The professional DPIA solution for every GDPR-regulated organisation
Create, manage and archive legally watertight Data Protection Impact Assessments. Fully compliant with GDPR, supervisory authority guidelines and the NOREA PIA methodology.
- GDPR-compliant
- Art. 35
- NOREA PIA
- PIA
- EU AI Act
- 2026
Phase C · Risk identification
Threat #12: unauthorised access by third-party processor. Suggested control: pseudonymise the BSN field before transfer.
- ·Threat library: 28/28 reviewed
- ·Pre-assessment: GDPR art. 35 confirmed
- ·DPO advice: requested
Everything you need for DPIA compliance
From data processing to risk analysis: one integrated platform.
- 01
4-Phase Wizard
Step-by-step guidance through the entire DPIA process per the NOREA PIA methodology.
ABasics & scope
7 structured fields
BProportionality
11 NOREA questions
CRisk matrix
5×5 heatmap, 28 threats
DMeasures & DPO advice
Controls + residual risk
2 of 4 phases · 50% - 02
5×5 Risk Matrix
Heatmap with 28 preloaded threat scenarios calibrated across regulated sectors.
28123 - 03
AI Writing Assistant
Generated risk descriptions and measures based on your context, your DPO stays in control.
··✎·DPO · review · accept / reject
- 04
Multi-tenant
Full data separation per organisation with role-based access control.
ORG ARLS
ORG BRLS
ORG CRLS
- 05
EU AI Act module
Classify high-risk AI systems and produce the conformity evidence the supervisor expects.
minimallimitedhighunacceptable - 06
Audit trail & exports
Immutable history, PDF/DOCX export and a coverpage ready for the Autoriteit Persoonsgegevens.
- created
- phase_c_completed
- dpo_advice_requested
- exported.pdf
Step through a real DPIA, phase by phase.
The four phases below are the product's own screens, filled with a worked example: a customer onboarding and sanctions-screening process. Switch phases and watch the risk matrix follow the assessment.
Risk identification
Determine impact and likelihood per threat (5×5)
Assess the 28 pre-loaded threat scenarios. Adjust impact and likelihood per scenario.
- #17
Ransomware attack on an internal system
5 × 3High - #13
Data breach at a processor (SaaS vendor or cloud provider)
4 × 3High - #23
Retention period exceeded without timely deletion
3 × 4High - #20
Unsecured API integration with an external system
3 × 3Medium - #14
Unlawful transfer of data to a third country
4 × 2Medium
- Low (1-4)
- Medium (5-9)
- High (10-15)
- Critical (16-25)
- Critical
- 0
- High
- 3
- Medium
- 2
- Low
- 0
Sample record for illustration. Labels, phases, threat catalogue and 5×5 scoring are identical to the product.
Built on a proven methodology
DPIA Studio integrates the NOREA PIA methodology, supervisory guidelines and EU AI Act requirements into one workflow.
- —NOREA PIA methodology as the basis for risk analysis
- —Pre-assessment checklist integrated into Phase A
- —28 sector-specific threat scenarios
- —EU AI Act classification module (high-risk AI)
- —Full audit trail for accountability
Basics & Context
Processing overview, data subjects, lawfulness
Necessity & Proportionality
Purpose limitation, subsidiarity, data minimisation
Risk Identification
Threat scenarios, impact assessment, heatmap
Measures & Residual Risk
Controls, effectiveness, DPO advice
Built for the rhythm of modern privacy work
- 01
- 0%
- 02
- 0
- 03
- 0
- 04
- 0%
Faster first draft with the AI assistant
Sector-specific threats out of the box
Phases that mirror NOREA PIA
Audit-grade evidence per DPIA
Transparent pricing
Starter
3 editors · 5 reviewers · 12 DPIAs/year
€ 149/mo
Excl. VAT, billed monthly
- ·4-phase wizard
- ·5×5 risk matrix
- ·PDF export with cover page
- ·Email support
Business
Most chosen10 editors · 20 reviewers · 24 DPIAs/year
€ 449/mo
Excl. VAT, billed monthly
- ·Everything in Starter
- ·AI writing assistant
- ·EU AI Act module
- ·Role-based workflow
- ·Priority support
Enterprise
Unlimited editors, reviewers and DPIAs
On request/mo
Excl. VAT, billed monthly
- ·Everything in Business
- ·SSO / SAML
- ·API & webhooks
- ·Group / parent-tenant rollup
- ·SLA guarantee
Includes add-ons for DPO consultants and multi-client advisory practices.
View all plans & add-onsAnswers for privacy teams
Yes. The platform implements GDPR art. 35 verbatim, follows the NOREA PIA methodology and ships an audit-grade trail per DPIA.
“DPIA Studio gave our privacy team back two days a week. The risk matrix and AI assistant are calibrated for the way regulated organisations actually work, and the audit trail makes accountability effortless.”
Ready to professionalise your DPIA practice?
Start a free 7-day trial today or book a 30-minute walkthrough with a privacy specialist.