2020 – 2024 · Microsoft Priva
2020 – 2024 · Microsoft Priva
Microsoft Priva · DSR · Consent · Risk · Assessments · Tracker Scanning
The Problem
Privacy operations at large enterprises were running on duct tape. Subject rights requests were tracked in shared spreadsheets. Consent models were managed through third-party tools that didn't connect to internal data. Privacy risk assessments meant emailing questionnaires and waiting weeks for responses.
Microsoft's opportunity was to replace all of this with a unified, automated privacy operations platform built natively into the Microsoft 365 ecosystem that millions of enterprise customers already used.
My Role
I led end-to-end UX design across all five privacy products over four years, developed largely in parallel rather than sequentially, from initial concept through public launch. I also contributed to the unified navigation and home experience that tied all five products together as Microsoft Priva.
Origin
Research/input. Priva started as two PMs and me, with a hypothesis and no funded product — one of several workstreams running inside the broader, multi-year Babylon effort that was simultaneously building out what would become Azure Purview. I took part in the research directly: cold-calling privacy professionals on LinkedIn, with no existing product to anchor the conversation, just questions about how they handled compliance today.
Insight. Two patterns showed up in nearly every call. Everything was manual — Excel trackers, offline processes, no system of record. And everything was disconnected — a privacy officer juggling five separate processes with no single place to see status across any of them.
Decision. The team wrote a white paper synthesising what we'd heard. I built the case for it visually — low-fidelity PowerPoint walkthroughs with wireframes, structured around a fictional company and named personas, each with their own scenario walked step by step: log in, select a workflow, complete a form, see the result. Kept deliberately rough so we could socialise the idea quickly and iterate without over-investing before we knew the concept had legs. That pairing got us funded, specifically for Consent Management and DSR.
Expansion. Growth from two products to five wasn't re-pitched from scratch each time. Shipping DSR and Consent built enough trust with stakeholders that Privacy Risk, Assessments, and Tracker Scanning got greenlit with less friction. Ongoing customer syncs, not another round of cold outreach, told us where to grow next.
The original framework slide from the pitch deck — organising every privacy need we'd heard on customer calls into three jobs-to-be-done: Assess, Control, Trust. This structure is what got Consent Management and DSR funded.
Design Process — Customer Feedback Loop
Each product had a standing weekly customer call, run by the PM with at least one active customer, and I was in every one. Feedback wasn't collected and reviewed later — it was triaged live, as a joint call between me and the PM: what could ship in the next build, and what needed more structural planning. That weekly rhythm, sustained across all five products over several years, is what let the suite evolve at the pace it did without needing a single big pivot to justify each change.
The Five Products
Subject Rights Requests (DSR/SRR). Designed a case management dashboard for data subject requests at scale — intake, automated discovery across connected systems, fulfilment, and audit logging. Integration with Purview's data catalog turned a days-long manual search into an automatic one, surfacing every location a person's data lived. At Microsoft's internal scale, that automation wasn't optional.
The shipped DSR case detail view — status stepper (Queued → Identity validation → Active → Approve → Send → Complete) alongside request properties and scope, so a privacy officer can see exactly where any request stands without opening a separate tracker.
Consent Management. Built a wizard for configuring cookie consent banners — text, behaviour, regional rules (GDPR vs CCPA), CDN deployment — customisable for brand while enforcing the legal elements compliance required. I also designed the deployment tracker, showing where consent models were live and where gaps remained.
Original low-fi wireframe from the pitch deck — Charlie, a Data Privacy Officer persona, publishing a new consent model and selecting a template.
The shipped customization panel — live device preview alongside styling controls, replacing the wireframe's placeholder template list with real brand and layout control.
Privacy Risk Management. Designed insight pages surfacing risk patterns — data shared externally, overshared SharePoint sites, excessive retention — each paired with a recommendation workflow from detection to action. Framing stayed outcome-oriented throughout: "avoid data hoarding," "prevent oversharing."
The shipped Alerts dashboard — status breakdown, an active-alerts-over-time trend, and a filterable list by severity, so a risk pattern is never just a raw count.
Privacy Assessments. Replaced annual questionnaire cycles with a continuously updated record. Forms auto-populated using Purview's data map, suggesting relevant data sources for a given activity — cutting the manual effort for business owners completing assessments.
The shipped Assessment builder — question configuration alongside a conditional logic panel controlling when follow-up questions appear, replacing the static annual questionnaire this product was built to retire.
Tracker Scanning. Designed a scan results page categorising trackers on customer websites — advertising, analytics, functional — alongside compliance gaps like missing notices or undisclosed third-party trackers. Readable at a glance, actionable at a click.
Original low-fi wireframe — Charlie creating a new cookie scanning project, before any real cookie or lineage data existed to design against.
The shipped lineage view — website → script → cookie, with each node classified or flagged uncategorised, so a privacy officer can see exactly what a script is doing, not just that it exists.
Unified Experience
The largest design challenge across four years was ensuring five distinct, complex products felt like one coherent tool. I contributed to the common navigation scheme and the Microsoft Priva home dashboard — a single entry point giving privacy officers a cross-product view of open DSRs, active risk patterns, and outstanding assessments. Shared visual patterns — identical table layouts, status chips, filter panels — across all five products meant that once a user learned one, they could navigate any of them without relearning.
Outcome
All five products were developed over four years — DSR and Consent, the first two funded, ran in private preview with 10+ customers from mid-2021, validating the automated discovery and consent workflows against real usage well before public availability. Rather than releasing each product individually as it was completed, all five launched together as Microsoft Priva at the IAPP Global Summit in April 2024 — a single coordinated suite, not a rolling series of feature drops. Priva is now available to all Microsoft 365 customers.
Privacy teams using the platform moved from disconnected manual workflows to a single managed environment — with continuous monitoring replacing static annual snapshots, and automated data discovery replacing multi-day manual searches.
Microsoft Priva launching publicly — the culmination of the four-year arc from cold-call research to a coordinated five-product suite.