Enabling large companies like Flickr, Bolt build Products compliant with US state privacy laws
Customer problems & Project overview
How do you convert a laborious manual form filling activity into an exciting and seamless task like Typeform/Googleform? This project solved this esoteric challenge—as we are in principle making the customers designers.
In order to build a new product in large B2B/B2C companies, you have to do a Data Privacy Impact Assessment. This is one of the Data processing assessments to be made when dealing with personal data, and is to be submitted to the state Attorney-General.
In understanding the current state of affairs, we spoke at length with the lawyers, and privacy team at Transcend. We uncovered these user pain points:
It's a laborious process riddled with operational friction
The problem of ambiguity as each organization has different data processing needs.
Hence the need for a custom management tool where they can design their DPIAs, and other Assessment templates
Providing an answer to these questions involved giving the users these capabilities:
A Template editor/designer
Customer data request management portal
Assessments library
Role
Product designer, working directly with Product manager, & Senior designer, Jesse Herlitz
Duration
4 months
What did I learn?
Interaction patterns, nuances and mental model for designing a robust Template Editor
Design thinking in 'creator', and 'preview' modes
Designing features such a date picker; question types for file upload, website/number entry, multichoice, long text, short text, rating, and a complex table flow
Landing page experience evolution
The Template editor → Admin lands here when they create a new template
Create and Preview modes
Set Question types for customers
Placeholder suggestions
Editor elements: Multiple choice & file upload question types
Editor elements: navigation components
Editor elements: Paragraph and short question types
Editor elements: Website, number entry and ratings
Editor elements: Simple yes/no question type
Table question type
How the solutions performed
Customers can now handle all privacy and AI assessments in a singular platform—collaborate seamlessly, track necessary DPO approvals, and map individual assessments to their appropriate data categories, systems, vendors, and more. Plus, easily upload existing assessments for a single source of truth.
Transcend also can pre-populate templates with relevant metadata from the customer's Data Inventory map, pull in the applicable Purposes of Processing or Data Categories associated with the project, accelerating their workflows and simplifying privacy compliance.
References
© November 2024