figma guide

Designing subprocessor breach notification and cascade impact UI in Figma: vendor alerts, customer impact, and regulatory timelines

Design subprocessor breach notification UI in Figma with vendor incident intake, cascade impact mapping, customer notification drafts, and multi-jurisdiction deadline tracking.

Published
Updated
Aug 16, 2026
Read time
7 min
Level
Intermediate

Quick answer

Subprocessor breach UI intake vendor incident notices, maps which customer data was affected, and drives controller obligations—regulator clocks, user notifications, and contract follow-up. Design a vendor alert inbox, cascade impact worksheet (systems → data categories → customers), notification draft studio, and jurisdiction deadline tracker tied to your DPA hub. Start from the Figma guides hub and pair with breach notification, vendor risk, war room, forensic evidence, and Dev Mode handoff.


Who this is for

  • Product designers building privacy ops tooling for processor/controller breach workflows.
  • Legal and privacy teams receiving vendor breach emails at 2 a.m. and needing structured intake.
  • Security and incident response linking vendor incidents to internal war room processes.

Vendor breach inbox (admin overview)

SubprocessorBreachInbox — Acme App · 2 active vendor incidents · 1 regulator clock running
├── Header: Awaiting triage 1 · Impact assessment 1 · Notifying 0 · Closed 30d: 4
├── Actions: [ Log manual alert ] [ Open war room ] [ Export incident bundle ]
├── Tabs: Active · Awaiting vendor · Regulator deadline · Customer notify · Closed
├── Sort: Deadline · Severity · Vendor · Detected date
├── Row example:
│   VIN-992 · EmailCo (processor) · Detected 2026-08-16 02:14 · 70h until EU notify · Triage
│   VIN-991 · AnalyticsCo · Detected 2026-08-14 · Customer notify draft ready · High
└── Link: [DPA hub](/designing-data-processing-agreements-and-subprocessor-management-ui-in-figma/) · [Breach reporting](/designing-breach-notification-and-regulatory-reporting-ui-in-figma/) · [Status page](/designing-customer-incident-status-page-and-communication-ui-in-figma/)
Column / elementPurpose
VendorSubprocessor from DPA registry
Regulator clockTime to controller notification obligation
Customer impactEstimated affected users / tenants
SeverityVendor-reported + your assessment
War room linkInternal IR coordination

Verdict: Vendor breaches fail when the alert stays in legal’s inbox—structured intake starts the cascade impact worksheet immediately.


Vendor alert intake panel

VendorAlertIntake — VIN-992 · EmailCo · Status: Triage
├── Source: Vendor portal webhook · Email PDF attached · Ticket INC-4419
├── Vendor claims:
│   ├── Incident type: Unauthorized access to mailing list API
│   ├── Data categories: Email, name, marketing preferences
│   ├── Approx records: 120,000 (vendor estimate · unverified)
│   ├── Containment: API key rotated 2026-08-16 01:00 UTC
│   └── Vendor SLA: Full report within 72h per DPA Section 8.2
├── Your validation checklist:
│   ├── ☐ Confirm vendor in [DPA registry](/designing-data-processing-agreements-and-subprocessor-management-ui-in-figma/)
│   ├── ☐ Map to internal systems and [ROPA](/designing-records-of-processing-activities-and-data-mapping-ui-in-figma/) activities
│   ├── ☐ Identify affected tenants / regions
│   ├── ☐ Legal review: Is this a personal data breach under GDPR?
│   └── ☐ Open [war room](/designing-security-operations-shift-handover-and-war-room-ui-in-figma/) if customer data confirmed
├── Regulator clocks (controller obligations):
│   ├── EU (GDPR): Notify SA within 72h of awareness · Deadline 2026-08-19 02:14 · Not started
│   ├── UK: ICO 72h · Same awareness timestamp
│   └── US state: Varies · Trigger after impact assessment
└── Actions: [ Start impact worksheet ] [ Request vendor update ] [ Mark false positive ] [ Escalate legal ]

Treat vendor claims as unverified until your impact worksheet confirms scope.


Cascade impact worksheet

CascadeImpact — VIN-992 · EmailCo mailing API
├── Data flow map:
│   Acme App → EmailCo (processor) → Sub-sub: DeliverabilityCo?
├── Data categories affected:
│   ├── Email address · 98,000 confirmed Acme users · Marketing purpose
│   ├── First name · 98,000 · Same
│   └── Marketing prefs · 98,000 · Link [consent admin](/designing-consent-records-and-preference-management-admin-ui-in-figma/)
├── Tenant breakdown:
│   ├── EU: 41,000 · UK: 12,000 · US: 45,000
│   └── B2B tenants requiring direct notice: 3 enterprise accounts
├── Risk assessment:
│   ├── Likelihood of harm: Medium (email + name phishing)
│   ├── Special category data: No
│   ├── Children: Unknown · Run [children's privacy](/designing-childrens-privacy-age-verification-and-parental-consent-ui-in-figma/) check
│   └── Encrypt/at rest: Vendor claims yes · Verify in vendor report
├── Controller decision: Personal data breach? → Yes · Notify users? → Likely yes EU/UK
└── Link: [Forensic evidence](/designing-forensic-evidence-management-and-chain-of-custody-ui-in-figma/) · [Audit log](/designing-audit-log-and-security-activity-ui-in-figma/)

The worksheet is the bridge between vendor PDF and your regulator/user notifications.


Regulator notification tracker

JurisdictionTriggerDeadlineStatusOwner
EU (lead SA)Personal data breach72h from awarenessDraftLegal
UK ICOSame72hNot startedLegal
US-CA500+ CA residentsWithout unreasonable delayPending countPrivacy
Enterprise DPAsContractualPer customer DPA3 tickets openAccount team
RegulatorNotify — VIN-992 · EU lead SA · Deadline 2026-08-19 02:14 UTC
├── Countdown: 70h 12m remaining · Red under 24h
├── Draft: Pre-filled from cascade worksheet · Edit before submit
├── Fields: Nature of breach · Categories · Approximate numbers · Measures taken · DPO contact
├── Attachments: Vendor report · Internal timeline · [Chain of custody](/designing-forensic-evidence-management-and-chain-of-custody-ui-in-figma/) refs
├── Submit log: submitted_at · reference_number · immutable snapshot
├── Extension: Document if full scope unknown at 72h · Art. 33(4) phased notification note
└── Link: [Breach reporting UI](/designing-breach-notification-and-regulatory-reporting-ui-in-figma/) for first-party incidents (shared components)

Reuse deadline widgets from first-party breach UI—controllers face the same clocks.


Customer and user notification studio

CustomerNotifyStudio — VIN-992 · Draft v3 · Pending legal approval
├── Audience segments:
│   ├── All affected users (98k) · Email + in-app banner
│   ├── EU/UK only (53k) · Stricter copy · Link [DSAR portal](/designing-data-subject-access-request-and-gdpr-portal-ui-in-figma/)
│   └── Enterprise tenants (3) · Custom PDF + CSM task · Per-contract wording
├── Template blocks:
│   ├── What happened (plain language) · What data · What we are doing
│   ├── What you can do (password reset, vigilance) · Support contact
│   ├── Regulator rights · Link [privacy settings](/designing-privacy-settings-and-data-management-ui-in-figma/)
│   └── Do not include: Unverified vendor internals · Over-promising containment
├── Channels: Email · In-app · [Status page](/designing-customer-incident-status-page-and-communication-ui-in-figma/) · Trust center update
├── Approval: Legal ✓ · DPO ☐ · Comms ☐ · Send scheduled: —
└── Post-send: Log to [audit trail](/designing-audit-log-and-security-activity-ui-in-figma/) · Open [privacy request queue](/designing-privacy-request-queue-and-case-management-ui-in-figma/) for spikes

Segment notifications by jurisdiction and contract, not one blast to everyone.


Vendor follow-up and contract actions

VendorFollowUp — VIN-992 · EmailCo · DPA Section 8.2 obligations
├── Required from vendor:
│   ├── ☐ Root cause report · Due 2026-08-19 · Received: Partial
│   ├── ☐ Affected record list (Acme scoped) · Due 2026-08-18
│   ├── ☐ Remediation plan · Due 2026-08-22
│   └── ☐ Sub-subprocessor disclosure if DeliverabilityCo involved
├── Contract actions:
│   ├── Document breach in [vendor risk](/designing-vendor-risk-assessment-and-third-party-reviews-ui-in-figma/) record
│   ├── Trigger audit rights · Schedule call · Credit/chargeback tracker
│   └── Evaluate termination / switch processor workflow
├── Internal remediation:
│   └── Link [privacy remediation](/designing-privacy-impact-remediation-tracking-and-action-plan-ui-in-figma/) if product changes required
└── Close criteria: Regulator filed · Users notified · Vendor report complete · Post-incident review scheduled

Handoff checklist (Dev Mode)

  • VendorIncident — incident_id, vendor_id, detected_at, awareness_at, vendor_severity, status, war_room_id.
  • CascadeImpact — incident_id, data_categories[], affected_user_count, regions[], tenant_ids[], breach_decision, harm_level.
  • RegulatorDeadline — incident_id, jurisdiction, deadline_at, submitted_at, reference_number, status.
  • CustomerNotification — incident_id, segment_id, channel, template_version, approved_by[], sent_at.
  • VendorObligation — incident_id, obligation_type, due_at, received_at, artifact_url.
  • IncidentTimeline — event_type, timestamp, actor, source (vendor/internal), note.
  • Accessibility — Countdown text + visual; notification preview screen-reader friendly; table keyboard nav.

Common mistakes

MistakeWhy it hurtsFix
Trust vendor scope blindlyUnder-notify usersCascade worksheet with your data map
Miss awareness timestampWrong 72h clockLog when internal team confirmed breach
One notification for all regionsWrong legal copySegment by jurisdiction and contract
No DPA linkWrong obligationsPull contract SLA from DPA hub
Forget enterprise tenantsContract breachB2B segment with CSM tasks
No vendor follow-up trackerIncomplete closureObligation checklist with due dates
Duplicate war room + privacy toolSplit brainLink or embed war room status
Skip post-incident reviewRepeat incidentsAuto-schedule PIR on close

  1. Intake vendor alert into structured record with awareness timestamp.
  2. Run cascade impact worksheet against ROPA and tenant data.
  3. Start regulator clocks and draft notifications in parallel—not sequentially after vendor final report.
  4. Open war room when customer impact confirmed; link forensic evidence if internal systems involved.
  5. Segment customer notifications by region and enterprise contracts.
  6. Track vendor obligations until root cause and scoped record list received.
  7. Close with PIR and update vendor risk score in Dev Mode.

FAQ

Processor vs controller breach UI?

This post covers you as controller receiving processor notices. First-party breaches use breach notification UI—share deadline and draft components.

Vendor says “no personal data”?

Document false positive path with legal sign-off; still log incident for vendor risk history.

Sub-subprocessor involved?

Extend cascade worksheet with sub-sub row; pull disclosure from DPA hub chain.

Post-notification DSAR spikes—add incident tag and bulk response templates in queue filters.

72h with incomplete vendor data?

Support phased regulator notification UI: initial filing + amendment task with second deadline.


Next steps

Share on X

§ Keep reading

Related guides.