Assessments

Conduct privacy impact assessments using configurable templates. Score risks, document mitigations, and manage approval workflows for DPIAs, TIAs, LIAs and custom assessments.

Assessment Templates

Choose a built-in template, or the custom one for a review that none of the others covers. Each template carries its own questions and risk criteria, and every assessment made from one goes through the same approval workflow.

LIA

Legitimate Interests Assessment

Evaluate whether legitimate interests can be relied upon as a legal basis

CUSTOM

Custom Assessment

A flexible template for a privacy review that none of the other types covers

TIA

Transfer Impact Assessment

Evaluate safeguards for international data transfers (Schrems II)

DPIAPremium

Data Protection Impact Assessment

Required under GDPR Article 35 for high-risk processing activities

Every type is open on this hosted service, at no charge and with no lock on the export. The Premium mark applies to the self-hosted kit, where such a type is installed from a signed module.

Approval Workflow

Assessments move through a structured approval workflow. Each stage has clear ownership and the system tracks who approved what and when.

1

Draft

Author creates assessment

2

In Progress

Completing questions

3

Pending Review

Submitted for approval

4

Approved

Assessment signed off

Risk Scoring

Each assessment calculates an overall risk level based on the likelihood and impact of identified risks. The system supports four risk levels.

LOW

MEDIUM

HIGH

CRITICAL

The score is calculated from the answers as you work through the assessment, and the overall level follows from all of them together. It appears on the assessment, on the exported report, and in the portfolio report, which gives the assessments at high risk their own cards.

Risk Mitigations

Document mitigation measures for each identified risk. Track implementation status and assign ownership for follow-up actions.

Example Mitigations

Implement data encryption at rest and in transitImplemented
Add access controls and audit loggingImplemented
Conduct annual vendor security reviewPlanned
Deploy data loss prevention (DLP) toolsIn Progress

Run a DPIA in eight steps

This is the path through the real screens, from the dashboard to the exported report.

1

Start a DPIA from the dashboard

DPO

The dashboard carries a "Start a DPIA" quick action. It opens the new-assessment form with the type already chosen. The Assessments module reaches the same form, for every type the product offers.

2

Name it and create it

DPO

Give the assessment a name. You may link it to a processing activity from your inventory and to a vendor. Both are optional and both feed the auto-fill.

  • A linked processing activity lets the app propose answers from your data inventory
  • A linked vendor brings in its certifications and privacy technologies
3

Choose the frameworks

DPO

The first question asks which rules the assessment has to satisfy: the European ones, the Californian ones, or both. The answer decides which questions appear below and which requirements the report reports on.

  • European Union: Regulation (EU) 2016/679, Articles 35 and 36
  • California: 11 CCR sections 7150, 7152, 7155 and 7157
4

Work through the European steps

DPO

Processing description, scope and context, necessity and proportionality, consultation, risk identification, measures, and residual risk with the conclusion. The pills at the top of the page show how much of each step is answered.

5

Answer the Californian steps

DPO

Shown only when California is chosen. First the activities that make a risk assessment necessary; if none of them applies, the product says so and claims no Californian requirement. Then the nine content items, the timetable, the submission and the executive attestation.

6

Clear what is outstanding

DPO

A panel above the assessment lists everything still missing, in plain words: the questions nobody has answered and the legal requirements nothing covers yet. Every item is a link that jumps to the step and the field that answers it.

7

Record mitigations and approve

Approver

Add mitigation measures for the risks you identified, each with an owner and a due date, then submit. An organisation of one person can submit and approve in a single action; otherwise a named approver approves the assessment, rejects it or returns it for changes. An approved assessment is locked and kept as a record.

8

Export the report

DPO

Export is available at every stage and never refuses. While anything is outstanding the document is marked a draft on every page and lists what is missing on the first one.

The conformance table

Every finished assessment carries a table with one row per requirement of the frameworks you chose, its primary source, and whether the answers cover it. Nothing is marked covered unless an answer covers it, and the report says outright when the assessment does not yet conform to a framework.

European Union

Regulation (EU) 2016/679, Articles 35 and 36

Art. 35(7)(a)A systematic description of the envisaged processing operations and the purposes, including where applicable the legitimate interest pursued
Art. 35(7)(b)An assessment of the necessity and proportionality of the processing in relation to the purposes
Art. 35(7)(c)An assessment of the risks to the rights and freedoms of data subjects
Art. 35(7)(d)The measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance
Art. 35(2)The advice of the data protection officer, where one is designated
Art. 35(9)The views of data subjects or their representatives, where appropriate
Art. 36(1)Prior consultation with the supervisory authority where the residual risk remains high
Art. 35(11)Review when the risk changes

California

11 CCR sections 7150, 7152, 7155 and 7157

11 CCR 7150(b)Whether the processing is one of the six activities that require a risk assessment
11 CCR 7152(a)(1)The purpose of the processing activity
11 CCR 7152(a)(2)The categories of personal information processed, and whether they include sensitive personal information
11 CCR 7152(a)(3)The operational elements of the processing
11 CCR 7152(a)(4)The benefits of the processing to the business, the consumer, other stakeholders and the public
11 CCR 7152(a)(5)The negative impacts on consumers' privacy
11 CCR 7152(a)(6)The safeguards planned to address the negative impacts
11 CCR 7152(a)(7)Whether the business will start or continue the processing, weighing the negative impacts as mitigated against the benefits
11 CCR 7152(a)(8)The names and positions of the people who prepared, reviewed and approved the assessment
11 CCR 7152(a)(9)The dates on which the assessment was reviewed and approved
11 CCR 7155When the assessment must be conducted, when it must be reviewed and updated, and how long it is kept
11 CCR 7157Submission to the agency by 1 April 2028, the executive attestation, and the duty to provide the full assessment within 30 days of a request

The rows below are the requirements the product tracks today. In the report each one also carries its status, covered or outstanding, and the step of the assessment that answers it.

DPO Central provides informational tools and templates, not legal advice. Verify with qualified counsel before relying on outputs.

PDF Exports

Export individual assessments or your entire assessment portfolio as professionally formatted PDF reports. Designed for regulators, auditors, and board presentations.

Individual Assessment Export

Export any single assessment as a detailed PDF with cover page, executive summary, all questions and responses, risk scores, mitigations, and approval history.

Conformance table: one row per requirement, covered or outstanding

Draft mark on every page while anything is outstanding

Cover page with the assessment type and its primary source

Stat cards (risk, completion, mitigations)

Section-by-section Q&A with inline risk badges

Mitigation tracking table

Approval history

Assessment Portfolio Report

Export a cross-assessment summary showing your entire impact assessment programme status, by type, risk level and completion.

Status & risk distribution across all assessments

Type breakdown (DPIA, LIA, Custom)

High risk & overdue detail cards

Mitigation completion tracking

Per-type detail pages

Hosted pilot: free, capped (see docs), and with no contractual safeguards. To deploy real customer details, run your own instance.