Standard · GDPR Article 35
GDPR DPIA compliance, run as a three-stage workflow.
One workspace that walks a data protection impact assessment from the processing context through the Article 35 questionnaire to a risk-tagged PDF report. Conditional sub-questions only surface when the answer above earns them. Evidence attaches to the question it supports.
First month free. No card required.
The three stages.
- Stage 1 — Project intake
- Open a new DPIA. Capture the project name, client, owner, and a short description of the processing activity.
- One screen. Save and you land in the workspace where the rest of the work happens.
- Stage 2 — Article 35 questionnaire
- Walk the questionnaire section by section — lawfulness, necessity, risks, and safeguards.
- Conditional sub-questions only appear when an answer above triggers them, so you do not defend blanks that do not apply.
- Each answer is tagged with a risk weight — High, Medium, Low.
- Auto-saves on every change.
- Stage 3 — Evidence and risk review
- Attach evidence directly to the question it supports — DPAs, retention schedules, screenshots, anything that backs the answer.
- Uploader and timestamp are recorded automatically against the file.
- Read the risk-tagged summary across all answers and jump back to anything that needs editing before it goes to the DPO.
- Output — Regulator-ready PDF
- Click once. The PDF compiles in the background and downloads to your machine.
- The report rolls the processing context, every answer, the attached evidence references, and the risk weighting into a single document.
- The report stays available from the assessment forever — regenerate any time.
Self-serve, or guided by a consultant.
- Self-serve
- Your team runs the DPIA end to end. The owner, the DPO, and any other internal reviewers all work inside the same workspace. You pay only the platform fee.
- Guided
- An independent privacy consultant from the SME directory joins the workspace as a reviewer. They walk the questionnaire alongside you, flag answers that need attention, and sign off the final report. You pay the platform fee plus the consultant's review fee, prorated by the day.
Two rates. One while you work. One after.
Activewhile the questionnaire and evidence are still in motion.
Passiveonce the DPIA report ships and the workspace becomes a read-only record.
Self-serve
Your team runs the DPIA end to end.
$75 / month
$10 / month
Guided
Platform fee plus an independent consultant from the SME directory. Browse rates after you sign in.
See directory
See directory
Rates shown are indicative. The exact daily number is displayed inside the product before any assessment is launched.
How the meter works.
- Why two rates
- A DPIA is a living document. You finish it once and revisit it whenever the processing changes. The meter is split so you pay full rate only while the questionnaire and evidence are in motion, and a much lower rate while the signed-off report sits as a reference.
- Prorated daily
- Charges add up by the day. No annual contract. No per-seat fee. Cancel any time and the meter stops on the cancel date.
- First month free
- The first assessment on your first workflow is free for the first month. No card required at sign-up.
- Switch when the DPO signs off
- Flip the assessment to passive and the meter drops to the lower rate. The questionnaire, evidence, and PDF report stay accessible and exportable.
When you need a DPIA — and how a guided workflow produces one
A Data Protection Impact Assessment (DPIA) is the GDPR’s mandatory risk assessment for processing that is "likely to result in a high risk to the rights and freedoms of natural persons" — Article 35. In practice that captures far more than most teams expect: systematic profiling or scoring of people, large-scale processing of sensitive data, systematic monitoring of public areas, matching datasets, processing children’s data at scale, and — increasingly — deploying AI systems that make or support decisions about individuals. European regulators publish their own must-DPIA lists on top of the GDPR’s criteria, and skipping a required DPIA is itself an infringement, independent of whether the processing ever causes harm.
A defensible DPIA has a defined shape: a systematic description of the processing and its purposes, an assessment of necessity and proportionality, an identification of risks to data subjects, and the measures that bring those risks down — with the DPO consulted and the outcome documented before processing starts. The common failure mode is treating it as a one-off essay: unstructured documents that miss assessment criteria, cannot be compared across projects, and are painful to update when the processing changes.
regXperience runs each DPIA as a guided three-stage workflow. Stage one is project intake: what is being processed, about whom, why, and through which systems and processors. Stage two is the structured Article 35 questionnaire, walking assessors through necessity, proportionality and risk criteria question by question. Stage three is evidence and risk review — attach the supporting material, record the mitigations and residual risk, and export a regulator-ready PDF report your DPO or supervisory authority can read without a walkthrough. Every DPIA follows the same structure, so your tenth assessment is as consistent as your first.
See pricing — pay by the day, no annual contract — or browse the compliance guides to go deeper.
Frequently asked questions
When is a DPIA legally required under GDPR?
Whenever processing is likely to be high-risk for individuals — Article 35(3) names systematic and extensive profiling with significant effects, large-scale processing of special-category or criminal-offence data, and systematic large-scale monitoring of publicly accessible areas. National regulators extend this with their own mandatory lists (new technologies, biometrics, location tracking, children’s data and more). If you are unsure, running the screening questions in a DPIA tool is faster than debating it.
Do I need a DPIA for AI systems?
Very often, yes. AI systems that profile, score or make decisions about people typically meet the "new technology + systematic evaluation" criteria that trigger Article 35, and EU regulators consistently flag AI deployments as DPIA territory. A DPIA is also a natural on-ramp for EU AI Act obligations, since much of the risk analysis overlaps.
What must a DPIA contain?
Article 35(7) requires four elements: a systematic description of the processing operations and purposes (including legitimate interests pursued), an assessment of necessity and proportionality, an assessment of the risks to data subjects’ rights and freedoms, and the measures envisaged to address those risks and demonstrate compliance. The regXperience questionnaire maps to these elements, and the exported report presents them in that order.
Who should carry out the DPIA?
The controller is responsible, with the advice of the Data Protection Officer where one is appointed, and with processors contributing details of their processing. In practice a product or project owner completes the intake and questionnaire, and the DPO or privacy counsel reviews — the regXperience workflow assigns those roles explicitly so the review trail is visible.
Start your first workflow — first month free
Sign in to start