Introduction

An overview of the Neostra privacy compliance platform, its modules, and how organisations get started.

Overview

Neostra is a privacy compliance platform that brings governance, privacy rights, consent, notices, and data inventory together in one application. It is built for organisations that process personal data under India's Digital Personal Data Protection Act (DPDPA), the EU and UK GDPR, the CCPA/CPRA, and other data protection laws, and for the privacy, legal, and engineering teams responsible for meeting those obligations.

With Neostra you can receive and fulfil privacy rights requests, collect and record consent, maintain an inventory of the personal data you process, run privacy and risk assessments, manage data breaches, and publish privacy notices and a privacy center for the individuals whose data you hold.

Who uses Neostra

Modules

Neostra is organised into modules. The modules available to your organisation depend on your subscription, and what each user can see and do within them depends on their role.

ModulePurpose
GovernanceMeasure and track your organisation's regulatory readiness, including accountability measures, oversight responsibilities, and compliance status.
Breach ManagementRecord and respond to data breaches through a structured process, with risk scoring, notification deadlines for each applicable regulation, and remediation tracking.
Privacy Rights ManagerSet up channels to receive privacy rights requests and manage their fulfilment through workflows, clear ownership, and consistent communication with the requester.
Data InventoryDiscover and maintain an inventory of the personal data processed across your systems to support accuracy, purpose limitation, and retention management.
Privacy CenterOffer individuals a central place for everything related to their privacy, including notices, request forms, and request status.
Consent ManagementCollect, manage, and record clear, purpose-based consent, including updates and withdrawals, with full visibility across your organisation.
AssessmentsCreate and manage privacy and risk assessments for processing activities, vendors, and organisational practices, with defined ownership and assignments.
Privacy NoticesCreate and maintain privacy notices that explain data usage, purposes, individual rights, and available grievance mechanisms.

Regulatory coverage

Neostra is regulation-agnostic. It ships with a library of privacy laws that includes the EU and UK GDPR, the DPDP Act, the CCPA/CPRA and other US state laws, LGPD, PIPEDA, and laws across Asia Pacific, the Middle East, and Africa. Each entry defines its jurisdictions, whether the Global Privacy Control signal applies, and its breach notification window. You can adjust any of these values or add regulations of your own. See Regulations for how the platform maps to specific obligations.

Tenants, brands, and processes

Each customer organisation operates in its own tenant. All data, users, and configuration are isolated to the tenant. Within a tenant you model your organisation as brands, which typically represent business units, products, or subsidiaries, and as processes and sub-processes under each brand. Intake forms, collection points, users, assessments, and privacy centers can be scoped to a brand, so a single tenant can run privacy operations for several business units with separate teams and branding. A user may belong to more than one tenant and selects the organisation to work in after signing in.

Getting access

Access to Neostra is by invitation. A tenant administrator invites users from the Settings menu, and each user receives an email with a registration link to set a password and sign in. Where a tenant requires two-factor authentication, users complete the setup on their first sign in. Individuals who submit requests or manage their consent do not need an account; they use your public forms, the request portal, and the preference center.

If your organisation does not yet have a Neostra tenant, contact Neostra to have one provisioned. The first administrator is invited by email and can then set up the tenant using the Quickstart.

Next steps

Was this page helpful?