Recordant is a data protection application for DPOs and heads of compliance. It records every data subject request, every breach and every processing activity, and runs each one on the deadline its country sets. Recordant records and clocks. It does not search your databases. It assigns the search to the person who owns the system, runs the clock while they look, and keeps the proof of what came back.
Requests and breaches usually live in a spreadsheet and a shared mailbox, so the deadline is whatever someone remembers. Recordant starts the clock the day a case is logged, at the period for that entity's country: 30 days in Saudi Arabia, 21 in Malaysia, 30 under DIFC law, 72 hours for a breach. The queue sorts by the oldest promise. The audit trail is written as the work happens, so the regulator's filing is never assembled from email afterwards.
Key Features
- Request cases with identity check, search assignment, approval, reply letter and close, each step on an audit trail nobody can edit.
- Breach incidents with their own 72 hour clock and the regulator notification date on the row.
- Record of processing activities: system, purpose, legal basis, owner, exportable as CSV or PDF.
- Country packs for Saudi Arabia (PDPL, SDAIA), Malaysia (PDPA, JPDP) and the DIFC, editable without a developer. The UAE pack ships configurable and marked Regulation pending, because the federal executive regulations have not set a period.
- Letter templates per entity and language.
- Two AI assistants in the Joget AI Agent Builder: one classifies the request from the person's own words, one drafts the reply from your template and leaves gaps in brackets where the record is silent. Both suggest. A person reviews and sends.
- Group ready: one register, a separate clock per entity and regulator.
Frequently asked questions
Does Recordant find the person's data in our systems?
No. It assigns the search to the system owner, runs the clock and records the result. Discovery stays with your own systems and tools.
Does it file the breach with the regulator?
It produces the incident pack and runs the 72 hour clock. Filing through the regulator's portal stays a human step, because that is how SDAIA and JPDP receive notifications.
Can the AI send a letter?
No. It drafts from your template. A person reviews, edits and sends.
What if our country is not in the list?
Add a country pack with its request and breach periods, languages and regulator. Every entity picks a pack.
Why is the UAE clock blank?
The federal executive regulations have not set a period. The pack ships configurable and marked Regulation pending. Set your own internal deadline, or change one field when the regulation lands.
Do we need Joget Enterprise?
Yes. Recordant is verified on DX 9.1.1 Enterprise and the assistants use the Enterprise AI Agent Builder.
How do I get Recordant?
Recordant is a licensed app for Joget DX 9 Enterprise. Contact Joget or write to sales@joget.org for a tailored demo and pricing.
We also work with specialist privacy and compliance consulting partners who can configure Recordant around your entities and regulators and take your programme through to audit ready.
Contact
Send the name of one entity and its regulator to Contact Joget or sales@joget.org, and we will walk one request through Recordant on that entity's clock in 30 minutes.