The Evidence Standard
A privacy decision
is only as strong as
its follow-through.
For the CIO, CISO, and General Counsel, the task is to connect the requirement, the data, the decision, and the result. Kestryl Cockpit for USA brings that work into one operating view without confusing technical evidence with legal judgment.
01 The management problem
A request can be closed before the underlying work is complete.
A closed ticket is an administrative fact. It does not, on its own, establish which systems were searched, which copies were checked, what changed, or why something was retained. A board needs an answer to those questions before it can rely on the status.
Consider a business with a customer record in Salesforce, a copy in a warehouse, and related documents in a shared library. A decision made in Salesforce does not establish the state of the other copies. That is an illustrative operating problem, not a customer result: the distance between a decision and its follow-through.
The investment question is therefore broader than whether a tool can find personal data. Can the organization keep the scope, decisions, actions, and exceptions together as the data moves between teams and systems?
The board needs to know what the status means, not merely what color it is.
02 The investment thesis
One operating view. Not one assumed answer for every state.
The USA cockpit provides a fifty-state view of the records, requests, and matters in scope. It associates records with a state, retains the basis for that association, and makes unresolved records visible. That is useful evidence for legal review, not a determination that a particular law applies.
Deadlines, rights, extensions, and other legal settings come from a cited, versioned table approved by counsel. Historical work keeps the version used at the time. A change in those settings need not erase the basis on which an earlier request was handled.
This is the foundation of an accountable operating model: common ways to organize work, combined with requirements that remain specific to the relevant situation. Uniform workflow must not become uniform legal assumptions.
03 Why this foundation
Use the integration investment. Do not confuse connection with coverage.
For organizations using Informatica IDMC, the Secure Agent provides the starting point for bringing approved source data into a customer-controlled working environment. Kestryl adds discovery, review, approved treatment, and the evidence record. The cockpit makes that work accessible to privacy and business owners.
The supported source set includes Salesforce, SAP S/4HANA and ECC, SAP SuccessFactors, SAP Ariba, Oracle E-Business Suite, Oracle NetSuite, Microsoft Dynamics 365, ServiceNow, Workday, and SharePoint Online. Attachment retrieval brings supported documents into the agreed scope.
The economic case is a design rationale, not a quantified return promised here: reuse established integration and review processes rather than maintaining a separate account of the same data for every privacy workflow. The cost of onboarding each source still depends on permissions, extraction, document access, and the relationships that must be supplied.
A connection opens the door. A defined scope makes the resulting evidence useful.
04 What leadership receives
Ten outcomes, without a blanket compliance claim.
The cockpit brings ten named privacy outcomes into a common record. They cover discovery, downstream follow-through, incident scoping, retention, and evidence. They do not replace legal interpretation or the customer’s obligations.
| No. | Business outcome | What the cockpit brings together |
|---|---|---|
| 01 | Know what you hold | Inventory personal data in the connected systems and documents within scope. |
| 02 | Find sensitive data | Bring candidate sensitive categories and potential minors’ records into human review. |
| 03 | Track known copies | Follow the downstream relationships your team supplies or imports from its data catalog. |
| 04 | Scope a rights request | Locate records and linked documents using the identifiers provided for the individual. |
| 05 | Check deletion follow-through | Compare system-of-record confirmations with follow-up findings across known copies. |
| 06 | Check opt-out follow-through | Compare recorded preferences with permissions still present in downstream data. |
| 07 | Understand provenance | Record marketing sources, vendor relationships, and customer-declared broker status. |
| 08 | Scope an incident | Organize affected records by state and category to support the response team. |
| 09 | Make retention accountable | Associate retention decisions with a purpose, an owner, a review date, and exceptions. |
| 10 | Assemble reviewable evidence | Bring findings, decisions, actions, and outstanding issues together by state or matter. |
Rights requests use the identifiers supplied for an individual to filter the in-scope search and associated documents. That does not establish complete identity resolution across unknown identifiers. Downstream checks use declared relationships or available catalog lineage; the scanner does not discover the entire copy network on its own.
05 Approved remediation
Be precise about what changed, where, and under whose authority.
Mask, Vault, and Strip offer different treatments for an approved value. Mask replaces it with a protected representation. Vault retains an encrypted original for authorized recovery. Strip removes it from the approved working output without vault-based recovery. Each action requires approval, a defined scope, and the applicable hold checks.
Recovery requires the correct key and retained encrypted record; a changed target or unavailable key can prevent restoration.
Mask, Vault, and Strip apply to approved structured working data and supported document copies. The document scope includes Word, Excel, PowerPoint, OpenDocument, email, archives, and supported text and data formats, subject to the limits of each format.
Supported document actions produce a separate cleansed copy. Original files are not overwritten. PDFs, scanned pages, images, and legacy Word .doc files remain discovery-only; audio and video handling is limited to supported metadata and tags.
These document boundaries follow the current Kestryl product description; keyed restoration into a database cell or cleansed document copy is described on the Security page. The USA cockpit’s working-data actions must still be distinguished from execution in the original business system.
Do not equate a protected copy with completed erasure
Source records, original files, backups, and historical database pages can remain. Source-system actions and the follow-up evidence are separate parts of the workflow. Counsel determines what is required and what must be retained.
06 Where responsibilities meet
Keep the hand-offs visible.
| Workstream | Cockpit contribution | Responsibility retained elsewhere |
|---|---|---|
| State-level requirements | Record associations, unresolved cases, cited settings, and the version used. | Counsel determines applicability and approves legal settings. |
| Opt-outs and consent | Compare recorded signals and permissions across known copies. | Consent tools receive the signals and maintain consent status. |
| Source-system action | Coordinate scope and retain available execution and follow-up evidence. | Source systems execute deletion, correction, and other native actions. |
| Incident response | Scope selected records and files by state and category. | The response team and counsel decide reportability and send notices. |
| Sensitive categories | Flag candidates and record the review basis. | Reviewers resolve inferences; a detected pattern does not establish consent. |
| Broker and vendor data | Retain declared provenance and broker flags. | The customer and counsel determine broker status and contractual duties. |
| Consent-order obligations | Track owners, dates, terms, status evidence, and supporting packs. | Counsel assesses the obligation and whether its terms have been met. |
These are operating boundaries, not footnotes. They identify where a hand-off requires evidence and prevent one team’s completed task from being presented as an end-to-end legal conclusion.
07 Financial discipline
Fund a control objective, not an unverified savings claim.
The board should evaluate the investment against the work it needs to control: finding in-scope data, coordinating reviews, following decisions into known copies, and assembling a reliable response. A product capability is not a quantified reduction in legal exposure.
Before commitment, ask for the full cost of the deployment: integration and source access, document extraction, legal-setting maintenance, security and key custody, operating ownership, and the evidence review process. Ask what remains manual and what depends on another platform.
Set a baseline for the chosen workflow. Measure time spent on discovery and review, unresolved state assignments, known copies awaiting follow-up, overdue work, and missing execution evidence. These are suggested management measures, not results claimed for Kestryl.
A defensible business case begins with the work to be controlled and the evidence required to close it.
08 A durable foundation
Change the requirements without losing the record.
No product can guarantee readiness for every future law or enforcement position. A more credible objective is to maintain a working model that can absorb new requirements while preserving how earlier decisions were reached.
The cockpit preserves versions of legal settings and the settings associated with historical work. New sources can be added to the scope, and additional known-copy relationships can be recorded. Those changes require review and validation; they are not merely cosmetic updates to a dashboard.
For organizations using both the USA and DPDP cockpits, the value is a shared product family and a familiar operating approach. Regional requirements and approval decisions remain separate. The USA pages do not import India’s request or notice clocks.
09 The buying decision
Three questions worth asking before deployment.
What exactly is in scope?
Name the systems, fields, supported document formats, known copies, and identifiers the workflow will use. Record the exclusions. A list of connector names is not an acceptance test.
Who decides, and who acts?
Name the people who approve legal settings, resolve ambiguous findings, check holds, authorize actions, and accept evidence. Distinguish cockpit actions from those executed in the source systems.
What would make us accept the result?
Agree an end-to-end test using authorized data and the customer’s workflow. Check the unresolved cases, a held record, a supported document copy, a discovery-only file, an outstanding downstream copy, and the resulting evidence pack. Establish actual performance on the deployed configuration rather than relying on a target.
Availability and accountability
Kestryl Cockpit for USA is generally available. Source permissions, legal settings, document support, and operating responsibilities are confirmed for each deployment. Technical evidence supports customer and counsel review; it is not a representation of legal compliance.
Put one priority workflow in front of the right decision-makers.
Bring privacy, legal, security, and data leadership to the same briefing. Define what must be found, what may change, who approves it, and what evidence is required before the work is closed.
GENERALLY AVAILABLE · CUSTOMER DECISIONS · REVIEWABLE EVIDENCE