I

The professional DPIA solution for every GDPR-regulated organisation

Create, manage and archive legally watertight Data Protection Impact Assessments. Fully compliant with GDPR, supervisory authority guidelines and the NOREA PIA methodology.

Art. 35
PIA
2026

Phase C · Risk identification

Threat #12: unauthorised access by third-party processor. Suggested control: pseudonymise the BSN field before transfer.

  • Threat library: 28/28 reviewed
  • Pre-assessment: GDPR art. 35 confirmed
  • DPO advice: requested
3 × 2
II

Everything you need for DPIA compliance

From data processing to risk analysis: one integrated platform.

  1. 4-Phase Wizard

    Step-by-step guidance through the entire DPIA process per the NOREA PIA methodology.

    Basics & scope

    7 structured fields

    Proportionality

    11 NOREA questions

    Risk matrix

    5×5 heatmap, 28 threats

    Measures & DPO advice

    Controls + residual risk

  2. 5×5 Risk Matrix

    Heatmap with 28 preloaded threat scenarios calibrated across regulated sectors.

  3. AI Writing Assistant

    Generated risk descriptions and measures based on your context, your DPO stays in control.

  4. Multi-tenant

    Full data separation per organisation with role-based access control.

  5. EU AI Act module

    Classify high-risk AI systems and produce the conformity evidence the supervisor expects.

  6. Audit trail & exports

    Immutable history, PDF/DOCX export and a coverpage ready for the Autoriteit Persoonsgegevens.

III

Step through a real DPIA, phase by phase.

The four phases below are the product's own screens, filled with a worked example: a customer onboarding and sanctions-screening process. Switch phases and watch the risk matrix follow the assessment.

Risk identification

Determine impact and likelihood per threat (5×5)

Assess the 28 pre-loaded threat scenarios. Adjust impact and likelihood per scenario.

  • Ransomware attack on an internal system

    5 × 3High
  • Data breach at a processor (SaaS vendor or cloud provider)

    4 × 3High
  • Retention period exceeded without timely deletion

    3 × 4High
  • Unsecured API integration with an external system

    3 × 3Medium
  • Unlawful transfer of data to a third country

    4 × 2Medium
5
10
151×
20
25
4
81×
121×
16
20
3
6
91×
121×
15
2
4
6
8
10
1
2
3
4
5
0
3
2
0

Sample record for illustration. Labels, phases, threat catalogue and 5×5 scoring are identical to the product.

IV

Built on a proven methodology

DPIA Studio integrates the NOREA PIA methodology, supervisory guidelines and EU AI Act requirements into one workflow.

  • NOREA PIA methodology as the basis for risk analysis
  • Pre-assessment checklist integrated into Phase A
  • 28 sector-specific threat scenarios
  • EU AI Act classification module (high-risk AI)
  • Full audit trail for accountability
A

Basics & Context

Processing overview, data subjects, lawfulness

B

Necessity & Proportionality

Purpose limitation, subsidiarity, data minimisation

C

Risk Identification

Threat scenarios, impact assessment, heatmap

D

Measures & Residual Risk

Controls, effectiveness, DPO advice

V

Built for the rhythm of modern privacy work

0%

Faster first draft with the AI assistant

0

Sector-specific threats out of the box

0

Phases that mirror NOREA PIA

0%

Audit-grade evidence per DPIA

VI

Transparent pricing

Starter

3 editors · 5 reviewers · 12 DPIAs/year

€ 149

  • ·4-phase wizard
  • ·5×5 risk matrix
  • ·PDF export with cover page
  • ·Email support
Get started

Business

10 editors · 20 reviewers · 24 DPIAs/year

€ 449

  • ·Everything in Starter
  • ·AI writing assistant
  • ·EU AI Act module
  • ·Role-based workflow
  • ·Priority support
Get started

Enterprise

Unlimited editors, reviewers and DPIAs

On request

  • ·Everything in Business
  • ·SSO / SAML
  • ·API & webhooks
  • ·Group / parent-tenant rollup
  • ·SLA guarantee
Get started

Includes add-ons for DPO consultants and multi-client advisory practices.

VII

Answers for privacy teams

Yes. The platform implements GDPR art. 35 verbatim, follows the NOREA PIA methodology and ships an audit-grade trail per DPIA.

DPIA Studio gave our privacy team back two days a week. The risk matrix and AI assistant are calibrated for the way regulated organisations actually work, and the audit trail makes accountability effortless.

Ready to professionalise your DPIA practice?

Start a free 7-day trial today or book a 30-minute walkthrough with a privacy specialist.