checks against and prints: who the controller is, who to contact, which regulations you assess against, where your data subjects are, and the catalog of security measures a record can claim. It is admin-only. Every other Privacy page reads from here; the Article 30 export prints the controller block verbatim.

Where to find it

SettingsPrivacy

The tab appears only for organizations on the Privacy segment. Links from the overview and from scan details land on /settings?tab=privacy#regulations.

The Privacy settings tab with the setup rail, controller details, and regulation coverageThe Privacy settings tab with the setup rail, controller details, and regulation coverage
The setup rail counts the five sections you have completed.

A rail on the left tracks setup out of five: Organization, Privacy contact, GDPR-specific, Security measures, and Regulation coverage, with a RoPA header preview showing how the controller block will print.

Key actions

Record controller details

Under Organization, fill Legal entity name, Registered address, and Jurisdiction.
Under Privacy contact, fill Contact name and Contact email.
Under GDPR-specific, fill DPO name and DPO email if you have appointed one, and the EU representative name, EU representative email, and EU representative address if you are established outside the EU.
Save. The toast reads "Controller details saved".

Leave the DPO fields empty if none is appointed; the Article 30 document then prints "None appointed" rather than a blank.

Set the default role

Default role answers "Your role for new processing activities": Controller, Processor, or Joint controller. It is applied to every record that has no explicit role, and it decides which register the record belongs to; Article 30(1) and 30(2) are separate registers, so set this before completing records rather than after.

Maintain the security-measure catalog

Security measures (TOMs) (Art. 32, Art. 30(1)(g)) is the list a record can tick under Security measures. Measures derived from the data map appear in their own card.

Click Add a measure.
Give it a name, a category (Encryption, Access control, Pseudonymisation, Resilience & availability, Backup & recovery, Testing & evaluation, Organisational, Other), an optional control mapping (No control mapped or a control from your frameworks), and a description.
Save; the toast reads "Measure added".

Edit a row inline or choose Archive measure. Archiving keeps the measure on records that already claim it but removes it from the list for new ones. The empty state reads "No measures yet. Add the controls you want implied on privacy records."

Choose regulation coverage

Regulation coverage is where you choose what to assess against. Signals are derived from your data map, but the switch is yours.

Under Data-subject jurisdictions, search and add the countries where the people whose data you process are located.
Read each regulation row: short name, jurisdiction, full name, the count of obligations found in your data map, a GPC badge where the law recognises Global Privacy Control, and Coverage signal or No signal.
Expand a row for its summary, obligations, and what it changes: Assessment, Sensitive data, Sale/share opt-out, Global Privacy Control.
Turn on the switch labelled "Assess against" for each regime you operate under.

The catalog covers GDPR, ePrivacy, UK GDPR, PECR, FADP, KVKK, LGPD, PIPEDA, Quebec Law 25, PIPL, APPI, PIPA, DPDP, the Singapore and Thai PDPAs, the Australian and New Zealand Privacy Acts, POPIA, the US state laws, and the GPC specification. What you switch on becomes the Legal scope of every scan, the per-regulation findings in Monitoring, and the Evaluation scope chips on the overview.

Statuses and fields

FieldWhere it is used
Legal entity name, Registered address, JurisdictionArticle 30 header
Contact name, Contact emailArticle 30 "Privacy contact"
DPO name, DPO emailArticle 30 "Data protection officer"
EU representative fieldsArticle 30 header when set
Default roleRegister assignment for records without a role
Security measuresCheckbox list on every record; Article 30(1)(g)
Data-subject jurisdictionsCoverage signals per regulation
"Assess against" switchesScan legal scope, findings, overview chips

Tips and gotchas

A Coverage signal means your data map shows processing a regulation would reach, not that the regulation applies to you. The switch is a choice of what to assess against; it is not a determination of legal applicability.

Map each measure to a control. A mapped measure lets the compliance side point at the same evidence the privacy record claims.

What Noru does not do

Noru does not decide which laws apply, appoint a DPO, or validate an EU representative. Switching a regulation on does not add obligations to records; it changes what scans and coverage are measured against. Archiving a measure does not strip it from records that claimed it.

Last updated on