Skip to content
Fig platform · prove

Privacy & Data ProtectionConnected to the bigger picture.

ROPA, DPIA, DSAR, consent management, breach notification, and Privacy by Design.

Professional reviewing business documents
What this means for your team
  • ROPA and Data Mapping
  • DPIA and DSAR
  • Consent and Breach
The practical difference

Privacy & Data Protection, with ownership and evidence.

Privacy compliance lives in spreadsheets and shared drives. DSAR responses miss statutory deadlines. Processing activities are undocumented. Breach notifications are assembled under pressure with incomplete data.

01

ROPA and Data Mapping

Maintain controller and processor processing records with fields relevant to Article 30, including purpose, lawful basis, retention and transfers. Review completeness and applicability with the responsible privacy team.

02

DPIA and DSAR

Structured DPIA screening and assessment linked to change management. Track subject access requests, applicable timelines, review, redaction and response decisions.

03

Consent and Breach

Track consent where it is the lawful basis, alongside other lawful bases and processing records. Breach workflows support risk assessment and notification timing after awareness; a human decides whether notification is required.

04

Privacy by Design

Project-level privacy assessments for new systems and changes. Data deletion and portability controllers. Legal hold management with retention exceptions. Personal data inventory linked to the asset register.

Inside Fig

See the work.
Keep the evidence.

This compliance controls view shows the wider Fig environment. Ask us to demonstrate privacy & data protection against your own requirements.

A tailored walkthrough lets you review the relevant workflows, supported connections and reporting before deciding whether Fig is right for your team.

See it in a demo
Fig Cyber Essentials control table showing declared, enforced and evidenced control strength
Fig mobile app Home screen showing framework compliance, monitoring coverage and device posture
Fig platform · Compliance controls
Built around your role

One platform. Different responsibilities.

Bring delivery, oversight and assurance together without losing sight of who owns the next action.

Colleagues working together with laptops in an office

MSPs & MSSPs

Deliver privacy compliance as a managed service. Multi-tenant ROPA, DSAR management, and breach notification across client portfolios.

Explore Fig for MSPs
Business team discussing shared priorities

In-house teams

Connect privacy, supplier and incident records. For a personal-data breach, assess the affected processing population across relevant systems and lawful bases, then record the awareness time, risk assessment and notification decision.

Explore Fig for organisations
Reviewing business records and supporting documentation

Compliance & audit teams

Complete evidence chain from processing activity registers through impact assessments, consent records, breach notifications, and deletion logs for GDPR, UK GDPR, and DORA compliance.

Discuss your requirements
A considered start

Evaluate the fit. Then agree the rollout.

Start with the outcomes you need. We will discuss scope, delivery and commercial terms with you before you commit.

  1. 1

    Tell us what matters

    Discuss your current approach to privacy & data protection, the teams involved and the requirements you need to meet.

  2. 2

    Review the workflows

    See the relevant features in a tailored demonstration. Confirm integration coverage, responsibilities and any configuration needed.

  3. 3

    Agree your next step

    Review the proposed scope and pricing. Set implementation priorities, ownership and review points around your organisation or client portfolio.

Platform functionality and automation depend on the agreed scope, configuration and connected systems. Software supports your compliance programme; it does not replace an independent assessment or guarantee certification.

Before you decide

Your questions, answered.

Need to discuss a specific requirement or client scenario?

Speak to Fig
Does this replace OneTrust?

Compare the ROPA, DPIA, DSAR, consent, cookie, vendor and breach workflows you actually use, including integrations and package scope. Fig Group may cover selected privacy governance needs or work alongside a specialist service.

How does breach notification work?

Record when the organisation became aware of a suspected personal-data breach, link the affected processing activities and investigate people affected across all relevant sources, including processing that does not rely on consent. A responsible reviewer assesses risk, jurisdiction and exemptions, then decides whether and when to notify.

Can we manage DSARs through Fig Group?

Yes. Subject access requests are tracked from intake through to response with statutory deadline monitoring. Response workflows include data gathering, review, redaction, and delivery with full audit trails.

How does Privacy by Design integrate with change management?

A flagged change can trigger privacy screening before approval. A qualified reviewer decides whether the proposed processing is likely to be high risk and needs a DPIA, then records the assessment and any required actions.

Does this cover UK GDPR as well as EU GDPR?

Yes. Fig Group supports both UK GDPR and EU GDPR requirements, including the differences in supervisory authority notification, data transfer mechanisms, and lawful basis documentation.

Take the next step

See how privacy & data protection could work for you.

Tell us what you would like to achieve. We will arrange a relevant conversation about the platform, your requirements and the right next step.

  • A walkthrough focused on your priorities
  • Clarity on scope, connections and delivery
  • A discussion of pricing for your requirements

Speak to Fig

Tell us what you need. We’ll help you take the next step.

A brief message is all we need to get started.