Practical, interactive toolkits — a readiness checker, a full DPIA template and an Article 30 / Section 8 RoPA. Fill them in here, save to your browser, then print to PDF or export to CSV. Nothing is uploaded; everything stays on your device.
Scope, lawful basis, notice, consent, rights, retention, transfers and breach in one pass.
Every answer maps to a control, with a risk rating and a suggested order of remediation.
Runs entirely in your browser, in line with our own privacy notice.
Aligned to GDPR Article 35 and DPDP Rule 13. Complete the four parts below, add the risks you identify, and export. Your entries auto-save in this browser.
| Risk to individuals | Likelihood | Severity | Rating | Mitigation / control |
|---|
Saved to this browser.
Aligned to GDPR Article 30 and DPDP Section 8 accountability. Add one row per processing activity. Two sample rows are included — edit or delete them.
| Processing activity | Purpose | Data subjects | Categories of data | Lawful basis | Recipients | Retention | Transfers | Safeguards |
|---|
Saved to this browser.
Capture, evidence and withdraw consent with a defensible audit trail. CSV-ready columns: subject, purpose, timestamp, method, status, withdrawal.
Horizon scanning of amendments and commencements across the jurisdictions you operate in.
Due-diligence set for processors, sub-processors and cross-border recipients.
Log, assess and notify within statutory windows, with role assignments.
Mechanisms and assessments for cross-border transfers.
Checklist mapping controls to ISO/IEC 27001, 27701 and 42001 evidence.
We can adapt every template to your systems, vendors and jurisdictions, and train your team to maintain them.
Talk to a consultant