Risk & Compliance

Impact assessments
that regulators trust

Guided multi-step assessment wizard with enforced two-person approval workflows, risk findings tracking, and immutable records that prove your due diligence.

8-Step DPIA Wizard

Guided assessment wizard: Project Description → Data Inventory → Necessity & Proportionality → Risk Identification → Risk Mitigation → Stakeholder Consultation → DPO Opinion → Summary & Sign-off.

Two-Person Approval

GDPR Art.35(2) requires independent review. FOCTTA enforces: Compliance Analyst creates → DPO reviews and opines → Legal Reviewer approves or rejects. No single person can both create and approve.

Risk Findings

Identify and track risk findings per assessment. Each finding has likelihood (1-5), impact (1-5), auto-computed risk score, category, mitigation plan, and optional promotion to the Risk Register.

Multiple Templates

GDPR Standard DPIA (8 steps), GDPR Lite DPIA (5 steps), and DPDPA Privacy Impact Assessment (6 steps). Templates define step count, titles, and required fields.

Immutable After Approval

Once approved, assessments and their findings become immutable. Any modification returns 409 Conflict. Re-assessment requires a new version — preserving the complete approval history.

PDF Export

Generate comprehensive PDF reports with assessment details, wizard answers, findings table, DPO opinion, legal approval, and risk heatmap. Stored in S3 with signed URL access.

Why teams choose this

GDPR Art.35(2) compliant two-person approval workflow
Guided wizard ensures no assessment step is skipped
Risk findings link directly to the Risk Register
Immutable post-approval ensures regulatory integrity
Processing activity linkage answers "has this been assessed?"
Re-assessment versioning preserves complete history
PDF export for regulatory submissions and board presentations
Scheduled review reminders 14 days before next_review_date
DPIA

Ready to get started?

See dpia / pia assessments in action with a personalized demo.

Request a Demo