4

Settings

Organisation profile, people, modules and the integrations that feed them.

Delivery

How non-urgent notifications reach people. Critical rules always deliver immediately regardless of this setting.

Rules (13 of 14 enabled)

Each rule exists because a statutory clock or an obligation exists. The clause chips make that link explicit.

  • Critical
    Board notification deadline approaching48h / 24h / 12h / 4h

    Fires at 48, 24, 12 and 4 hours before the 72-hour deadline for an open personal data breach. Escalates to the DPO and the Principal Secretary at 12 hours.

    In-appEmailSMSS.8(6)R.7
  • Critical
    Incident not acknowledged within one hour60 minutes

    The 24x7 acknowledgement SLA. Pages the on-call incident lead.

    In-appSMSTeamsS.8(6)
  • High
    Rights request approaching the statutory period70% of window

    Fires when a request reaches 70% of its response window, and again on the day it becomes overdue.

    In-appEmailS.11S.12R.13
  • High
    Grievance escalation60% of window

    Fires at 60% of the published grievance response period, because the published period binds the organisation.

    In-appEmailS.8(10)S.13
  • Critical
    Children's data detected in a new location

    Any scan that classifies new elements as children's personal data in a source not previously known to hold it.

    In-appEmailS.9R.10
  • Critical
    Access to data with withdrawn consent

    Any attempt to read an element whose consent has been withdrawn and which is queued for erasure.

    In-appSIEMS.6S.8(7)
  • Critical
    Mass read on a classified table> 10,000 rows

    Row volume exceeding the policy threshold on any table containing personal data.

    In-appSIEMTeamsS.8(4)R.6
  • Critical
    DLP incident classified as a potential breach

    Automatically proposes escalation to Breach Response, which starts the 72-hour clock.

    In-appEmailTeamsS.8(6)R.7
  • High
    Processor agreement expiring60d / 30d

    Fires 60 and 30 days before a Data Processing Agreement expires.

    In-appEmailS.8(1)R.6
  • Medium
    Evidence expiring45 days

    Fires 45 days before an evidence document passes its validity date.

    In-appS.28
  • Medium
    Retention item awaiting approvalDaily digest

    A daily digest of erasure items queued for a data owner's decision, including the Rule 8 advance-notice window.

  • High
    New regulatory publication

    MeitY circulars, Board notifications, Gazette amendments and sectoral guidance affecting an active clause.

    In-appEmailS.27
  • High
    Shadow AI detected

    A new unsanctioned AI service observed receiving personal data.

  • Medium
    Connector failure24 hours

    A discovery connector failing for more than 24 hours, because an unmonitored source is a blind spot in every downstream module.

    In-appEmailS.4