DPO Central

A single source of truth for your privacy management program. DPO Central helps organizations manage data inventory, DSARs, assessments, incidents, and vendor relationships from one unified platform.

Hosted pilot

The hosted service is there to try the product. It is free, and it is not meant for real client matter. An instance of your own carries none of the limits below.

Editing lasts 90 days from the organization's first sign-in, and the count never starts before the day the service went live. After that the organization becomes read-only: nothing is removed, and everything can still be exported.

An organization may create 3 impact assessments. The count is of the assessments created, so deleting one does not free a place. The ones already there can still be edited, submitted, approved and exported.

Record ceilings

An organization can hold up to:

  • 25 systems
  • 250 data elements
  • 50 processing activities
  • 100 data flows
  • 50 transfers
  • 50 vendors
  • 50 vendor contracts
  • 100 data subject requests
  • 25 assessments
  • 10 assessment templates
  • 25 incidents
  • 25 AI systems
  • 5 members

An account belongs to one organization.

Exports are not limited, at any stage. Every report and data export stays available while editing is open and after the organization becomes read-only.

There are no contractual safeguards: no data processing agreement, no service level and no security certification.

To work with real customer details, run your own instance.

Quick Start

1

Sign in

Use your email magic link or Google account

2

Set up your organization

Create or join an organization and invite your team

3

Build your data inventory

Register data assets, elements, and processing activities

4

Start managing privacy

Handle DSARs, run assessments, and track incidents

User Roles

DPO Central uses role-based access control. Each role inherits permissions from the roles below it.

Owner

Full control including billing, team management, and organization settings

Admin

Manage users, configure modules, and access all privacy features

Privacy Officer

Full access to all privacy modules, run assessments, manage incidents

Member

Create and edit records, submit DSARs, report incidents

Viewer

Read-only access to dashboards, reports, and records

Reports & PDF Exports

Export professionally formatted PDF reports across every module. Designed for regulators, auditors, board presentations, and internal governance reviews.

Assessment Export

Individual DPIA/LIA detail with Q&A, risk scores, mitigations

Assessment Portfolio

Cross-assessment program status by type, risk, and completion

DSAR Performance

Request volumes, SLA compliance, resolution trends (no PII)

Regulatory Landscape

Jurisdiction analysis with transfer exposure and penalty summary

Data Inventory

Asset register with data elements, flows, and transfers

ROPA

Record of Processing Activities per GDPR Article 30

Vendor Register

Third-party inventory with risk tiers, contracts, and certifications

Breach Register

Incident history with notifications, timelines, and severity breakdown

Open Core Licensing

DPO Central follows an open core model. The core platform is available under AGPL-3.0. Premium modules cost €60 a year each in the kit (your own instance), activated offline with a licence file. The hosted service is a free pilot with limits: every module is included there, and nothing is sold.

Core (Open Source)

  • Data Inventory & ROPA
  • DSAR management & public portal
  • Incident tracking
  • Basic assessments (LIA, Custom)
  • Vendor management (basic)

Premium modules (€60 a year each in the kit)

  • DPIA, PIA, TIA assessments
  • Vendor risk assessments
  • Vendor Catalog (starter catalog of common processors)
  • Advanced audit features
Hosted pilot: free, capped (see docs), and with no contractual safeguards. To deploy real customer details, run your own instance.