DPIAs that read like an assessment, not a form you filled in afterwards.

Article 35 exists to make you pause before you deploy something high-risk. ISO-STANDARD.app runs the whole cycle: an EDPB-based screening test that tells you whether a DPIA is even required, a guided assessment with plain-English prompts, risk scoring aimed at harm to the individual, and an immutable signed-off version your regulator, your DPO and your enterprise buyer can all read.

Why most DPIAs fail an ICO review

Two failure modes dominate. The first is the retrospective DPIA — written after launch, so it documents decisions instead of shaping them. The second is the risk table that scores fines and reputational damage to the business rather than harm to the person whose data is being processed. Both are visible to a regulator within a page.

The platform enforces the structure Article 35(7) actually asks for: a description of the processing, an assessment of necessity and proportionality, the risks to the rights and freedoms of data subjects, and the measures that address them. Where residual risk stays high, it tells you plainly that Article 36(1) prior consultation with the ICO applies.

Features

EDPB screening wizard

Nine-criteria screening test with a recorded outcome, so you can evidence why a DPIA was or was not required for any given project.

AI-drafted first pass

Describe the processing in your own words and the AI drafts every narrative section and suggests risks to individuals, always leaving placeholders where a fact is needed.

Harm-based risk scoring

Likelihood and severity scored before and after your measures, with automatic residual banding and a prior-consultation flag when high risk remains.

Mitigations become real actions

Push any measure straight into the remediation tracker with an owner and a due date — the DPIA stops being a document and becomes a work plan.

Scheduled reviews

DPIAs are living documents. Set a review date and the owner gets chased by email before it falls due.

Locked versions and PDF export

Sign-off snapshots an immutable version. Export a branded PDF for the ICO, your DPO or a customer's procurement team.

Who it's for

SMEs launching an AI or analytics feature

Pain: You know a DPIA is probably needed but no one is sure what 'high risk' means or what goes in it.

With ISO-STANDARD.app: Screening tells you whether it applies; guided prompts and AI drafting get a defensible assessment written the same day.

DPOs and privacy consultants

Pain: DPIAs scattered across Word files with no review dates and no version history.

With ISO-STANDARD.app: One register per client workspace, locked versions, review reminders and exportable packs.

Teams already running ISO 27001 or ISO 42001

Pain: Privacy risk assessed separately from information-security risk, so mitigations never get tracked.

With ISO-STANDARD.app: DPIA measures land in the same remediation tracker as your control and audit actions.

Run your first DPIA this afternoon

Start with the screening test, pick a template for HR, CCTV, marketing or AI processing, and let the platform take it through to sign-off.

Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.

AI-enabled — privacy-respecting

AI does the drafting. You keep the control — and the data.

How we handle data →
  • AI that assists — not replaces

    Assisted drafting for policies, risks, controls and buyer questionnaires. Every AI suggestion is reviewed and approved by you before it lands in the record.

  • Opt-in, workspace-scoped

    AI features run only when you invoke them, only against the workspace you're in. We never mine your data to answer someone else's prompt.

  • Your data stays yours

    Prompts routed via the AI Gateway to model providers whose API terms exclude your content from model training. Nothing is sold or shared for advertising.

  • Isolated by design

    Row-level security enforces workspace boundaries at the database. MFA, SSO, audit logs and least-privilege roles govern who sees what.

We never sell personal information, never share it for advertising, and never use your workspace content to train third-party models. Full sub-processor list and Acceptable Use Policy on the Trust page.

MM
Michael McCarroll
Founder · 25+ years
IT governance · Information security · AI
Why this platform exists

Enterprise-grade governance — built for the SMEs and consultants enterprise GRC forgets.

I've spent 25 years in corporate governance — aligning technology, controls and compliance with what the business is actually trying to do. Time and again, the same pattern: the organisations that win new clients aren't the ones with the biggest GRC budget. They're the ones who can demonstrate trust on demand. This platform is the tool I wanted for the SMEs and consultants I've worked with — institutional-grade governance without an institutional price tag, built on the way audits and buyer reviews actually happen.