Standard · GDPR Article 35

DPIA, run as a three-stage workflow.

One workspace that walks a data protection impact assessment from the processing context through the Article 35 questionnaire to a risk-tagged PDF report. Conditional sub-questions only surface when the answer above earns them. Evidence attaches to the question it supports.

Sign in and open DPIA

First month free. No card required.

The three stages.

Stage 1 — Project intake
  1. Open a new DPIA. Capture the project name, client, owner, and a short description of the processing activity.
  2. One screen. Save and you land in the workspace where the rest of the work happens.
Stage 2 — Article 35 questionnaire
  1. Walk the questionnaire section by section — lawfulness, necessity, risks, and safeguards.
  2. Conditional sub-questions only appear when an answer above triggers them, so you do not defend blanks that do not apply.
  3. Each answer is tagged with a risk weight — High, Medium, Low.
  4. Auto-saves on every change.
Stage 3 — Evidence and risk review
  1. Attach evidence directly to the question it supports — DPAs, retention schedules, screenshots, anything that backs the answer.
  2. Uploader and timestamp are recorded automatically against the file.
  3. Read the risk-tagged summary across all answers and jump back to anything that needs editing before it goes to the DPO.
Output — Regulator-ready PDF
  1. Click once. The PDF compiles in the background and downloads to your machine.
  2. The report rolls the processing context, every answer, the attached evidence references, and the risk weighting into a single document.
  3. The report stays available from the assessment forever — regenerate any time.