TCPTCP OpsUser manual

TCP PRIVACY

User manual

Search the public TCP Privacy manual for PIMS, Operate, registers, evidence, Improve, backup & restore, billing and administration.

Current product state

  • Data backup combines Tenant Backup and Restore in one area. Tenant Administrators and Platform SuperAdmins can use this area.
  • Enterprise: Create and open the ISO/IEC 27701 GAP Report under Reports. There is no separate Assurance navigation area.
  • The GAP Report includes a management summary, prioritized actions and reader-safe evidence labels.
  • PDF output for new GAP reports is created server-/worker-side as an immutable report artifact. Reports created before R176 retain HTML and Word; create a new report to obtain an immutable PDF.
  • Assessment mappings are not part of customer navigation.
01Introduction and product understanding3

What is TCP Privacy?

All editions
#

TCP Privacy helps organizations build, operate and continuously improve a structured Privacy Information Management System (PIMS).

  • PIMS / Build creates and manages the documented privacy management system.
  • Operate executes recurring privacy processes in a structured way and updates the associated registers.
  • Improve supports effectiveness measurement, corrective measures and, depending on edition, assurance functions.

Build → Operate → Improve

All editions
#

The three product areas form one connected management cycle. Operational and Improve results can trigger a new PIMS revision.

  • Build defines the effective baseline.
  • Operate applies that baseline to concrete cases.
  • Improve evaluates effectiveness and initiates improvement.

ISO/IEC 27701 readiness – not automatic certification

All editions
#

TCP Privacy is designed to support structured preparation and evidence for ISO/IEC 27701. Using the software does not replace a certification body and does not guarantee certification.

  • Responsibility for actual implementation remains with the organization.
  • Certification decisions are made solely by the relevant certification body.
02Getting started / onboarding3

Registration and ESSENTIAL trial

All editions
#

New public registrations start with a one-month ESSENTIAL trial without requiring a payment method.

  • The trial ends on the same calendar day of the following month; if that date does not exist, it ends on the last calendar day of that month.
  • If a paid plan is purchased during the trial, the subscription starts immediately and the remaining trial time is forfeited.

First sign-in and navigation

All editions
#

After selecting the organization, the left navigation shows the areas available for the user's role, edition and product state.

  • Start with PIMS before relying on productive Operate processes as evidence.
  • Hidden functions may be caused by missing permissions, edition limits or unmet functional prerequisites.

Recommended first steps

All editions
#

A fixed sequence is recommended for a traceable start.

  • 1. Review organization and user details.
  • 2. Define roles and responsibilities.
  • 3. Complete the baseline situation and assessment for the first PIMS version.
  • 4. Generate, review and approve the required PIMS documents.
  • 5. Activate the PIMS version and then use Operate/Improve.
03Editions and feature scope3

ESSENTIAL, PROFESSIONAL and ENTERPRISE

All editions
#

The edition determines the functional product scope; organization size alone is not an edition criterion.

  • ESSENTIAL covers core PIMS and core Operate functions.
  • PROFESSIONAL adds further risk, transfer and deletion processes and CAPA.
  • ENTERPRISE adds advanced governance and assurance functions such as internal audits, management review and control tests.

Upgrading to a higher edition

All editions
#

Paid upgrades become effective after successful completion of the applicable payment or Enterprise process.

  • When expanding the edition, the existing PIMS version can be extended with newly required documents.
  • Newly added content must pass the applicable build and approval process before becoming effective together.

Downgrade at period end

All editions
#

Paid downgrades are scheduled for the end of the current billing period where the target change is permitted.

  • PROFESSIONAL → ESSENTIAL becomes effective at period end.
  • ENTERPRISE → PROFESSIONAL or ESSENTIAL also becomes effective only after the current ENTERPRISE period ends.
  • Until then, the current feature scope and price remain in effect; there is no prorated credit for the current period.
04Users, roles and permissions5

Role model

All editions
#

TCP Privacy separates technical permissions from functional responsibilities in PIMS, workflow and audit processes.

  • Tenant Administrator manages the tenant within the permitted scope.
  • Privacy system roles govern responsibilities such as owner, reviewer, approver or auditor.
  • Custom roles can represent additional tenant-specific permission models.

Invite users and assign roles

All editions
#

In Users and assignments, tenant administrators manage tenant members. A tenant invitation is accepted and activated only after the invited user successfully signs in to TCP Privacy.

  • The tenant administrator creates the invitation and defines the intended initial roles.
  • The invited user opens the invitation link and first completes account setup or sets the required password.
  • After successful account setup, the user is automatically redirected back to TCP Privacy.
  • The user then signs in with the invited email address and the password just created. Completing account setup or setting the password alone does not yet activate tenant access.
  • Only the successful sign-in completes the tenant invitation: the invitation is accepted, the tenant membership becomes active and the intended roles take effect.
  • Until that successful sign-in, the tenant administrator sees the status “Acceptance pending”.
  • After activation, roles can be assigned tenant-wide or, where supported, with a narrower scope, time-limited and revoked when the responsibility ends.
  • Temporary direct permissions are exceptional and should be granted only with a traceable reason and as narrowly as necessary.

Review access and temporary permissions

All editions
#

Access review shows effective role and permission assignments and supports controlled creation of time-limited direct ALLOW or DENY rules.

  • Review effective access especially when responsibilities change, users leave or exceptional permissions are required.
  • Direct permissions do not replace the regular role model and should not be used as permanent standard assignments.

Owner, reviewer and approver

All editions
#

Document and process approvals follow the governance profile applicable to the relevant document or workflow type.

  • The owner creates or is responsible for the functional content.
  • The reviewer performs an independent functional review where required by the profile.
  • The approver provides an additional approval where required by the governance profile.

Privacy auditor and audit manager

From ENTERPRISE
#

Internal audits use separate audit roles to distinguish execution from review.

  • The Privacy Auditor performs the fieldwork.
  • The Audit Manager performs the defined review responsibility.
05Create and operate the PIMS – Build5

PIMS version and baseline situation

All editions
#

A PIMS version bundles the baseline situation, structured selections and generated PIMS documents applicable to a specific state.

  • The baseline situation is stored per version.
  • An active PIMS version is not edited directly; changes are made through a revision.

Prerequisites for editing the first PIMS document

All editions
#

Before PIMS documents can be edited or generated, the organizational foundations for document governance must be fully set up.

  • First confirm the baseline situation of the current PIMS version.
  • For full standard document governance, TCP Privacy requires at least three additional active users besides the Tenant Administrator.
  • Owner, reviewer and approver must be fully assigned to different people. PIMS document editing is enabled only then.
  • This product-level separation of duties supports controlled document governance, independent review and traceable approval in an ISO/IEC 27701-oriented PIMS; it does not state that ISO/IEC 27701 literally requires three additional users.
  • Recommended sequence: invite users → assign the required Privacy roles → set up standard document governance → edit PIMS documents.

Assessment and document need

All editions
#

Assessment results support determining which PIMS content and documents are relevant to the tenant.

  • The document catalog is shown according to edition.
  • A document is treated as not required only once the assessment sources relevant to the need decision have been sufficiently evaluated.

Generate PIMS documents

All editions
#

PIMS documents are generated from structured product rules, confirmed tenant facts and the selections applicable to the version.

  • Generation is designed to be traceable and reproducible.
  • Changes to relevant inputs can require regeneration and renewed approval.

Activate a PIMS version

All editions
#

A PIMS version becomes effective only after the required current documents have been approved and the version is then explicitly activated.

  • Activation is a separate action and is not the same as approving an individual document.
  • The previously active version remains historically traceable and is superseded by the new version.
06Document control and approvals4

Approval profiles SIMPLE, STANDARD and ENHANCED

All editions
#

The Product Mapping defines a minimum and default document-control profile for each document type.

  • SIMPLE: owner completion without a mandatory independent reviewer or approver stage.
  • STANDARD: owner plus independent reviewer.
  • ENHANCED: owner, reviewer and an additional approver stage.

Sequence and dependencies of PIMS documents

All editions
#

The PIMS directory follows functional build stages. Documents in a later stage become editable only after the required preceding PIMS documents have been created and any other displayed prerequisites have been met.

  • If a required preceding document does not yet exist, TCP Privacy does not show an ineffective Edit button; it indicates that preceding documents must be created first.
  • Where possible, the action column identifies the specific preceding documents that are still missing.
  • The restriction is lifted automatically once the required preceding documents exist and the other functional prerequisites for the build stage are satisfied.
  • Later changes to facts, policies or governance can require regeneration or renewed approval of affected documents in a new PIMS revision.

Understanding document status

All editions
#

Document statuses show whether a document is still being worked on, already approved or effective within an active PIMS version.

  • DRAFT: work is in progress.
  • APPROVED: required approval completed, but not necessarily effective yet.
  • EFFECTIVE: part of the active PIMS version.
  • REVIEW_DUE: effective, but periodic review is due.

Start a new PIMS revision

All editions
#

Changes to an active PIMS baseline are made through a new or already open revision.

  • Affected documents can become subject to approval again after changes.
  • Only activation of the fully prepared revision replaces the previous effective state.
07Operate – execute privacy processes5

Operate basics

All editions
#

Operate executes concrete privacy cases using structured workflow blueprints. Questions, decisions, evidence and register effects are linked traceably.

  • The UI shows the current workflow phase and, where available, the position in the sequence.
  • Structured inputs are preferred over free text where functionally appropriate.

How Operate works

All editions
#

Operate applies the currently effective PIMS to concrete privacy cases. Each case starts with a specific workflow version and the effective PIMS document versions on which it is based, then proceeds step by step to the intended outcome.

  • When ‘Cases and registers’ is opened for the first time, TCP automatically sets up the Operate workflows required for the edition if none exist yet. Compilation runs sequentially in the background and progress is displayed.
  • If compilation of a workflow fails, the error is stored and setup continues with the next workflow. The failed workflow can then be started again manually using ‘Retry workflow’.
  • ‘Start case’ always uses the current effective workflow version. At the same time, TCP freezes the underlying effective PIMS document versions and the related PIMS context for that case.
  • At start, only case-specific data required by the workflow is requested. Responsible role, due dates and any intended register binding are determined by the effective workflow and are not freely overridden by the user.
  • The case is then processed step by step. TCP shows the current step, responsible role, work instruction, required questions, required evidence and the permitted next decisions or outcomes.
  • A step can only be completed when the required data, evidence and completion criteria defined by the workflow are satisfied. Negative decisions require a reason and can route the case into a defined rework step.
  • Where the process maintains a register, TCP creates a related draft register entry when the case starts. Workflow steps can add or update register data; at the intended completion the register state is finalized according to the workflow. If a case is cancelled, a related draft register entry is archived.
  • Later PIMS changes or newly generated workflow versions do not silently alter a case that has already started. The PIMS and workflow baseline frozen for the case is retained for traceability.

Core processes in ESSENTIAL

All editions
#

ESSENTIAL contains the core user-startable Operate processes.

  • New processing activity (NEW_PROCESSING_ACTIVITY).
  • Data subject request (DATA_SUBJECT_REQUEST).
  • Privacy breach (PRIVACY_BREACH).
  • Processor review (PROCESSOR_REVIEW).

Additional PROFESSIONAL processes

From PROFESSIONAL
#

PROFESSIONAL extends the Operate catalog with further structured review and lifecycle processes.

  • Data protection impact assessment (DPIA).
  • Transfer review (TRANSFER_REVIEW).
  • Deletion run (DELETION_RUN).

Additional ENTERPRISE processes

From ENTERPRISE
#

ENTERPRISE adds further governance processes in the Operate environment.

  • Privacy-by-design review (PRIVACY_BY_DESIGN_REVIEW).
  • Legal hold (LEGAL_HOLD).
  • Training assignment (TRAINING_ASSIGNMENT).
08Register management2

Registers as structured evidence

All editions
#

Registers consolidate structured results from PIMS and Operate processes and support continuous evidence management.

  • Entries can be created or updated by completed workflow steps.
  • The relevant register view shows the functional lifecycle and provenance of the data.

Review register data

All editions
#

Before completing a workflow, the intended register effects should be reviewed.

  • Automatically transferred data remains traceable to the underlying case.
  • Corrections should follow the intended functional process rather than uncontrolled overwriting of the evidence trail.
09Improve / effectiveness and audits4

Monitor effectiveness

All editions
#

Improve supports structured evaluation of whether the PIMS and its controls achieve the intended outcomes in operation.

  • Metrics and results are maintained with their associated product and control references.
  • Identified improvement needs can trigger follow-up activities or a PIMS revision.

Nonconformities and CAPA

From PROFESSIONAL
#

From PROFESSIONAL onward, nonconformities and corrective/preventive actions can be tracked in the NONCONFORMITY_CAPA process.

  • Actions are linked to responsibility, status and evidence.
  • CAPA provides traceable handling of identified deviations and improvement needs.

Internal audits

From ENTERPRISE
#

ENTERPRISE supports structured internal audits (INTERNAL_AUDIT) with planning, frozen scope/criteria, fieldwork, evidence assessment and review.

  • Audit criteria are selected from permitted TCP values rather than defined as uncontrolled free text.
  • Fieldwork is bound to the criteria frozen during planning.
  • Auditor and audit review are designed as separate governance roles.

Control tests and management review

From ENTERPRISE
#

ENTERPRISE extends Improve with assurance functions for control tests (CONTROL_TEST) and management review (MANAGEMENT_REVIEW).

  • Control tests document testing of defined controls and associated evidence.
  • Management review supports structured management evaluation of the PIMS.
10Reports and evidence2

Report types

All editions
#

TCP Privacy can generate versioned reports from the privacy data available in the relevant edition.

  • PIMS report: documented PIMS state.
  • Operate report: structured process and register information.
  • Effectiveness report: Improve/effectiveness results within the available scope.
  • Overall report: consolidated view across available areas.

Using reports as evidence

All editions
#

Reports support internal and external evidence purposes but do not replace an independent legal or certification assessment.

  • When sharing reports, consider the version, generation time and underlying PIMS state.
  • Exported reports should be handled in accordance with the organization's internal document-control rules.
11ISO/IEC 27701 readiness2

From PIMS creation to readiness

All editions
#

TCP Privacy supports a traceable path from the documented PIMS baseline through operation to improvement.

  • PIMS/Build: documented governance and control baseline.
  • Operate: traceable execution of recurring privacy processes.
  • Improve: effectiveness assessment and edition-dependent assurance.

Preparing for internal and external audits

From ENTERPRISE
#

The combination of an effective PIMS, registers, evidence, internal audits and management review can support preparation for a certification audit.

  • Before an external audit, open findings, overdue reviews and incomplete evidence should be addressed.
  • The certification body independently evaluates actual implementation and effectiveness beyond the software.
12Billing and subscription management3

Billing and billing periods

All editions
#

Paid plans are billed net in EUR on a monthly or annual basis. The billing period starts on the purchase date.

  • ESSENTIAL and PROFESSIONAL can be purchased through the designated online checkout.
  • ENTERPRISE is handled through an individual offer/contract process.

Payment methods

All editions
#

Available Stripe payment methods are managed in the billing process. For SEPA, the edition is activated after successful checkout and mandate creation.

  • A later failed debit can move the account to PAST_DUE.
  • Saved payment methods can be reused in supported upgrade processes.

ENTERPRISE offer and activation

From ENTERPRISE
#

ENTERPRISE is not offered as a standard self-service checkout. An individual offer and approval process follows the inquiry.

  • After approval, a personal Stripe payment link can be provided for monthly or annual billing.
  • Downgrades from ENTERPRISE become effective at the end of the already paid ENTERPRISE period.
13Invoices and tax information3

Billing profile

All editions
#

Paid B2B purchases require organization and billing data including country, VAT ID, invoice email and contact person.

  • Changes to billing data should be reviewed before the next billing-relevant transaction.
  • Customer billing data and seller data are maintained separately.

VAT ID and VIES validation

All editions
#

EU VAT identification numbers are checked against VIES for billing-relevant transactions.

  • VALID means the validation confirmed the number as valid.
  • INVALID means the number was not confirmed as valid in the performed validation.
  • PENDING can be used where a reliable final validation is temporarily unavailable.

Invoices, credits and proration

All editions
#

Plan changes can create invoices or credits depending on direction and timing. Deferred downgrades at period end do not create an immediate prorated credit.

  • Service periods are shown on the invoice.
  • Negative billing amounts are handled as appropriate credit documents.
14Privacy and security of TCP Privacy3

Tenant separation and access

All editions
#

TCP Privacy uses tenant-specific access contexts and permissions so users can access only the data and functions authorized for their tenant.

  • Roles and permissions are enforced server-side.
  • Administrative special privileges are handled separately from normal tenant memberships.

Sign-in and identity

All editions
#

Sign-in uses the identity methods provided by the product. A natural user identity should not be created multiple times as independent trial users across providers.

  • Protect individual user accounts and do not share personal credentials.
  • Remove or disable access as soon as it is no longer required for the tenant.

Shared security responsibility

All editions
#

TCP Privacy technical safeguards do not replace the customer's organizational security measures.

  • Customers remain responsible for correct user assignment, role allocation and handling exported data.
  • Security-relevant anomalies should be reported promptly through the designated support channel.
15Data export, cancellation and deletion3

Trial end and retention

All editions
#

After a trial that is not converted to a subscription ends, existing privacy data remains readable/exportable for the defined retention period before deletion.

  • The intended retention period is six months unless earlier deletion is requested.
  • Changes are disabled during a read-only phase.

Cancel a subscription

All editions
#

Cancellation generally becomes effective at the applicable period end unless the specific contract provides otherwise.

  • The currently paid feature scope remains available until the effective date.
  • A time-limited export phase may follow contract termination.

Export data and request deletion

All editions
#

Before final deletion, required evidence and data should be preserved using the designated export functions.

  • Requested earlier deletion can end existing recovery and export options.
  • Deleted tenant data cannot continue to be used as regular product data after completion of the designated deletion process.
16Administration of your tenant3

Manage users

All editions
#

Tenant administrators can manage users within their permissions and assign the required roles.

  • Grant only the permissions required for the relevant task.
  • Review roles regularly, especially when responsibilities or personnel change.

Maintain the organization structure

All editions
#

The organization structure represents legal and operational scopes that can be used, among other things, for role and permission assignments.

  • Legal entities represent legally independent companies within the tenant.
  • Organization units represent areas, departments or teams hierarchically.
  • Cost centers and projects can be maintained as additional functional scopes.
  • Changes should preserve the functional traceability of existing role and process assignments.

Organization and billing settings

All editions
#

Organization and billing data should be kept current because they are used in product and billing processes.

  • Changes to functional PIMS governance follow the designated PIMS revision process.
  • Platform administration is not a normal tenant function and is handled separately.
17Troubleshooting and FAQ3

PIMS cannot be activated

All editions
#

First check whether all documents required for the current revision are current, generated and fully approved.

  • Open reviews or approvals prevent activation.
  • Changes to baseline situation, policies or governance can reset existing approvals.

Workflow cannot be started or completed

All editions
#

Common causes are missing permissions, unmet PIMS prerequisites, edition restrictions or required decisions that are not yet complete.

  • Check messages in the workflow and the status of the active PIMS version.
  • For reproducible errors, document workflow type, phase and visible error message for support.

VAT, payment or plan change fails

All editions
#

Check billing country, VAT ID, payment status and any currently scheduled plan change.

  • An INVALID VAT ID can block billing-relevant checkout operations.
  • An already scheduled downgrade can prevent scheduling the same change again.
  • Deferred downgrades at period end are not new checkouts and should not be blocked by a renewed VAT checkout validation.
18Support and contact2

Prepare a support request

All editions
#

A good error description speeds up resolution and reduces follow-up questions.

  • State the tenant/organization, affected product area and time.
  • Describe the action performed and the visible error message.
  • Do not send passwords, secrets or full payment data.

ENTERPRISE contract and plan questions

From ENTERPRISE
#

Individual ENTERPRISE contract questions are handled through the designated Enterprise contact process.

  • A downgrade to PROFESSIONAL or ESSENTIAL can be scheduled in the product for period end.
  • Individual contract changes outside the standard plan-change flow remain subject to separate support.
19Release notes / What's new?2

Which changes are published?

All editions
#

Customer release notes describe visible new features, relevant behavior changes and important fixes.

  • Internal patch numbers, technical intermediate fixes and implementation details are not fully mirrored into customer documentation.
  • If a change requires customer action, that action is stated explicitly.

Current customer-relevant changes

All editions
#

The documentation is updated together with customer-relevant product changes.

  • ENTERPRISE downgrades to PROFESSIONAL or ESSENTIAL are scheduled for the end of the current ENTERPRISE period.
  • The public product positioning emphasizes ISO/IEC 27701 readiness and the PIMS lifecycle.
20Glossary and index3

Core terms

All editions
#

The following terms are used in a defined product context within TCP Privacy.

  • PIMS: Privacy Information Management System.
  • Tenant: organizationally and technically separated customer area.
  • Policy: structured normative product selection affecting PIMS content.
  • Fact: concrete tenant-determinable variable, not a normative rule.
  • Evidence: material supporting a statement, decision or assessment.
  • Workflow: structured sequence for handling a concrete privacy case.

Improve terms

From PROFESSIONAL
#

Improve uses additional terms for deviations and improvement actions.

  • Finding: documented observation from a review or assessment.
  • Nonconformity: identified nonconformity against an applicable requirement.
  • CAPA: Corrective and Preventive Action for structured action tracking.

Audit terms

From ENTERPRISE
#

Internal audits use a dedicated structured terminology.

  • Scope: defined audit scope.
  • Criteria: frozen audit criteria used during fieldwork.
  • Fieldwork: execution of the audit assessment and evidence evaluation.
  • Management review: structured management evaluation of the PIMS.
21Backup and restore2

Create and download a tenant backup

All editions
#

Tenant administrators can create and download the customer-side tenant data as a verifiable ZIP backup.

  • Creation runs asynchronously in the background while TCP Privacy shows the backup status.
  • The ZIP contains tenant-related inputs, uploads, generated artifacts, versions, relationships and metadata required for integrity and later restoration.
  • The completed ZIP remains available in private storage for 24 hours; each download link is valid only for a short period.
  • Only one current backup ZIP is retained per tenant. A new backup replaces the previous current backup.

Restore a tenant from a TCP backup

All editions
#

The tenant administrator can upload a valid TCP tenant-backup ZIP, validate it and selectively return functionally consistent areas to the backup state.

  • Restore means overwriting the selected area with the backup state; old and new data are not merged.
  • Dependencies between selected areas are validated before restore; inconsistent partial restores are blocked.
  • Before every destructive restore, TCP Privacy creates a mandatory full safety backup of the current tenant state. The safety backup is retained for seven days.
  • During restore, the tenant is locked against writes. Audit history remains append-only and is never overwritten or deleted by restore.
  • Global user identities and authentication data are not restored; tenant-specific roles and assignments can be part of the restore.