Capture
Start with the facts your team already knows. Import the rest as the record grows.
Run privacy work across every client and legal entity with one clear record of what they do, who owns it, and how every decision was made.
Designed for DPOs, privacy-service providers, and their client teams.
A client’s processing activity is not a row in isolation. It connects to people, systems, vendors, risks, actions, and evidence. GDManager keeps those connections visible.
One activity. Every relationship.
Review in progressStart with the facts your team already knows. Import the rest as the record grows.
Link owners, vendors, risks, tasks, decisions, and documents to the work they support.
See what changed, what needs review, and which evidence supports each decision.
Start with each client entity’s core privacy record, then add governed workflows without rebuilding the same owners, tasks, and evidence.
Capture processing activities, systems, vendors, lawful bases, retention, and safeguards as connected facts.
RoPA · data map · vendorsLink assessments and risks to an owner, a decision, a due date, and the evidence needed to close the work.
DPIA · LIA · risk treatmentTrack requests and incidents with deadlines, review history, notification decisions, and report-ready evidence.
DSR · breaches · reportingGDManager is designed to keep generated suggestions separate from human answers and approvals. Every accepted or overridden decision retains its rationale.
Suggestions stay clearly labelled
Source records remain visible
Human review changes legal status
Request the processor’s updated sub-processor list before completing this review.
Example interface · Product direction
Privacy software should protect the records it asks you to centralise and keep every client inside the right entity boundary. These principles guide GDManager’s product and infrastructure decisions.
GDManager is in development. Join the pilot conversation and tell us which client privacy workflow costs your team the most time.