The software for DPOs and privacy consultants managing multiple clients: records of processing, data breach, DPIA, deadlines and documents for every client in one place. Each client gets a private link to send you privacy reports in real time.
Built by a DPO, for DPOs.
I'm Pietro Cravero, certified Data Protection Officer and founder of Studio Cravero Consulting. DPO Workspace comes from my daily GDPR consulting work for public administrations and private organizations.
Every feature is designed to solve an operational problem I've encountered myself. No vaporware. No magical automation promises. Just tools you actually use every day.
Article 30 records in 5 different spreadsheets — Updated on different dates, you don't know which one is the latest.
Client A's deadlines in Client B's calendar — You miss a periodic review and only notice it afterwards.
Data breach: 20 minutes to find the documents — When a client calls, you waste precious time of the 72h window.
Regulatory updates pushed only to callers — You share them only with clients who call. Others fall behind.
Not a generic tool retrofitted for privacy. A workspace designed around the real workflow of an external DPO: every client with their dossier, every deadline tracked, every breach with automatic audit log.
Same structure, every client
Not just an archive. A workspace that brings order, continuity, and traceability.
The hardest part of an external DPO's job is not the paperwork: it is finding out that something happened. Here the client tells you directly, with a link and a code, and the report is born as a tracked event.
Each client gets a private address with a code. No passwords to manage, no extra users to pay for.
A short form in plain language: what happened, when, who is involved. They do not need to know the GDPR to use it.
The report lands in the right client's queue, with a certain date and time. Who said what, and when, stays on the record.
You pick the event type and the workflow starts: the steps to follow and the deadline computed from the law, not guessed. A data breach starts the 72 hours of Art. 33.
Answer a few guided questions and get a professionally laid-out draft with your client's details. No more copy-pasting from old files.
Compiling and preview are free. Export included from the Pro plan.
Privacy document
Patient privacy notice
Provided under Art. 13 GDPR
Controller
Centro Medico Esempio
Generated
20/06/2026
Reference
DPOW-PAZ
Everything you need to respond to a supervisory authority inspection or a client audit, without panic.
Every document shows creation date, last modification, and author.
Draft, in review, complete, to update. Quick filters per client.
History of every operation (creation, modification, deletion) append-only.
Free annotations linked to the client to contextualize decisions.
Configurable review frequency, alerts on upcoming or overdue deadlines.
PDF package with client profile, Art. 30 register, and operational timeline.
Not a generic office software. A workspace built for those who work as DPO professionally, handle multiple mandates, and need to demonstrate accountability.
Certified professionals acting as external DPO for multiple entities or companies.
Consultants supporting clients on GDPR compliance without formally holding the role.
Structured firms with multiple professionals managing privacy matters in parallel.
DPOs serving municipalities, schools, health authorities, with specific documentary needs.
Specialists for SMEs, hospitality, retail with recurring mandates.
Networks and cooperatives of privacy consultants sharing methods and tools.
DPO Workspace is built around privacy by design and by default.
All files and metadata are encrypted at-rest on Google Cloud (AES-256) and in transit via TLS 1.3. No plain-text access along the chain.
Your data and documents are hosted on Google Firebase infrastructure, europe-west1 region (Belgium). No extra-EU transfer in ordinary operation.
Every user lives in a separate workspace. Database access rules prevent an account from reading another's data.
Every upload, modification, or deletion is recorded in an internal append-only audit trail - useful in case of inspection.
DPO Workspace is an operational tool that supports the DPO. It does not replace the professional judgment of the Data Protection Officer nor the responsibility of the data controller.
Read more about security and compliance →31 pre-configured document areas. Upload documents, assign states, add notes. Everything in the right place, for every client.
Collection, versioning, and review of notices under Art. 13-14 GDPR.
Letters of appointment and designations of subjects authorized to process.
Art. 30 register with editable form and sector templates.
List of external processors and Art. 28 agreements.
Risk assessment documents and DPIAs under Art. 35.
Incident register with 72h notification timer under Art. 33.
Cookie policy, banner, and census of web processing activities.
Signage, floor plans, assessments on the use of camera systems.
Certificates, materials, and tracking of training activities.
Tracking of requests under Art. 15-22 GDPR.
Audit documents, follow-ups, and document deadlines.
Automated systems, AI Act, traceability of algorithmic decisions.
Register of transfers to third countries and TIA assessment (Chapter V, Art. 44-49).
Documentation on security measures and NIS2 obligations beyond classic GDPR.
None of these is a promise: they are all in production now. Hover a card to hold it still.
A private link per client: they report events without having an account.
You do not estimate the deadline: the article computes it. Art. 33's 72 hours start from the exact time.
Every client's deadlines in your own calendar, updating themselves.
You search for a clause inside a three-year-old scanned PDF and you find it.
Notices, appointments, consents, AI Act: fill in a questionnaire, leave with a draft to review.
A single file you can hand over: client sheet, Art. 30 register, timeline of operations.
For each client, what is missing and where. It tells you where to put your hours.
Your data is yours outside here too: read access via API with revocable keys.
Invites, owner, editor and viewer permissions, and 2FA on every account.
Monday morning you know what falls due, for which client, and what came in from the portals.
30-day free trial on every plan. No credit card required.
To get started
Primo mese gratuito
Most chosen plan
Primo mese gratuito
For small firms
Primo mese gratuito
VAT excluded where applicable.
Analysis from a working DPO's perspective. Italian DPA, EDPB, fines and regulatory updates.
SATS asked members for a photo kept in the membership system and used at the desk to check the identity of people coming in. Datatilsynet found the notice stated the wrong legal basis, failed to explain the right to object, and that objections were rejected without demonstrating compelling legitimate grounds. The deadline to fix it is 11 September 2026.
On 14 August the French finance ministry announced that the tax administration's information system had been breached: a third party was able to consult and extract data on individuals and businesses. Identifiers and passwords appear untouched — which is precisely why the risk is not account takeover but phishing built on genuine tax data.
On 25 August the Swedish authority published guidance on streaming youth sport. Many clubs stream children's matches online, and the guidance sets out the factors that decide what is allowed. But the part worth reading is the other one: responsibility when the municipality owns the venue and the club wants to install cameras.
On 19 August the CNIL translated for the public its May 2026 recommendation on assessing creditworthiness. Inside are three numbers and one principle that concern anyone doing scoring: twenty-four months for past incidents, six months for the data of a refused application, and a right of access to the score that cannot be dismissed by invoking trade secrecy.
On 24 August the CNIL published its rules for the digital workspaces used in schools. The decisive point is not the protection of minors but a principle of administrative law: the neutrality of the public education service includes commercial neutrality, so trackers used for advertising or profiling are prohibited in principle. If the tool has them, the controller must switch them off.
Practical deep dives from the product and from DPO practice.
DPO software: internal and external
What you need when you handle more than one organisation, and the notification duty.
Records of processing (Art. 30)
What it must contain, who must keep it, Excel vs software.
Software for consultants and external DPOs
Multi-client by design: one workspace, all your clients.
AI Act: obligations and documents
The deadlines and the 7 documents to be ready for August 2026.
DPO software comparison
DPO Workspace vs 5 alternatives, no hedging.
Deadlines with a legal basis
Why every review interval cites its source.
Operational news for DPOs
Decisions and updates, turned into concrete actions.
30 full days, no credit card required. After that you can activate a plan or let it expire — your data is kept for 90 days.
No. DPO Workspace is an operational tool that supports the DPO in their activities. It does not replace professional judgment nor the responsibility of the data controller.
Yes. EU hosting (europe-west1), TLS 1.3 encryption in transit, AES-256 at rest. Daily backups. GDPR Art. 28 DPA available on request.
Yes, anytime. Client export to CSV/Excel, Article 30 record to PDF/Word.
Yes, the tool is designed exactly for independent DPOs, small professional firms and privacy consultants managing 30-50 clients at a time.
Your plan stays active until the end of the period already paid. After that, access is blocked until you reactivate. Data is kept for 90 days post-cancellation.