← All Projects

2020 – 2024 · Microsoft Priva

03

2020 – 2024 · Microsoft Priva

Microsoft Priva –
Privacy management

Microsoft Priva · DSR · Consent · Risk · Assessments · Tracker Scanning

Lead Designer GDPR / CCPA 5 Products Enterprise Privacy Microsoft 365
Shipped full-screen consent model customization view in Microsoft Purview Consent Management, showing the live device preview and styling controls
Project Details

Privacy operations at large enterprises were running on duct tape. Subject rights requests were tracked in shared spreadsheets. Consent models were managed through third-party tools that didn't connect to internal data. Privacy risk assessments meant emailing questionnaires and waiting weeks for responses.

Microsoft's opportunity was to replace all of this with a unified, automated privacy operations platform built natively into the Microsoft 365 ecosystem that millions of enterprise customers already used.

Lead Designer — all 5 products

I led end-to-end UX design across all five privacy products over four years, developed largely in parallel rather than sequentially, from initial concept through public launch. I also contributed to the unified navigation and home experience that tied all five products together as Microsoft Priva.

Research/input. Priva started as two PMs and me, with a hypothesis and no funded product — one of several workstreams running inside the broader, multi-year Babylon effort that was simultaneously building out what would become Azure Purview. I took part in the research directly: cold-calling privacy professionals on LinkedIn, with no existing product to anchor the conversation, just questions about how they handled compliance today.

Insight. Two patterns showed up in nearly every call. Everything was manual — Excel trackers, offline processes, no system of record. And everything was disconnected — a privacy officer juggling five separate processes with no single place to see status across any of them.

Decision. The team wrote a white paper synthesising what we'd heard. I built the case for it visually — low-fidelity PowerPoint walkthroughs with wireframes, structured around a fictional company and named personas, each with their own scenario walked step by step: log in, select a workflow, complete a form, see the result. Kept deliberately rough so we could socialise the idea quickly and iterate without over-investing before we knew the concept had legs. That pairing got us funded, specifically for Consent Management and DSR.

Expansion. Growth from two products to five wasn't re-pitched from scratch each time. Shipping DSR and Consent built enough trust with stakeholders that Privacy Risk, Assessments, and Tracker Scanning got greenlit with less friction. Ongoing customer syncs, not another round of cold outreach, told us where to grow next.

Process Original Babylon Privacy pitch deck slide showing the Assess, Control, Trust framework used to define privacy features

The original framework slide from the pitch deck — organising every privacy need we'd heard on customer calls into three jobs-to-be-done: Assess, Control, Trust. This structure is what got Consent Management and DSR funded.

Each product had a standing weekly customer call, run by the PM with at least one active customer, and I was in every one. Feedback wasn't collected and reviewed later — it was triaged live, as a joint call between me and the PM: what could ship in the next build, and what needed more structural planning. That weekly rhythm, sustained across all five products over several years, is what let the suite evolve at the pace it did without needing a single big pivot to justify each change.

Subject Rights Requests (DSR/SRR). Designed a case management dashboard for data subject requests at scale — intake, automated discovery across connected systems, fulfilment, and audit logging. Integration with Purview's data catalog turned a days-long manual search into an automatic one, surfacing every location a person's data lived. At Microsoft's internal scale, that automation wasn't optional.

Final Shipped DSR case detail view showing a status stepper from Queued through Complete, request properties, and scope fields

The shipped DSR case detail view — status stepper (Queued → Identity validation → Active → Approve → Send → Complete) alongside request properties and scope, so a privacy officer can see exactly where any request stands without opening a separate tracker.

Consent Management. Built a wizard for configuring cookie consent banners — text, behaviour, regional rules (GDPR vs CCPA), CDN deployment — customisable for brand while enforcing the legal elements compliance required. I also designed the deployment tracker, showing where consent models were live and where gaps remained.

Process Low-fidelity wireframe from the original pitch deck showing a persona named Charlie publishing a new consent model

Original low-fi wireframe from the pitch deck — Charlie, a Data Privacy Officer persona, publishing a new consent model and selecting a template.

Final Shipped consent model customization panel with a live device preview of a cookie notification banner

The shipped customization panel — live device preview alongside styling controls, replacing the wireframe's placeholder template list with real brand and layout control.

Privacy Risk Management. Designed insight pages surfacing risk patterns — data shared externally, overshared SharePoint sites, excessive retention — each paired with a recommendation workflow from detection to action. Framing stayed outcome-oriented throughout: "avoid data hoarding," "prevent oversharing."

Final Shipped Alerts dashboard with an alert status donut chart, an active alerts over time trend chart, and a filterable alert list

The shipped Alerts dashboard — status breakdown, an active-alerts-over-time trend, and a filterable list by severity, so a risk pattern is never just a raw count.

Privacy Assessments. Replaced annual questionnaire cycles with a continuously updated record. Forms auto-populated using Purview's data map, suggesting relevant data sources for a given activity — cutting the manual effort for business owners completing assessments.

Final Shipped Assessment builder with question configuration and a conditional logic panel

The shipped Assessment builder — question configuration alongside a conditional logic panel controlling when follow-up questions appear, replacing the static annual questionnaire this product was built to retire.

Tracker Scanning. Designed a scan results page categorising trackers on customer websites — advertising, analytics, functional — alongside compliance gaps like missing notices or undisclosed third-party trackers. Readable at a glance, actionable at a click.

Process Low-fidelity wireframe from the original pitch deck showing Charlie creating a new cookie scanning project

Original low-fi wireframe — Charlie creating a new cookie scanning project, before any real cookie or lineage data existed to design against.

Final Shipped tracker lineage view showing a website, script, and cookie graph with classification labels

The shipped lineage view — website → script → cookie, with each node classified or flagged uncategorised, so a privacy officer can see exactly what a script is doing, not just that it exists.

The largest design challenge across four years was ensuring five distinct, complex products felt like one coherent tool. I contributed to the common navigation scheme and the Microsoft Priva home dashboard — a single entry point giving privacy officers a cross-product view of open DSRs, active risk patterns, and outstanding assessments. Shared visual patterns — identical table layouts, status chips, filter panels — across all five products meant that once a user learned one, they could navigate any of them without relearning.

All five products were developed over four years — DSR and Consent, the first two funded, ran in private preview with 10+ customers from mid-2021, validating the automated discovery and consent workflows against real usage well before public availability. Rather than releasing each product individually as it was completed, all five launched together as Microsoft Priva at the IAPP Global Summit in April 2024 — a single coordinated suite, not a rolling series of feature drops. Priva is now available to all Microsoft 365 customers.

Privacy teams using the platform moved from disconnected manual workflows to a single managed environment — with continuous monitoring replacing static annual snapshots, and automated data discovery replacing multi-day manual searches.

Photo from the Microsoft Priva product launch

Microsoft Priva launching publicly — the culmination of the four-year arc from cold-call research to a coordinated five-product suite.

Project Details
← AI-Powered Privacy Manager Project Babylon — Azure Purview →