Consent and purpose defined in policy.
Privacy, legal, and compliance
See where behaviordiverges from policy.
Compare sensitive-data movement with consent, GPC signals, disclosures, contracts, approved purposes, and regulatory obligations.

Decision view
Policy says one thing. The recipient chain shows another.
Place the documented promise beside the observed request, recipient, and consent state so counsel can focus review on the material difference.Additional service receives sensitive data.
Focus counsel on the material difference.
Map sensitive-data behavior
Follow personal, account, health, transaction, session, device, and credential data through direct and downstream recipients.
- Raw and transformed data
- Recipient ownership and role
- Purpose and geography context

Validate consent controls
Compare what happens before and after reject, accept, no-action, and GPC states to determine whether privacy mechanisms change data sharing as intended.
- Consent-state comparison
- GPC signal response
- Pre-consent transmission

Compare behavior with obligations
Review observed paths against disclosures, contracts, approved uses, retention expectations, data-residency requirements, and regulatory frameworks.
- Stated-versus-observed gaps
- Vendor and subprocessor review
- Regulatory context

Preserve the decision record
Keep each issue connected to its supporting observation, owner, remediation decision, policy update, and evidence refresh.
- Review-ready evidence
- Accountable remediation
- Historical change record

Data Risk Review
See where data movement diverges from policy.
Request a privacy and compliance evidence review.
Compare policy with behavior Start with one policy, customer journey, or vendor relationship.