Assurance¶
The Assurance page provides a compliance health overview for your organization. It displays 12 scoring cards, each representing a key area of privacy compliance. Use this dashboard to identify strengths and gaps in your privacy program at a glance.
URL path: /data-controllers/{id}/dashboard/assurance
Access: Select Assurance in the left sidebar.
Assurance cards¶
The Assurance dashboard displays the following 12 compliance areas:
- Data Governance — Organizational policies, leadership, and governance framework supporting data protection.
- Lawful Basis & Purpose — How your organization establishes and documents the legal basis for each processing activity.
- Rights Management — Your readiness to handle data subject rights requests across all applicable rights.
- Consent Management — Configuration and tracking of consent categories, collection, and withdrawal.
- Data Protection — Technical and organizational measures protecting personal data (encryption, access controls, etc.).
- Breach Management — Preparedness for detecting, reporting, and responding to data breaches.
- International Transfers — Safeguards for transferring personal data across borders.
- Accountability — Evidence of compliance activities, documentation, and audit readiness.
- Transparency — How effectively your organization communicates data practices to data subjects.
- Data Minimization & Retention — Controls ensuring you collect only necessary data and retain it only as long as required.
- Third Party Management — Oversight of data processors, sub-processors, and third-party relationships.
- Employee Training & Awareness — Staff training programs and awareness initiatives for privacy compliance.
Each card shows a compliance score for its area. The score reflects how fully you have configured and maintained that area of your privacy program — for example, whether you have documented processing purposes, configured consent categories, enabled rights management services, or completed required assessments.
How scoring works¶
Assurance scores are calculated based on the completeness and currency of your privacy program configuration within each area. Factors that contribute to a score include:
- Whether required settings are configured (e.g. active consent categories, enabled rights services, documented processing purposes)
- Whether documents have been generated, reviewed, and approved (e.g. privacy notices, DPIAs, processor agreements)
- Whether ongoing obligations are being met (e.g. rights requests responded to within deadlines, breach reports filed on time)
- Whether supporting infrastructure is in place (e.g. Tag Manager deployed, Transparency Center published, team roles assigned)
Scores update automatically as you make changes in Dxtra. A low score in an area indicates configuration gaps or overdue actions — select the card to see what specific items need attention.
Note
Assurance scores measure the completeness of your Dxtra configuration, not the legal sufficiency of your privacy program. A high score means you have configured Dxtra thoroughly; it does not constitute a legal compliance certification. Consult a qualified legal professional for compliance advice specific to your jurisdiction.
Related¶
- Assessments — Run DPIAs, transfer impact assessments, and vendor risk assessments
- Compliance Issues — Track and resolve compliance issues
- Processor management — Manage third-party data processors