Privacy settings
Set controller details, covered regulations, data-subject regions, and the security-measure catalog.
What it is
The Privacy tab of organization settings holds what the rest of Privacy checks against and prints: who the controller is, who to contact, which regulations you assess against, where your data subjects are, and the catalog of security measures a record can claim. It is admin-only. Every other Privacy page reads from here; the Article 30 export prints the controller block verbatim.
Where to find it
SettingsPrivacyThe tab appears only for organizations on the Privacy segment. Links from the
overview and from scan details land on /settings?tab=privacy#regulations.


A rail on the left tracks setup out of five: Organization, Privacy contact, GDPR-specific, Security measures, and Regulation coverage, with a RoPA header preview showing how the controller block will print.
Key actions
Record controller details
Leave the DPO fields empty if none is appointed; the Article 30 document then prints "None appointed" rather than a blank.
Set the default role
Default role answers "Your role for new processing activities": Controller, Processor, or Joint controller. It is applied to every record that has no explicit role, and it decides which register the record belongs to; Article 30(1) and 30(2) are separate registers, so set this before completing records rather than after.
Maintain the security-measure catalog
Security measures (TOMs) (Art. 32, Art. 30(1)(g)) is the list a record can tick under Security measures. Measures derived from the data map appear in their own card.
Edit a row inline or choose Archive measure. Archiving keeps the measure on records that already claim it but removes it from the list for new ones. The empty state reads "No measures yet. Add the controls you want implied on privacy records."
Choose regulation coverage
Regulation coverage is where you choose what to assess against. Signals are derived from your data map, but the switch is yours.
The catalog covers GDPR, ePrivacy, UK GDPR, PECR, FADP, KVKK, LGPD, PIPEDA, Quebec Law 25, PIPL, APPI, PIPA, DPDP, the Singapore and Thai PDPAs, the Australian and New Zealand Privacy Acts, POPIA, the US state laws, and the GPC specification. What you switch on becomes the Legal scope of every scan, the per-regulation findings in Monitoring, and the Evaluation scope chips on the overview.
Statuses and fields
| Field | Where it is used |
|---|---|
| Legal entity name, Registered address, Jurisdiction | Article 30 header |
| Contact name, Contact email | Article 30 "Privacy contact" |
| DPO name, DPO email | Article 30 "Data protection officer" |
| EU representative fields | Article 30 header when set |
| Default role | Register assignment for records without a role |
| Security measures | Checkbox list on every record; Article 30(1)(g) |
| Data-subject jurisdictions | Coverage signals per regulation |
| "Assess against" switches | Scan legal scope, findings, overview chips |
Tips and gotchas
A Coverage signal means your data map shows processing a regulation would reach, not that the regulation applies to you. The switch is a choice of what to assess against; it is not a determination of legal applicability.
Map each measure to a control. A mapped measure lets the compliance side point at the same evidence the privacy record claims.
What Noru does not do
Noru does not decide which laws apply, appoint a DPO, or validate an EU representative. Switching a regulation on does not add obligations to records; it changes what scans and coverage are measured against. Archiving a measure does not strip it from records that claimed it.
Related
Last updated on