Release Notes

Product News: A Unified Document Library, Article 30 ROPA Reports & Enhanced Data Flows

The Data Hub gets a unified document library with a template-driven Policy Builder, versioned editing, and access controls, plus a managed layer for Article 30 ROPA reports and richer directional data-flow mapping.

Concord Team · Published Mon Jun 15 2026

Product News: A Unified Document Library, Article 30 ROPA Reports & Enhanced Data Flows

Most privacy programs keep their proof in too many places. The privacy policy lives in one tool, the SOC 2 report in a shared drive, the DPAs in email, the record of processing in a spreadsheet someone rebuilds every quarter. Every external request then becomes a scavenger hunt.

This release is the start of fixing that. The Data Hub now includes a unified document library that gives every policy, report, statement, and record a single home, and a fully managed layer for Article 30 records of processing built on top of it. We've also enriched how you map data flows between systems, so what your documentation says matches how your data actually moves.

The Document Library: One Home for Everything You Have to Prove

Your compliance documents now live in one global library inside the Data Hub, organized by type, so policies, reports, statements, FAQs, and links each have their own place instead of their own tool.

  • Everything in one inventory. Filter by status, search across the library, and sort by type, category, or access level to find what you need without digging.
  • A real editor with version history. Open any document into a full editor, compare changes between releases, and see how a document evolved. Drafts stay private until you publish, so nothing goes live before it's ready.
  • Access levels on every document. Each document carries its own access setting, from fully public to gated, which becomes the control that governs who can see it wherever it's shared.

The important part isn't the table. It's that a document now exists once, in one place, with one current version, and everything else points at it.

A Smarter Way to Build Policies

Creating a policy starts with a simple choice: build from a template, or upload one you already have.

Choose the Policy Builder and Concord starts you from a template and asks a few guided questions (company details, the specifics of how you handle data), then generates a complete, editable policy from your answers. It's the same guided approach behind our privacy, cookie, and AI policy templates, now unified into one consistent builder rather than a separate form for each policy type. Prefer to bring your own? Upload it and manage it in the library alongside everything else.

Every policy you build is saved in a structured, editable format, so revisiting and updating it later is straightforward, with no starting over and no wrestling with a document that's locked to its original wording.

Coming soon: 30+ policy templates. The builder launches with the templates you already know, and we're expanding it to over 30 policies covering the security, governance, and operational documents companies are routinely asked to produce. Same guided questions, same versioned editor, same library.

Built on a Unified Data Layer

The library isn't a folder bolted onto the product. It sits in the Data Hub alongside your systems, your processing activities, and your data flows, all in one shared data layer.

That's what makes the rest of this release possible. Your ROPA reports generate from the same processing activities you already maintain. Your cross-border transfers come from the same system records your data map is built on. Update the underlying data and every artifact drawn from it reflects the change, because there's no second copy to keep in sync.

It also sets up what's next, Concord Trust, a trust center platform where prospects and customers can self-serve the documentation they need to evaluate you. It reads from this exact library. Publish a policy in Concord Privacy and, when Trust arrives, you'll be able to feature it on your Trust Center without re-uploading anything, with the access level you already set deciding who sees it. Maintain the document once, in the Data Hub, and every surface where someone evaluates your company stays current on its own.

That's the direction: one source of truth behind your internal records and your external-facing proof.

Article 30 ROPA Reports

Under GDPR Article 30, controllers and processors must maintain a Record of Processing Activities, a structured register of what personal data they process, why, and where it goes. The information behind that record has long lived in Concord's Data Mapping, ready to feed your external systems. Now there's a fully managed layer for producing and maintaining the record itself, right inside Concord.

Here's how it works:

  • Generate in one click. Concord assembles a draft ROPA report from your existing processing activities, so you start from your real data instead of a blank template.
  • Edit with smart summary tokens. The report's summary supports tokens like {{Processing Activities Count}} and {{Data Categories List}} that resolve to live values from your mapping when you finalize, so the narrative always matches the data.
  • Finalize to a point-in-time record. Finalizing computes the tokens and freezes the report into an immutable snapshot with a stored PDF, exactly what you want for an audit trail. Need to reflect changes later? Generate a fresh report.
  • Export in the format you need. Finalized reports export to PDF, HTML, Markdown, and plain text, and remain viewable and exportable whenever you need to produce them.

Finalized reports land in the document library with everything else, so your Article 30 record sits next to the policies and reports it belongs with, rather than in someone's downloads folder.

ROPA reporting is part of the ROPA / PIA / DPIA add-on catalog, available on Premium and Enterprise plans at $99/month, or $990/year billed annually. Turn it on yourself from Billing in the admin console, no sales call required. If the add-on ever lapses, your existing reports stay fully readable and exportable, and you simply pause creating new ones. See the privacy plan comparison for where it fits.

Enhanced Data Flow Mapping

Understanding where data moves between your systems is central to a defensible privacy program, and we've made that mapping richer. You can now describe the direction of a data flow between two systems (one system sends to another, receives from it, or both), so your data map reflects how information actually moves, not just that a connection exists. Each flow captures the categories of data involved, and because a flow is shared between the two systems it connects, it stays consistent no matter which system you view it from.

The data locations you record on each system feed directly into your Article 30 reporting. When a processing activity touches a system that processes data outside the EEA, Concord treats those destinations as a third-country transfer and names the countries in the record, which is exactly what Article 30(1)(e) asks for. Countries with an adequacy decision are named too, since the obligation to identify the third country doesn't go away when a transfer is easier to justify. Your {{Transfers List}} resolves from those same locations, so the transfers in your ROPA reflect reality without extra bookkeeping.

Why It Matters

Documentation and records of processing are where privacy programs are proven: to regulators, to auditors, and to customers. The difference between a program that holds up and one that scrambles is usually not effort, it's whether the proof is current and easy to produce.

Putting your policies, your Article 30 records, your systems, and your data map into one data layer, with generation and versioning built in, means maintaining one thing instead of reconciling five. It keeps the paperwork in step with your program today, and it's the foundation everything we build next will run on.

Get Started

The Data Hub document library and enhanced data-flow mapping are available now. Article 30 ROPA reporting is one toggle away: open Billing in the admin console, add it to your plan, and generate your first report the same day. Want a walkthrough of how it all fits together first? Book a demo and we'll show you.