figma guide
Designing subprocessor breach notification and cascade impact UI in Figma: vendor alerts, customer impact, and regulatory timelines
Design subprocessor breach notification UI in Figma with vendor incident intake, cascade impact mapping, customer notification drafts, and multi-jurisdiction deadline tracking.
- Published
- Updated
- Aug 16, 2026
- Read time
- 7 min
- Level
- Intermediate
Quick answer
Subprocessor breach UI intake vendor incident notices, maps which customer data was affected, and drives controller obligations—regulator clocks, user notifications, and contract follow-up. Design a vendor alert inbox, cascade impact worksheet (systems → data categories → customers), notification draft studio, and jurisdiction deadline tracker tied to your DPA hub. Start from the Figma guides hub and pair with breach notification, vendor risk, war room, forensic evidence, and Dev Mode handoff.
Who this is for
- Product designers building privacy ops tooling for processor/controller breach workflows.
- Legal and privacy teams receiving vendor breach emails at 2 a.m. and needing structured intake.
- Security and incident response linking vendor incidents to internal war room processes.
Vendor breach inbox (admin overview)
SubprocessorBreachInbox — Acme App · 2 active vendor incidents · 1 regulator clock running
├── Header: Awaiting triage 1 · Impact assessment 1 · Notifying 0 · Closed 30d: 4
├── Actions: [ Log manual alert ] [ Open war room ] [ Export incident bundle ]
├── Tabs: Active · Awaiting vendor · Regulator deadline · Customer notify · Closed
├── Sort: Deadline · Severity · Vendor · Detected date
├── Row example:
│ VIN-992 · EmailCo (processor) · Detected 2026-08-16 02:14 · 70h until EU notify · Triage
│ VIN-991 · AnalyticsCo · Detected 2026-08-14 · Customer notify draft ready · High
└── Link: [DPA hub](/designing-data-processing-agreements-and-subprocessor-management-ui-in-figma/) · [Breach reporting](/designing-breach-notification-and-regulatory-reporting-ui-in-figma/) · [Status page](/designing-customer-incident-status-page-and-communication-ui-in-figma/)
| Column / element | Purpose |
|---|---|
| Vendor | Subprocessor from DPA registry |
| Regulator clock | Time to controller notification obligation |
| Customer impact | Estimated affected users / tenants |
| Severity | Vendor-reported + your assessment |
| War room link | Internal IR coordination |
Verdict: Vendor breaches fail when the alert stays in legal’s inbox—structured intake starts the cascade impact worksheet immediately.
Vendor alert intake panel
VendorAlertIntake — VIN-992 · EmailCo · Status: Triage
├── Source: Vendor portal webhook · Email PDF attached · Ticket INC-4419
├── Vendor claims:
│ ├── Incident type: Unauthorized access to mailing list API
│ ├── Data categories: Email, name, marketing preferences
│ ├── Approx records: 120,000 (vendor estimate · unverified)
│ ├── Containment: API key rotated 2026-08-16 01:00 UTC
│ └── Vendor SLA: Full report within 72h per DPA Section 8.2
├── Your validation checklist:
│ ├── ☐ Confirm vendor in [DPA registry](/designing-data-processing-agreements-and-subprocessor-management-ui-in-figma/)
│ ├── ☐ Map to internal systems and [ROPA](/designing-records-of-processing-activities-and-data-mapping-ui-in-figma/) activities
│ ├── ☐ Identify affected tenants / regions
│ ├── ☐ Legal review: Is this a personal data breach under GDPR?
│ └── ☐ Open [war room](/designing-security-operations-shift-handover-and-war-room-ui-in-figma/) if customer data confirmed
├── Regulator clocks (controller obligations):
│ ├── EU (GDPR): Notify SA within 72h of awareness · Deadline 2026-08-19 02:14 · Not started
│ ├── UK: ICO 72h · Same awareness timestamp
│ └── US state: Varies · Trigger after impact assessment
└── Actions: [ Start impact worksheet ] [ Request vendor update ] [ Mark false positive ] [ Escalate legal ]
Treat vendor claims as unverified until your impact worksheet confirms scope.
Cascade impact worksheet
CascadeImpact — VIN-992 · EmailCo mailing API
├── Data flow map:
│ Acme App → EmailCo (processor) → Sub-sub: DeliverabilityCo?
├── Data categories affected:
│ ├── Email address · 98,000 confirmed Acme users · Marketing purpose
│ ├── First name · 98,000 · Same
│ └── Marketing prefs · 98,000 · Link [consent admin](/designing-consent-records-and-preference-management-admin-ui-in-figma/)
├── Tenant breakdown:
│ ├── EU: 41,000 · UK: 12,000 · US: 45,000
│ └── B2B tenants requiring direct notice: 3 enterprise accounts
├── Risk assessment:
│ ├── Likelihood of harm: Medium (email + name phishing)
│ ├── Special category data: No
│ ├── Children: Unknown · Run [children's privacy](/designing-childrens-privacy-age-verification-and-parental-consent-ui-in-figma/) check
│ └── Encrypt/at rest: Vendor claims yes · Verify in vendor report
├── Controller decision: Personal data breach? → Yes · Notify users? → Likely yes EU/UK
└── Link: [Forensic evidence](/designing-forensic-evidence-management-and-chain-of-custody-ui-in-figma/) · [Audit log](/designing-audit-log-and-security-activity-ui-in-figma/)
The worksheet is the bridge between vendor PDF and your regulator/user notifications.
Regulator notification tracker
| Jurisdiction | Trigger | Deadline | Status | Owner |
|---|---|---|---|---|
| EU (lead SA) | Personal data breach | 72h from awareness | Draft | Legal |
| UK ICO | Same | 72h | Not started | Legal |
| US-CA | 500+ CA residents | Without unreasonable delay | Pending count | Privacy |
| Enterprise DPAs | Contractual | Per customer DPA | 3 tickets open | Account team |
RegulatorNotify — VIN-992 · EU lead SA · Deadline 2026-08-19 02:14 UTC
├── Countdown: 70h 12m remaining · Red under 24h
├── Draft: Pre-filled from cascade worksheet · Edit before submit
├── Fields: Nature of breach · Categories · Approximate numbers · Measures taken · DPO contact
├── Attachments: Vendor report · Internal timeline · [Chain of custody](/designing-forensic-evidence-management-and-chain-of-custody-ui-in-figma/) refs
├── Submit log: submitted_at · reference_number · immutable snapshot
├── Extension: Document if full scope unknown at 72h · Art. 33(4) phased notification note
└── Link: [Breach reporting UI](/designing-breach-notification-and-regulatory-reporting-ui-in-figma/) for first-party incidents (shared components)
Reuse deadline widgets from first-party breach UI—controllers face the same clocks.
Customer and user notification studio
CustomerNotifyStudio — VIN-992 · Draft v3 · Pending legal approval
├── Audience segments:
│ ├── All affected users (98k) · Email + in-app banner
│ ├── EU/UK only (53k) · Stricter copy · Link [DSAR portal](/designing-data-subject-access-request-and-gdpr-portal-ui-in-figma/)
│ └── Enterprise tenants (3) · Custom PDF + CSM task · Per-contract wording
├── Template blocks:
│ ├── What happened (plain language) · What data · What we are doing
│ ├── What you can do (password reset, vigilance) · Support contact
│ ├── Regulator rights · Link [privacy settings](/designing-privacy-settings-and-data-management-ui-in-figma/)
│ └── Do not include: Unverified vendor internals · Over-promising containment
├── Channels: Email · In-app · [Status page](/designing-customer-incident-status-page-and-communication-ui-in-figma/) · Trust center update
├── Approval: Legal ✓ · DPO ☐ · Comms ☐ · Send scheduled: —
└── Post-send: Log to [audit trail](/designing-audit-log-and-security-activity-ui-in-figma/) · Open [privacy request queue](/designing-privacy-request-queue-and-case-management-ui-in-figma/) for spikes
Segment notifications by jurisdiction and contract, not one blast to everyone.
Vendor follow-up and contract actions
VendorFollowUp — VIN-992 · EmailCo · DPA Section 8.2 obligations
├── Required from vendor:
│ ├── ☐ Root cause report · Due 2026-08-19 · Received: Partial
│ ├── ☐ Affected record list (Acme scoped) · Due 2026-08-18
│ ├── ☐ Remediation plan · Due 2026-08-22
│ └── ☐ Sub-subprocessor disclosure if DeliverabilityCo involved
├── Contract actions:
│ ├── Document breach in [vendor risk](/designing-vendor-risk-assessment-and-third-party-reviews-ui-in-figma/) record
│ ├── Trigger audit rights · Schedule call · Credit/chargeback tracker
│ └── Evaluate termination / switch processor workflow
├── Internal remediation:
│ └── Link [privacy remediation](/designing-privacy-impact-remediation-tracking-and-action-plan-ui-in-figma/) if product changes required
└── Close criteria: Regulator filed · Users notified · Vendor report complete · Post-incident review scheduled
Handoff checklist (Dev Mode)
- VendorIncident — incident_id, vendor_id, detected_at, awareness_at, vendor_severity, status, war_room_id.
- CascadeImpact — incident_id, data_categories[], affected_user_count, regions[], tenant_ids[], breach_decision, harm_level.
- RegulatorDeadline — incident_id, jurisdiction, deadline_at, submitted_at, reference_number, status.
- CustomerNotification — incident_id, segment_id, channel, template_version, approved_by[], sent_at.
- VendorObligation — incident_id, obligation_type, due_at, received_at, artifact_url.
- IncidentTimeline — event_type, timestamp, actor, source (vendor/internal), note.
- Accessibility — Countdown text + visual; notification preview screen-reader friendly; table keyboard nav.
Common mistakes
| Mistake | Why it hurts | Fix |
|---|---|---|
| Trust vendor scope blindly | Under-notify users | Cascade worksheet with your data map |
| Miss awareness timestamp | Wrong 72h clock | Log when internal team confirmed breach |
| One notification for all regions | Wrong legal copy | Segment by jurisdiction and contract |
| No DPA link | Wrong obligations | Pull contract SLA from DPA hub |
| Forget enterprise tenants | Contract breach | B2B segment with CSM tasks |
| No vendor follow-up tracker | Incomplete closure | Obligation checklist with due dates |
| Duplicate war room + privacy tool | Split brain | Link or embed war room status |
| Skip post-incident review | Repeat incidents | Auto-schedule PIR on close |
Recommended workflow
- Intake vendor alert into structured record with awareness timestamp.
- Run cascade impact worksheet against ROPA and tenant data.
- Start regulator clocks and draft notifications in parallel—not sequentially after vendor final report.
- Open war room when customer impact confirmed; link forensic evidence if internal systems involved.
- Segment customer notifications by region and enterprise contracts.
- Track vendor obligations until root cause and scoped record list received.
- Close with PIR and update vendor risk score in Dev Mode.
FAQ
Processor vs controller breach UI?
This post covers you as controller receiving processor notices. First-party breaches use breach notification UI—share deadline and draft components.
Vendor says “no personal data”?
Document false positive path with legal sign-off; still log incident for vendor risk history.
Sub-subprocessor involved?
Extend cascade worksheet with sub-sub row; pull disclosure from DPA hub chain.
Link to privacy request queue?
Post-notification DSAR spikes—add incident tag and bulk response templates in queue filters.
72h with incomplete vendor data?
Support phased regulator notification UI: initial filing + amendment task with second deadline.
Next steps
- Design data processing agreements and subprocessor management UI in Figma — vendor registry and contract SLAs
- Design breach notification and regulatory reporting UI in Figma — shared regulator draft and deadline components
- Design vendor risk assessment and third-party security reviews UI in Figma — post-incident vendor score updates
- Design customer incident status page and communication UI in Figma — public comms channel for breach updates
- Design post-incident review and root cause analysis UI in Figma — close the loop after notification
§ Keep reading