Data Protection Platform
Can you produce the record - or only the policy?
1
Unified DPO hub
5+
Privacy assurance packs
4
Discovery microservices
The Data Protection Platform is the operational workspace for Data Protection Officers. Consent. Rights. Records of processing. Breaches. Discovery. Privacy assurance. One place for teams that oversee personal data - including where that data meets AI systems.
One hub. Processes that leave a file. Companion discovery services when you need to find what is held.
It is built for day-to-day GDPR work, and for the point where AI systems and personal data are no longer separate questions.
Why organisations use it
Privacy teams are asked, more often now, to show how control actually runs - not only that a policy was approved.
The platform turns that work into a path that can be followed: structured workflows, portals for the people who make requests, discovery tools, and packs that can be signed and exported.
Typical starting points:
- Consent in one system, breaches in a spreadsheet, the RoPA in a document
- AI inventories, DPIAs and monitoring that do not stay linked
- Subject rights with no portal and no complete trail
- Reviewers who want a signed programme rather than a shared folder
- No reliable answer to "where is this person's data?"
What you get
Discover
Find, classify and redact personal data across sources and documents.
Assure
Run GDPR, DPIA, FRIA, TR 27563 and breach-notification programmes with packs you can sign and export.
Operate
Consent, RoPA, breaches and records - status-driven workflows and roles.
Engage
A public portal for subject-access requests, breach reports and feedback. The person making the request does not need a staff account.
From a new processing activity to a breach file, the path is the same: intake ? investigation ? decision ? evidence. An optional AI system inventory and log analysis keep privacy controls attached to the systems that process the data.
Platform capabilities
A modular suite under one DPO hub. Enable what you need. Companion discovery services can stay internal, with API keys and network controls.
DPO Hub
Organisation and project dashboards. Live links to every privacy module and service status.
Consent Library
Purposes, personal-data categories, services, encrypted data subjects, consents, capture API, DSAR export, governed erasure.
Consent Portal
Self-service preference changes. Identity matching. Staff approve-or-reject queues.
Public Rights Portal
External subject-access requests, breach reports, incidents and feedback. Optional anonymous intake.
Breach Operations
A seven-step breach workflow. Operational monitoring records. Service levels. Follow-up evidence.
RoPA Builder
A status-driven Record of Processing - from responsible parties to transparency obligations.
Records Management
File plan, retention, disposal workflow, litigation holds, a permanent disposal log.
Privacy Assurance Packs
GDPR, DPIA, FRIA, ISO/IEC TR 27563 privacy, and breach-notification programmes with sign-off.
Assurance Platform
Versioned programmes, fieldwork, independence checks, plans, evidence packs.
Regulatory Register
Seeded obligations across GDPR, the EU AI Act, NIS2, DORA and the CRA - with a simple compliance score.
System Inventory
Register AI and processing systems. Link monitoring, portal cases and assurance work.
Site Privacy Controls
Cookie banner and privacy notice aligned with GDPR and PECR-style expectations.
Personal Information Discovery
Multi-source search, DSAR packaging, document scan, permanent PDF redaction.
Personal-data detector
Detect personal-data categories in text and structured payloads. Rules you can tune.
Context Privacy Engine
Flag contextual-integrity risks across personal, health, financial and work contexts.
Runtime Analyzer (optional)
Ingest AI logs. Detect drift and anomalies. A human oversight queue. Operational alerts. Pairs with the AI Log Analyzer.
What that looks like in practice
| Outcome | In practice |
|---|---|
| Faster rights fulfilment | Portals, search, packaging and redaction reduce manual DSAR work |
| A clearer breach file | Timed steps, monitoring records, notification packs |
| A living RoPA and records | Workflow-guided processing records. Retention-controlled stores |
| Assurance you can export | Scored programmes, independence checks, signatures, packs |
| Privacy attached to AI | Inventory links consent, monitoring and assessments to real systems |
| One operational home | The DPO hub. Teams stop hunting across disconnected tools |
How teams use it
New processing
RoPA steps -> link the system -> DPIA / FRIA -> consent purposes -> file the evidence.
Subject request
Portal intake -> staff triage -> search and package -> DSAR export -> close.
Breach
Detect -> structured steps and service levels -> notify -> remediate -> keep the file.
Audit cycle
Select the programme -> run the fieldwork -> review and sign -> export the pack -> dashboard roll-up.
That is operations. Not a quarterly reconstruction of what should have happened.
Deployment
A containerised privacy operations stack: central hub, database, companion services for discovery, detection and context checks. Safe database export and import with checksums and a pre-import safety dump. Role-based access throughout.
What you can run depends on the modules you enable, the configuration and the deployment profile.
This page summarises platform capabilities for evaluation. It is not legal advice. Map controls to your controller or processor obligations with counsel.
Related assessments
DPIA and FRIA packs on this platform sit next to the ISO/IEC 42005 AIIA and the Article 27 FRIA work. Personal-data files, system-impact files and fundamental-rights files should tell one story. Separate folders tell three.
If you would like to see a unified DPO hub against your current stack, we can walk through it.
Talk to us