DPIAs that read like an assessment, not a form you filled in afterwards.
Article 35 exists to make you pause before you deploy something high-risk. ISO-STANDARD.app runs the whole cycle: an EDPB-based screening test that tells you whether a DPIA is even required, a guided assessment with plain-English prompts, risk scoring aimed at harm to the individual, and an immutable signed-off version your regulator, your DPO and your enterprise buyer can all read.
Why most DPIAs fail an ICO review
Two failure modes dominate. The first is the retrospective DPIA — written after launch, so it documents decisions instead of shaping them. The second is the risk table that scores fines and reputational damage to the business rather than harm to the person whose data is being processed. Both are visible to a regulator within a page.
The platform enforces the structure Article 35(7) actually asks for: a description of the processing, an assessment of necessity and proportionality, the risks to the rights and freedoms of data subjects, and the measures that address them. Where residual risk stays high, it tells you plainly that Article 36(1) prior consultation with the ICO applies.
Features
EDPB screening wizard
Nine-criteria screening test with a recorded outcome, so you can evidence why a DPIA was or was not required for any given project.
AI-drafted first pass
Describe the processing in your own words and the AI drafts every narrative section and suggests risks to individuals, always leaving placeholders where a fact is needed.
Harm-based risk scoring
Likelihood and severity scored before and after your measures, with automatic residual banding and a prior-consultation flag when high risk remains.
Mitigations become real actions
Push any measure straight into the remediation tracker with an owner and a due date — the DPIA stops being a document and becomes a work plan.
Scheduled reviews
DPIAs are living documents. Set a review date and the owner gets chased by email before it falls due.
Locked versions and PDF export
Sign-off snapshots an immutable version. Export a branded PDF for the ICO, your DPO or a customer's procurement team.
Who it's for
SMEs launching an AI or analytics feature
Pain: You know a DPIA is probably needed but no one is sure what 'high risk' means or what goes in it.
With ISO-STANDARD.app: Screening tells you whether it applies; guided prompts and AI drafting get a defensible assessment written the same day.
DPOs and privacy consultants
Pain: DPIAs scattered across Word files with no review dates and no version history.
With ISO-STANDARD.app: One register per client workspace, locked versions, review reminders and exportable packs.
Teams already running ISO 27001 or ISO 42001
Pain: Privacy risk assessed separately from information-security risk, so mitigations never get tracked.
With ISO-STANDARD.app: DPIA measures land in the same remediation tracker as your control and audit actions.
Run your first DPIA this afternoon
Start with the screening test, pick a template for HR, CCTV, marketing or AI processing, and let the platform take it through to sign-off.
Assisted drafting for policies, risks, controls and buyer questionnaires. Every AI suggestion is reviewed and approved by you before it lands in the record.
Opt-in, workspace-scoped
AI features run only when you invoke them, only against the workspace you're in. We never mine your data to answer someone else's prompt.
Your data stays yours
Prompts routed via the AI Gateway to model providers whose API terms exclude your content from model training. Nothing is sold or shared for advertising.
Isolated by design
Row-level security enforces workspace boundaries at the database. MFA, SSO, audit logs and least-privilege roles govern who sees what.
We never sell personal information, never share it for advertising, and never use your workspace content to train third-party models. Full sub-processor list and Acceptable Use Policy on the Trust page.
MM
Michael McCarroll
Founder · 25+ years
IT governance · Information security · AI
Why this platform exists
Enterprise-grade governance — built for the SMEs and consultants enterprise GRC forgets.
I've spent 25 years in corporate governance — aligning technology, controls and compliance with what the business is actually trying to do. Time and again, the same pattern: the organisations that win new clients aren't the ones with the biggest GRC budget. They're the ones who can demonstrate trust on demand. This platform is the tool I wanted for the SMEs and consultants I've worked with — institutional-grade governance without an institutional price tag, built on the way audits and buyer reviews actually happen.