DPO Quickstart¶
This guide walks you through configuring Dxtra as your compliance management platform. You'll review AI-generated assessments, configure processing activities and legal basis, set up breach reporting workflows, and manage data subject rights — all from a single dashboard.
Prerequisites
Your organization should have an active Dxtra account with a generated privacy program. If the initial setup hasn't been completed, start with the Business Owner Quickstart.
What you'll accomplish¶
- Review AI-generated Data Protection Impact Assessments
- Configure processing purposes and legal basis
- Set up breach and incident reporting
- Configure data subject rights management
- Grant auditor and regulator access
- Generate compliance reports
Step 1: Review your assessments¶
Sign in to app.dxtra.ai and go to Assessments in the left sidebar. Dxtra's AI generates several types of assessments based on your organization's profile and processing activities:
- Data Protection Impact Assessments (DPIAs) — Required under GDPR Article 35 for high-risk processing
- Transfer Impact Assessments (TIAs) — For international data transfers
- Legitimate Interest Assessments (LIAs) — When legitimate interest is your legal basis
- Algorithmic Impact Assessments — For AI/ML processing activities
- Vendor Risk Assessments — For third-party data processors
Each assessment includes an activity description, risk level rating, identified data categories, specific risks and vulnerabilities, and recommended safeguards.
Review and approve an assessment¶
- Click on any assessment to open the detail view
- Review each section — the AI populates these based on your questionnaire answers and industry context
- Click Edit to update any section that doesn't accurately reflect your processing
- Add notes about safeguards you've already implemented
- Click Save, then Approve when satisfied
Keep assessments current
DPIAs are living documents. When your processing activities change — new data categories, new vendors, new jurisdictions — revisit and update the relevant assessments. Dxtra flags when assessments may need review based on changes you make elsewhere in the platform.
Step 2: Configure processing purposes and legal basis¶
Go to Purposes in the left sidebar. This is the core of your Article 30 compliance record. The AI has generated your initial processing purposes based on your industry context and questionnaire answers.
Review generated purposes¶
The Purposes page organizes your data into three views:
- Tracked Data
- Data automatically observed, inferred, or generated through user behavior or system activity (analytics data, browsing patterns, device identifiers, etc.)
- Received Data
- Data explicitly provided by users during account setup, service usage, or customer interactions (names, email addresses, payment details, etc.)
- Legal Basis
- The legal justification for each processing activity across all applicable jurisdictions
Configure a processing purpose¶
Each purpose includes an expandable detail section. Click on any purpose to view and edit:
- Purpose name — A clear description of the processing activity (e.g., "E-Commerce and Online Retail", "Marketing (Non-Targeted)")
- AI-generated description — A detailed narrative of how and why you process data for this purpose. The AI generates this from your industry context — review for accuracy and edit as needed
- Data categories — The types of personal data involved (identifiers, contact details, financial data, behavioral data, etc.)
- Legal basis — Select the applicable basis for each jurisdiction:
- Consent
- Contract
- Legal Obligation
- Vital Interests
- Public Task
- Legitimate Interests (with linked LI Assessment)
- Retention period — How long data is kept for this purpose
- Recipients — Third parties who receive data for this purpose
- International transfers — Whether data crosses jurisdictional boundaries
Click Save after making changes to any purpose.
Add a new processing purpose¶
If the AI missed a processing activity or you've added a new one:
- Click Add Purpose
- Fill in the purpose details
- Select the applicable legal basis for each jurisdiction
- Click Create
Be thorough
Regulators expect processing records to be comprehensive. Document every way you use personal data, including internal HR processing, analytics, customer support, and marketing — not just the obvious customer-facing activities.
Step 3: Set up breach and incident reporting¶
Go to Breach & Incident Reporting in the left sidebar. Dxtra provides a structured workflow for handling data breaches from detection through resolution.
Configure your breach response plan¶
The AI generates a breach response procedure based on your jurisdictions. Review and customize:
- Detection and notification chain — Who gets notified first when a breach is detected (security team, DPO, legal, leadership) and through what channel
- Assessment criteria — How severity is determined (data categories compromised, number of data subjects affected, likelihood of harm)
- Authority notification — Which supervisory authorities to notify, auto-populated based on your operating regions
- Data subject notification — When and how to notify affected individuals
Report an incident¶
When a breach occurs:
- Go to Breach & Incident Reporting → Report Incident
- Fill in the incident details:
- Date and time of discovery
- Data categories affected
- Estimated number of data subjects involved
- Description of the incident
- Steps already taken
- Dxtra calculates which authorities require notification based on your jurisdictions
- The system generates a pre-populated breach report
- Review, finalize, and submit the report
- Dxtra tracks notification deadlines and sends reminders
Deadline tracking
GDPR requires notification to supervisory authorities within 72 hours of becoming aware of a breach. CCPA requires notification in the most expedient time possible. Dxtra tracks these deadlines automatically and sends escalation alerts as they approach.
Step 4: Configure data subject rights management¶
Go to Rights Management in the left sidebar. Dxtra supports all major data subject rights and provides a structured workflow for each.
Available rights¶
The Rights Management page shows which rights are enabled:
| Right | GDPR | Status |
|---|---|---|
| Right of Access | Art. 15 | Enabled |
| Right to Rectification | Art. 16 | Enabled |
| Right to Erasure | Art. 17 | Enabled |
| Right to Restriction | Art. 18 | Enabled |
| Right to Data Portability | Art. 20 | Enabled |
| Right to Object | Art. 21 | Enabled |
| Right to Not Be Subject to Automated Decision-Making | Art. 22 | Enabled |
Dxtra also detects Global Privacy Control (GPC) signals, allowing data subjects to opt out of data sales and sharing automatically.
Configure the rights request form¶
Dxtra generates a Data Subject Rights Request form that appears on your Transparency Center. The form includes:
- A dropdown for selecting the request type (access, erasure, rectification, portability, objection, opt-out)
- Identity verification fields
- A free-text field for additional context
You can embed this form on your website or link to it from your Transparency Center. Go to the form configuration section and choose Link (for a direct URL) or Embed / Preview (for an embeddable code snippet).
Handle incoming requests¶
When a data subject submits a request:
- You receive a notification in the dashboard and via email
- The request appears in Rights Management → Requests with its type, submission date, and deadline
- Verify the requester's identity using the configured verification method
- Process the request (retrieve data, delete records, correct information, etc.)
- Respond to the data subject within the applicable deadline
- Mark the request as resolved
Dxtra tracks deadlines automatically: one month for GDPR (extendable to three months for complex requests) and 45 days for CCPA (extendable to 90 days).
Step 5: Grant auditor and regulator access¶
Go to Settings → Team to manage access for external auditors.
- Click Invite Member
- Enter the auditor's email address
- Assign the Auditor role — this provides read-only access to:
- Processing activity records
- Assessment documentation
- Breach logs and resolution records
- Consent records (aggregated)
- Data retention schedules
- Rights request logs
- Set an access expiry date
- Click Invite
The auditor receives a secure login link. They can view compliance documentation without editing it, and you can revoke access at any time.
Audit preparation
Before an audit, use the reporting features (see next step) to generate a compliance package. This saves auditors time and demonstrates your organization's commitment to transparency.
Step 6: Generate compliance reports¶
Go to Assurance in the left sidebar to access Dxtra's reporting and compliance dashboard. Available reports include:
- Processing Activities Inventory
- A complete Article 30 record of all data processing activities, exportable as PDF
- Assessment Summary
- All DPIAs, TIAs, LIAs, and vendor risk assessments with their status and findings
- Breach Log
- A chronological record of all reported incidents, actions taken, and resolutions
- Data Subject Requests Log
- All rights requests received, their type, response time, and outcome
- Consent Records
- Aggregated consent statistics across consent categories, with grant/withdrawal trends
- Processor Compliance Status
- All data processors, their agreement status, and compliance posture
Each report can be filtered by date range and exported as PDF for submission to regulators or auditors.
What you just did¶
- Reviewed AI-generated Data Protection Impact Assessments and other compliance assessments
- Configured processing purposes, data categories, and legal basis for each jurisdiction
- Set up breach and incident reporting with deadline tracking
- Configured data subject rights management with an embeddable request form
- Granted read-only access for auditors and regulators
- Generated compliance reports for audit readiness
Next steps¶
- Onboard your data processors
- Review and configure agreements with every third party that processes personal data on your behalf. See Processor Management.
- Set up consent management
- Configure consent forms and banners for your digital properties. See Consent Management.
- Enable PII scanning
- Discover personal data across your connected systems and file storage. See PII Scanning.
- Invite your team
- Add legal, security, and support team members with appropriate role-based access. Go to Settings → Team → Invite Members.
- Schedule regular reviews
- Set a recurring calendar reminder to review processing activities, update assessments when practices change, check breach logs, and verify consent compliance. Monthly is recommended.
Key compliance deadlines¶
| Obligation | Deadline | Jurisdiction |
|---|---|---|
| Breach notification to authorities | 72 hours | GDPR |
| Breach notification to data subjects | Without undue delay | GDPR |
| Data subject access request response | One month (extendable to three months) | GDPR |
| Consumer rights request response | 45 days (extendable to 90) | CCPA/CPRA |
| DPIA required before processing | Before high-risk processing begins | GDPR Art. 35 |
Dxtra tracks all applicable deadlines and sends reminders as they approach.
Not legal advice
AI-generated content does not constitute legal advice. Consult a qualified legal professional for advice specific to your jurisdiction and business context.