Assessments
Conduct privacy impact assessments using configurable templates. Score risks, document mitigations, and manage approval workflows for DPIAs, TIAs, LIAs and custom assessments.
Assessment Templates
Choose a built-in template, or the custom one for a review that none of the others covers. Each template carries its own questions and risk criteria, and every assessment made from one goes through the same approval workflow.
Legitimate Interests Assessment
Evaluate whether legitimate interests can be relied upon as a legal basis
Custom Assessment
A flexible template for a privacy review that none of the other types covers
Transfer Impact Assessment
Evaluate safeguards for international data transfers (Schrems II)
Data Protection Impact Assessment
Required under GDPR Article 35 for high-risk processing activities
Every type is open on this hosted service, at no charge and with no lock on the export. The Premium mark applies to the self-hosted kit, where such a type is installed from a signed module.
Approval Workflow
Assessments move through a structured approval workflow. Each stage has clear ownership and the system tracks who approved what and when.
Draft
Author creates assessment
In Progress
Completing questions
Pending Review
Submitted for approval
Approved
Assessment signed off
Risk Scoring
Each assessment calculates an overall risk level based on the likelihood and impact of identified risks. The system supports four risk levels.
LOW
MEDIUM
HIGH
CRITICAL
The score is calculated from the answers as you work through the assessment, and the overall level follows from all of them together. It appears on the assessment, on the exported report, and in the portfolio report, which gives the assessments at high risk their own cards.
Risk Mitigations
Document mitigation measures for each identified risk. Track implementation status and assign ownership for follow-up actions.
Example Mitigations
Run a DPIA in eight steps
This is the path through the real screens, from the dashboard to the exported report.
Start a DPIA from the dashboard
DPOThe dashboard carries a "Start a DPIA" quick action. It opens the new-assessment form with the type already chosen. The Assessments module reaches the same form, for every type the product offers.
Name it and create it
DPOGive the assessment a name. You may link it to a processing activity from your inventory and to a vendor. Both are optional and both feed the auto-fill.
- •A linked processing activity lets the app propose answers from your data inventory
- •A linked vendor brings in its certifications and privacy technologies
Choose the frameworks
DPOThe first question asks which rules the assessment has to satisfy: the European ones, the Californian ones, or both. The answer decides which questions appear below and which requirements the report reports on.
- •European Union: Regulation (EU) 2016/679, Articles 35 and 36
- •California: 11 CCR sections 7150, 7152, 7155 and 7157
Work through the European steps
DPOProcessing description, scope and context, necessity and proportionality, consultation, risk identification, measures, and residual risk with the conclusion. The pills at the top of the page show how much of each step is answered.
Answer the Californian steps
DPOShown only when California is chosen. First the activities that make a risk assessment necessary; if none of them applies, the product says so and claims no Californian requirement. Then the nine content items, the timetable, the submission and the executive attestation.
Clear what is outstanding
DPOA panel above the assessment lists everything still missing, in plain words: the questions nobody has answered and the legal requirements nothing covers yet. Every item is a link that jumps to the step and the field that answers it.
Record mitigations and approve
ApproverAdd mitigation measures for the risks you identified, each with an owner and a due date, then submit. An organisation of one person can submit and approve in a single action; otherwise a named approver approves the assessment, rejects it or returns it for changes. An approved assessment is locked and kept as a record.
Export the report
DPOExport is available at every stage and never refuses. While anything is outstanding the document is marked a draft on every page and lists what is missing on the first one.
The conformance table
Every finished assessment carries a table with one row per requirement of the frameworks you chose, its primary source, and whether the answers cover it. Nothing is marked covered unless an answer covers it, and the report says outright when the assessment does not yet conform to a framework.
European Union
Regulation (EU) 2016/679, Articles 35 and 36
California
11 CCR sections 7150, 7152, 7155 and 7157
The rows below are the requirements the product tracks today. In the report each one also carries its status, covered or outstanding, and the step of the assessment that answers it.
DPO Central provides informational tools and templates, not legal advice. Verify with qualified counsel before relying on outputs.
PDF Exports
Export individual assessments or your entire assessment portfolio as professionally formatted PDF reports. Designed for regulators, auditors, and board presentations.
Individual Assessment Export
Export any single assessment as a detailed PDF with cover page, executive summary, all questions and responses, risk scores, mitigations, and approval history.
✓ Conformance table: one row per requirement, covered or outstanding
✓ Draft mark on every page while anything is outstanding
✓ Cover page with the assessment type and its primary source
✓ Stat cards (risk, completion, mitigations)
✓ Section-by-section Q&A with inline risk badges
✓ Mitigation tracking table
✓ Approval history
Assessment Portfolio Report
Export a cross-assessment summary showing your entire impact assessment programme status, by type, risk level and completion.
✓ Status & risk distribution across all assessments
✓ Type breakdown (DPIA, LIA, Custom)
✓ High risk & overdue detail cards
✓ Mitigation completion tracking
✓ Per-type detail pages