Vigilby Norn Labs

Compliance operations · In development

Run your entire compliance operation from one place.

Vigil brings data requests, data mapping, assessments, policies, training, regulatory change and compliance evidence into one operational workspace.

For DPO, legal and compliance teams.
Global by design. EU-first, starting with GDPR.

vigilExample GroupIllustrative preview

Workspace / Overview

Your operation, in view.

14 SEP
GDPR coverage

3 entities in scope

2 gaps to review
07Active requests
02Due this week
01Needs approval

Next in your queue

Access request · DSR-024Information collection in progress
16 Sep
DPIA · Elevated riskRecruitment system · DPO approval

Regulatory signal · Example

Updated retention guidance

May affect 2 processing activities. Review the source and impact.
Optional engines
Illustrative interface · Synthetic data · 14 Sep 2026

01 One operational layer

Compliance work should not live across six disconnected systems.

01

Shared inboxes

Requests arrive without a case owner.

02

Spreadsheets

Registers drift between versions.

03

Word documents

Policies sit apart from the work.

04

Shared drives

Evidence is buried in folders.

05

Manual trackers

Deadlines depend on reminders.

06

Regulatory newsletters

Updates arrive without context.

Vigil

One workspace connects each obligation to its owner, deadline and evidence.

Context → action → record

02 The platform

Know what applies. Act on what matters. Prove what was done.

A compliance operating system for mid-sized and large international companies. The organisation’s context travels with the work.

01

Understand

Build a live company profile and identify likely applicable obligations with visible reasoning.

Company context → obligation map
02

Operate

Run cases, assessments, tasks, approvals, reminders and deadlines from one workspace.

Obligation → owned action
03

Evidence

Maintain the documents, records and audit trail needed to show what happened and why.

Action → traceable record

03 Your operational view

The work that needs your attention. The context to act.

See coverage, gaps and risk alongside the cases in progress. Know what changed, what is overdue and which decision comes next.

vigilExample Group / GDPR workspaceIllustrative snapshot

Monday, 14 September 2026

Operational overview

Group view
Coverage
3 / 3 entities

Company profiles reviewed

Evidence gaps
02

Records need an update

Elevated risk
01

Assessment under review

Overdue work
01

Training follow-up

Your work queue

4 priority items

4 items shown in the example work queue.

  • TRN-018Overdue
    Complete privacy training follow-up

    Employee training · Example France

    Learning lead10 Sep · 4 days overdue
  • DSR-024Due soon
    Collect records for an access request

    Data-subject request · Example Germany

    Privacy team16 Sep · 2 days remaining
  • DPIA-007Approval needed
    Review the recruitment assessment

    DPIA · Group operations

    Group DPOReview before 18 Sep
  • MAP-012In progress
    Confirm supplier data flows

    Data mapping · Example Finland

    IT operations21 Sep

Coverage, open risks and evidence gaps stay visible together. A reviewed profile is not a guarantee of compliance.

Illustrative interface and synthetic organisation. Regulatory examples are hypothetical. Preview design may evolve.

04 The initial pack · In development

A complete operational layer for GDPR work.

One coherent GDPR pack connects intake, assessments, documents and evidence. Each part contributes to the same operational picture.

EU-first · In development
01

Data-subject requests

A case, an owner and a deadline for every request.

02

Data mapping & RoPA

Reviewed processing activities, ready for your record of processing.

03

DPIAs

Structured impact assessments with decisions and follow-up actions.

04

Breach management

Coordinate assessment, response and the record of what happened.

05

Questionnaire-driven policies

Draft policies from the organisation’s actual practices.

06

Training & certificates

Employee learning, quizzes and completion evidence.

07

DPO workflows

Assign work, involve colleagues and bring decisions back for review.

08

Document generation

Turn accepted information into consistent working documents.

09

Audit & evidence exports

Bring records, supporting material and activity history together.

05 Data-subject requests

From an incoming request to a defensible response.

A proposed workflow for the GDPR pack, from the existing privacy inbox to the final evidence record. Automation is being developed around accountable human decisions.

Illustrative case
DSR-2026-014 · Access request
  1. 01

    Request received

    Through the company’s existing privacy inbox.

  2. 02

    Detected and classified

    A proposed request type is identified for review.

  3. 03

    Case and deadline created

    The owner can check the legal deadline and its basis.

  4. 04

    Acknowledgement prepared

    Ready for the first working day, subject to approval.

  5. 05

    Collection tasks assigned

    Relevant teams are asked for the information needed.

  6. 06

    Reminded and escalated

    Outstanding contributions stay visible to the case owner.

  7. 07

    Response compiled

    Collected information becomes a draft response.

  8. 08

    Human review and approval

    An authorised reviewer decides what can leave the organisation.

    Human decision
  9. 09

    Response sent

    Only after approval, through the agreed communication channel.

  10. 10

    Evidence retained

    The response, decisions and supporting record close the case.

People retain control over legal assessments, deadline exceptions and outbound communications. Prepared does not mean sent.

06 Data mapping

Turn operational knowledge into a living data map.

Start with what the business already knows. AI-assisted extraction proposes the structure; the DPO reviews the facts and decides what enters the register.

01 / Source material

Upload existing knowledge

HR interview notesInterview · Synthetic example
Supplier onboarding.docxWorking document

Interview notes and existing documents supply the context.

02 / AI-assisted proposal

Extract. Find the gaps.

Candidate activity
Employee onboarding
Source
HR interview · §3
Missing information
Retention period

Candidate processing activities are linked to their sources. Missing fields become questions.

03 / DPO review

Correct. Accept. Record.

Proposal awaiting review

The DPO corrects the proposal. Vigil flags where a DPIA may be required, with reasoning for review.

After acceptanceStructured processing recordReady for optional Cadaster

07 Regulatory intelligence

Only the changes that matter to your organisation.

Vigil compares regulatory developments with your company profile. Each relevant signal explains the potential impact and the work to review.

  • What changedThe development and its source.
  • Why it may applyThe company facts behind the recommendation.
  • What could be affectedEntities, activities and responsibilities.
  • What needs reviewPolicies, workflows, training and records.
Illustrative applicability review
NIS2Review required
“Based on the information supplied, NIS2 is likely applicable.”
Reasoning
The supplied sector, entity size and EU operations suggest a potential match. National scope and exceptions still need checking.
Review next
Confirm entity scope with legal counsel. Review incident response, responsibilities and training.

Example of a planned pack. A recommendation for review, not a definitive legal conclusion.

08 A platform that can grow

Start with GDPR. Expand without rebuilding your compliance stack.

Add coherent regulatory and standards packs created by Norn Labs. The same company context, tasks and evidence can support the next area of work.

Initial pack

GDPR

Operational data protection

In development
EU AI ActPlanned
NIS2Planned
DORAPlanned
ISO 27001Planned
ISO 9001Planned
ISO 14001Planned
Anti-bribery and corruptionPlanned
CSRDPlanned
CS3DPlanned

Planned country overlays

One regulatory pack. The local context that matters.

Buy a regulatory pack once, then add country coverage for national implementation rules, regulator guidance, local templates and relevant updates. Scope and availability will be confirmed as packs are developed.

09 By Norn Labs

Coordinated work. Connected capabilities.

VigilWatches and coordinates
DispatchCommunicates
CadasterRecords

Optional engine · Planned

Cadaster

A structured, versioned register engine designed for audit-ready records.

  • RoPA and breach registers
  • AI-system and incident registers
  • Other statutory and compliance records

Optional engine · Planned

Dispatch

A communication engine designed to support compliant workflows.

  • Inbox intake and acknowledgements
  • Routing, reminders and escalations
  • Outbound notices and proof of sending

Whistleblowing capability · Integration planned

Kaja

Whistleblowing and case management within the broader Norn Labs ecosystem.

Vigil integration is planned, bringing this specialist capability into the wider compliance operation.

Explore Kaja

Cadaster and Dispatch are optional additions. Neither is included in the default Vigil subscription.

10 Connected to your working environment

Works with the systems where compliance work already happens.

The planned connections bring inbox intake and source documents into the workflow, so teams can start with the tools they already use.

Planned

Microsoft Outlook

Privacy inbox intake

Planned

Microsoft OneDrive

Documents and evidence

Planned

Gmail

Privacy inbox intake

Planned

Google Drive

Documents and evidence

Connector scope and availability will be confirmed during development discussions.

11 Accountability by design

Built for sensitive European compliance operations.

A European foundation

Norn Labs builds on European infrastructure with EU data residency. Vigil’s deployment arrangements will be confirmed with prospective customers.

Norn Labs privacy & security

People remain accountable

The product design keeps human approval at consequential legal and outbound steps, with recommendations linked to source information and explicit reasoning.

Review the controls with us

Access controls, auditability, encryption and evidence-retention arrangements are being defined and validated for Vigil. We will discuss the confirmed controls and deployment scope during evaluation.

Vigil supports compliance operations. It does not replace qualified legal advice.

Vigil · In development · Pre-order enquiries

Replace scattered compliance work with one operational system.

Tell us about your organisation, your current processes and the work you need to bring together.

Pre-order enquiries begin a discussion. No order or payment is taken, and no launch date is promised.

Read the Vigil FAQ