I

One transparent price ladder

Editor seats create DPIAs. Reviewer seats comment and approve. DPIA volumes are calibrated to how real privacy teams work, no cliff, no overage surprises.

Starter

Single privacy owner in one business unit. Scale-up, foundation or independent DPO.

1,639

3 editor seats
5 reviewer seats
12 DPIAs per year
  • 4-phase wizard (Phase A: D)
  • 5×5 risk matrix with 28 threats
  • PDF export with formal cover page
  • Audit trail per DPIA
  • Email support within 1 business day
Start 7-day trial

Business

DPO-led privacy team with multiple processing domains. Mid-market, scale-up group or regulated SaaS.

4,939

10 editor seats
20 reviewer seats
24 DPIAs per year
  • Everything in Starter
  • AI writing assistant
  • EU AI Act module
  • Role-based workflow (DPO, owner, reviewer)
  • Measures register with residual risk
  • Real-time collaboration & comments
  • Priority support within 4 hours
Start 7-day trial

Enterprise

Large enterprise, group structure, parent organisation or regulated network across sectors.

On request

Unlimited editor seats
Unlimited reviewer seats
Unlimited DPIAs
  • Everything in Business
  • SSO via SAML / Microsoft Entra ID
  • Group / parent-tenant rollup
  • API access for custom workflows
  • Audit export to SIEM
  • Dedicated implementation manager
  • SLA with response & resolution targets
  • Custom Data Processing Agreement
  • EU-NL data residency guarantee
Request quote

Prices excl. VAT. Yearly billing gets one month free. Group structures and parent-tenant rollups use the Enterprise tier. DPO consultants and advisory firms: pick the tier that fits your team, then add Multi-client workspaces below.

II

Add-ons & services

  1. Multi-client workspaces

    Fully isolated workspace per client, with its own audit trail and RLS. Built for DPO consultants and advisory firms serving several controllers.

  2. DPIA volume pack

    Adds 10 DPIAs/year to your plan. Stack as many packs as you need, no upsell wall when you hit the cap.

  3. Extra editor seat

    Above the editor seats included in your plan. Reviewer seats can be added the same way at € 9 / reviewer / month.

  4. EU-NL data residency

    Guaranteed storage in a Dutch data centre, with certification and evidence for your records of processing. Included in Enterprise.

  5. SSO / SAML

    Single sign-on with SAML, Azure AD / Microsoft Entra ID or Google Workspace, plus SCIM user provisioning. Available from Business; included in Enterprise.

  6. Spreadsheet import

    We import your existing DPIA register from Excel or CSV in under a day, mapped to phases A–D and the measures library. No charge on any plan.

III

Frequently asked questions

Why editor and reviewer seats instead of one seat type?
Real privacy work has two seat shapes. A DPO or privacy officer authors and edits DPIAs. Process owners, CISO reviewers and legal counsel comment and approve. Splitting them keeps reviewer access generous without inflating the price.
What counts as one DPIA?
One completed file with phases A through D, regardless of revision count. Drafts and re-assessments of the same processing within 12 months do not count as a new DPIA.
What if we exceed our DPIA cap?
Add a DPIA volume pack (+10 DPIAs/year, € 39/month), stack as many as you need. If you're routinely running out, moving up a tier is usually cheaper than stacking packs.
I'm a DPO consultant or advisory firm, which tier?
Pick the tier that fits your own team, then add Multi-client workspaces (€ 49/month per client). Each client gets an isolated workspace with its own audit trail and RLS. National firms and Big-4 practices go Enterprise.
How does this relate to the NOREA PIA methodology?
All plans follow the NOREA PIA methodology by default. No separate module, no surcharge.
Can I upgrade or downgrade mid-cycle?
Upgrades take effect immediately; downgrades take effect on the next billing period. Add-ons are cancellable monthly.
Is there a trial period?
Yes: 7 days fully functional without a credit card. Convert or cancel at any time.
Does this work for private-sector organisations?
Yes. GDPR Art. 35 and the EU AI Act apply to public and private controllers equally. The engine, threat library and workflow are sector-agnostic.
IV

Ready to professionalise your DPIA practice?

Start today with a free 7-day trial or schedule a demo with one of our privacy specialists.