Privacy overview
Operate data inventory, processing records, assessments, website monitoring, and privacy review from one connected model.
Privacy
The Privacy overview at /privacy prioritizes privacy work from the records and observations elsewhere in
the Privacy section. It is also used as the dashboard experience for privacy-focused organizations.
Data map
Systems, datasets, activities, and data-flow relationships.
RoPA
Review and approve records of processing activities.
Review queue
Reconcile observed access with declared processing.
Assessments
Document DPIA and data-protection assessment decisions.
Monitoring
Observe website consent, trackers, storage, and transport behavior.
Connected apps
Review third-party OAuth/SSO grants and vendor registration.
Settings
Define controller context, regulations, regions, and security measures.
What the overview tells you
- Article 30 ready: records that are approved, complete for conditionally required fields, in date, and unchanged from their approval snapshot.
- Risk score: a prioritization signal from the current privacy facts, not a legal compliance opinion.
- Needs your attention: drift, changed approvals, missing legal bases, overdue reviews, connector proposals, unowned records, assessment recommendations, and pending AI drafts.
- Sites at risk: monitored sites whose latest comparable scan requires attention.
- Systems mapped: the current technical processing inventory.
- Processing profile: sensitive data, international transfers, sale/sharing, targeted advertising, and profiling indicators declared by the current activities.
- Evaluation scope: covered regulations and data-subject regions configured in Privacy Settings.
Use overview cards as links into the source register. A zero can mean “no issue observed,” but it can also mean “no source connected” or “not configured.” Confirm coverage before drawing conclusions.
The privacy operating loop
- Define the legal entity, roles, regions, regulations, and security measures in Settings.
- Connect sources or push manifests to build the technical data map.
- Review derived processing records and add legal/organizational judgment in RoPA.
- Reconcile connected-app observations and connector proposals in the Review queue.
- Complete assessments for high-risk processing and link risks/evidence.
- Monitor public sites and route repeatable issues into remediation work.
- Re-review approved records whenever source facts drift or the review date arrives.
Privacy laws depend on jurisdiction, role, context, scale, and interpretation. Noru helps maintain records and evidence but does not determine which law applies or replace qualified privacy counsel.