Privacy Review for New Features
Every launch privacy-reviewed
Every product team wants to ship faster; every privacy review takes 3-6 weeks and becomes a blocker they route around. Features quietly launch with PII collection that legal didn't see; the DPO learns about it during a customer question or an incident. By then the data is collected, mapped to systems that weren't privacy-cleared, and pulling it back means a migration nobody has time for.
An hour-by-hour walkthrough.
Step by step.
- 01
Detect feature-launch records + parse scope
Read feature-launch records from Jira / Linear / Notion. Classifier identifies privacy-relevant features (PII collection, cross-border transfers, third-party data sharing, retention beyond baseline).
Jira · Linear · Notion · Privacy-relevance classifier - 02
Draft the Privacy Impact Assessment
PIA template: data types, flows, retention, legal basis, cross-border, user-rights impact. Draws from the launch description + system design docs + similar prior features. Highlights novel elements.
Reasoning · PIA template · Historical PIA library - 03
Cross-reference DSAR / retention / consent updates needed
New data types may require: DSAR playbook updates, retention rule additions, consent banner updates, subprocessor list additions, DPA amendments. Lex flags each; approval carries the update-list.
DSAR runbook · Retention policy · Consent management · Subprocessor list - 04
Legal review + conditional approval
Legal reviewer approves as-drafted, requests changes, requires conditions, or blocks pending significant redesign. Conditions tracked to fulfilment before approval marked complete.
Web UI · Slack · Teams · Approval flow - 05
Verify conditions + release for launch
Conditions verified: consent banner updated, DSAR runbook updated, subprocessor list updated. Feature-launch record marked privacy-approved. PIA filed for audit. Post-launch scan for scope creep.
Consent management · DSAR runbook · Subprocessor registry · Audit log
What you connect to make this run.
Jira · Linear · Notion · Product management
read+writeFeature-launch records with launch descriptions + design docs. Read for scope; write privacy-approval status + PIA link so launch gates cannot pass without approval.
OneTrust · TrustArc · Consent management
read+writeConsent-banner state + user-consent records. Verify banner updates for new data types; ensure consent records propagate to the systems consuming the data.
Retention policy · Subprocessor registry
read+writeRetention rules per data type; subprocessor list of third parties processing data. Updates required for launch flow through here + reflected in customer-facing DPA amendments.
PIA library · Compliance documentation
read+writeHistorical PIAs + compliance analysis. Similar prior features surface as reference; new PIA becomes reference for future similar features. Compounds over time.
Before and after, honestly.
Playbooks that pair with this one.
Data Subject Request Routing
New features may add DSAR-relevant data types; runbook updated as part of approval.
Privacy / Data Deletion
Deletion inventory updated to include new systems from launched features.
Vendor Security Review
New subprocessors require vendor security review + DPA before launch.
Answers about this playbook.
What if the feature doesn't collect PII (pure computational feature)?
Fast-track review: Lex classifies non-privacy-relevant, files a lightweight record noting the classification with reasoning, and marks approved automatically. Reviewer can spot-check the classification.
How does it handle features that use AI / LLMs?
AI-specific PIA questions: model provider, data sent to model, model retention policy, training-use permissions, cross-border transfer of prompts. Modern PIA templates include these; older ones being updated as we encounter each pattern.
Can it review third-party integrations we plug in?
Yes — third-party integration is a special feature type. Vendor security review + DPA + subprocessor addition all flow from the same trigger.
What about features that change scope after launch?
Post-launch scope changes require an amendment PIA. Product changes affecting data collection, retention, or sharing route to the same review flow with the prior PIA as baseline.
How does this interact with our internal launch process?
Privacy approval becomes a required gate in the launch process alongside security review + go-to-market readiness. Same launch record; parallel review streams.
See it run on your data.
Free plan, no credit card. Connect the systems this playbook needs and run it against a past event first.