The external DPO's workspace

The privacy & GDPR management software built by a DPO.

The software for DPOs and privacy consultants managing multiple clients: records of processing, data breach, DPIA, deadlines and documents for every client in one place. Each client gets a private link to send you privacy reports in real time.

30 days free · no card required · EU hosting · encrypted data
EU HostingEncrypted dataAppend-only audit trailMulti-client
Sassari, Sardegna2026
Certified DPOin practice
Photo coming
Who's behind it

Dott. Pietro Cravero

Built by a DPO, for DPOs.

I'm Pietro Cravero, certified Data Protection Officer and founder of Studio Cravero Consulting. DPO Workspace comes from my daily GDPR consulting work for public administrations and private organizations.

Every feature is designed to solve an operational problem I've encountered myself. No vaporware. No magical automation promises. Just tools you actually use every day.

0
document templates
0
document areas
0
published analyses
0
product languages
IDcert certified DPOLevel II Master in Personal Data Processing · Roma TreBased in Sassari, SardiniaVAT IT03059830905
Studio Cravero Consulting
The problem

When you handle 5+ clients, the system collapses.Scattered Drive folders, outdated spreadsheets, deadlines on Post-it notes. It works as long as you have one client.

Article 30 records in 5 different spreadsheets — Updated on different dates, you don't know which one is the latest.

Client A's deadlines in Client B's calendar — You miss a periodic review and only notice it afterwards.

Data breach: 20 minutes to find the documents — When a client calls, you waste precious time of the 72h window.

Regulatory updates pushed only to callers — You share them only with clients who call. Others fall behind.

The solution

Built by a DPO. For the real work of DPOs.

Not a generic tool retrofitted for privacy. A workspace designed around the real workflow of an external DPO: every client with their dossier, every deadline tracked, every breach with automatic audit log.

CSComune di SorsoPublic entity - Review frequency: 6 monthsActive
OverviewDocumentsRegisterBreachDeadlinesAudit
24
Documents
8
Processings
2
Deadlines
Latest documents
Informativa pazienti.pdfComplete
Registro art. 30 v2.xlsxIn review
DPIA videosorveglianza.pdfDraft

Same structure, every client

Not just an archive. A workspace that brings order, continuity, and traceability.

Event reporting

The client reports it. You already have the file open.

The hardest part of an external DPO's job is not the paperwork: it is finding out that something happened. Here the client tells you directly, with a link and a code, and the report is born as a tracked event.

  1. You give them a link, not an account

    Each client gets a private address with a code. No passwords to manage, no extra users to pay for.

  2. The client describes what happened

    A short form in plain language: what happened, when, who is involved. They do not need to know the GDPR to use it.

  3. It reaches you before the phone rings

    The report lands in the right client's queue, with a certain date and time. Who said what, and when, stays on the record.

  4. It becomes an event with its own deadline

    You pick the event type and the workflow starts: the steps to follow and the deadline computed from the law, not guessed. A data breach starts the 72 hours of Art. 33.

dpoworkspace.eu/segnala-evento/…
Report a privacy event
What happened
When
People involved
Send
Your queue
Comune di Sorso
Email sent to the wrong list
08/08/2026 · 09:15 · ~140
Data breachart. 33 GDPR
1Assess the risk to data subjects
2Decide whether to notify the authority
3Record the decision and the reasons
Notification deadline: 11/08/2026 · 09:15
Everything stays in the client's audit trail
Document generatorPro

From a questionnaire to a document ready to deliver

Answer a few guided questions and get a professionally laid-out draft with your client's details. No more copy-pasting from old files.

46 ready templates, multi-sector
Notices for healthcare, staff, clients, website, CCTV, e-commerce, hotels, gyms and more, plus appointments and consents.
Export to PDF and editable Word
Premium design: cover, numbered sections, tables and callouts. Ready to deliver or refine.
Mandatory DPO validation
The tool does the heavy lifting, but you export only after reviewing and confirming. The judgement stays yours.
Try the generator

Compiling and preview are free. Export included from the Pro plan.

Privacy document

Patient privacy notice

Provided under Art. 13 GDPR

Controller

Centro Medico Esempio

Generated

20/06/2026

Reference

DPOW-PAZ

1Data controller
2Processing summary
Purpose
Basis
Retention
DPO Workspace · dpoworkspace.euDRAFT · DPOW-PAZ
PDFWord
Accountability

Demonstrating compliance becomes tangible.

Everything you need to respond to a supervisory authority inspection or a client audit, without panic.

Available

Upload and last modified date

Every document shows creation date, last modification, and author.

Available

Document status

Draft, in review, complete, to update. Quick filters per client.

Available

Per-client audit log

History of every operation (creation, modification, deletion) append-only.

Available

Operational notes

Free annotations linked to the client to contextualize decisions.

Available

Per-client deadlines

Configurable review frequency, alerts on upcoming or overdue deadlines.

Available

Exportable client report

PDF package with client profile, Art. 30 register, and operational timeline.

Who it's for

Built on a real workflow.

Not a generic office software. A workspace built for those who work as DPO professionally, handle multiple mandates, and need to demonstrate accountability.

3–30
typical clients

Independent DPOs

Certified professionals acting as external DPO for multiple entities or companies.

5–20
typical clients

Privacy consultants

Consultants supporting clients on GDPR compliance without formally holding the role.

3–5
on the team

Law firms and privacy practices

Structured firms with multiple professionals managing privacy matters in parallel.

10+
bodies covered

Public sector and healthcare experts

DPOs serving municipalities, schools, health authorities, with specific documentary needs.

12
month cycle

SME and hospitality consultants

Specialists for SMEs, hospitality, retail with recurring mandates.

nodes

Consultant networks

Networks and cooperatives of privacy consultants sharing methods and tools.

Security

EU hosting, encryption, audit.

DPO Workspace is built around privacy by design and by default.

TLS 1.3 · AES-256

Encrypted at rest and in transit

All files and metadata are encrypted at-rest on Google Cloud (AES-256) and in transit via TLS 1.3. No plain-text access along the chain.

europe-west1 · BE

EU hosting

Your data and documents are hosted on Google Firebase infrastructure, europe-west1 region (Belgium). No extra-EU transfer in ordinary operation.

Firestore rules

Isolated client workspaces

Every user lives in a separate workspace. Database access rules prevent an account from reading another's data.

append-only

Action traceability

Every upload, modification, or deletion is recorded in an internal append-only audit trail - useful in case of inspection.

A document's journey
TLS 1.3AES-256 at-resteurope-west1Firestore rules
Audit trailappend-only
09:15upload
No retroactive edits: additions only.

DPO Workspace is an operational tool that supports the DPO. It does not replace the professional judgment of the Data Protection Officer nor the responsibility of the data controller.

Read more about security and compliance →
Documentation areas

Everything a DPO manages, in one place.

31 pre-configured document areas. Upload documents, assign states, add notes. Everything in the right place, for every client.

00/ 14 areas ready for every client

Privacy notices

art. 13-14

Collection, versioning, and review of notices under Art. 13-14 GDPR.

Appointments and authorizations

art. 29

Letters of appointment and designations of subjects authorized to process.

Records of processing

art. 30

Art. 30 register with editable form and sector templates.

Data processors

art. 28

List of external processors and Art. 28 agreements.

DPIA and impact assessments

art. 35

Risk assessment documents and DPIAs under Art. 35.

Data breach

art. 33-34

Incident register with 72h notification timer under Art. 33.

Cookies and web

ePrivacy

Cookie policy, banner, and census of web processing activities.

Video surveillance

art. 88

Signage, floor plans, assessments on the use of camera systems.

Privacy training

art. 39

Certificates, materials, and tracking of training activities.

Data subject requests

art. 15-22

Tracking of requests under Art. 15-22 GDPR.

Audit and deadlines

art. 24

Audit documents, follow-ups, and document deadlines.

AI documentation

AI Act

Automated systems, AI Act, traceability of algorithmic decisions.

Extra-EU transfers

art. 44-49

Register of transfers to third countries and TIA assessment (Chapter V, Art. 44-49).

NIS2 and network security

NIS2

Documentation on security measures and NIS2 obligations beyond classic GDPR.

What it actually does

Ten things others would call a filing cabinet.

None of these is a promise: they are all in production now. Hover a card to hold it still.

Client portal

A private link per client: they report events without having an account.

Deadlines anchored to the law

You do not estimate the deadline: the article computes it. Art. 33's 72 hours start from the exact time.

Deadline .ics feed

Every client's deadlines in your own calendar, updating themselves.

OCR and full-text search

You search for a clause inside a three-year-old scanned PDF and you find it.

46 document templates

Notices, appointments, consents, AI Act: fill in a questionnaire, leave with a draft to review.

Annual Audit Pack PDF

A single file you can hand over: client sheet, Art. 30 register, timeline of operations.

Compliance score

For each client, what is missing and where. It tells you where to put your hours.

REST API and keys

Your data is yours outside here too: read access via API with revocable keys.

Team and roles

Invites, owner, editor and viewer permissions, and 2FA on every account.

Weekly digest

Monday morning you know what falls due, for which client, and what came in from the portals.

Pricing

Simple pricing. Cancel anytime.

30-day free trial on every plan. No credit card required.

Solo

To get started

€19/mese

Primo mese gratuito

  • Up to 3 clients
  • 1 user
  • All 77 document areas
  • Art. 30 register
  • Data breach 72h
  • Data subject requests (Art. 15-22)
  • Staff training register
  • Extra-EU transfers and TIA
  • Audit log
  • 5 GB storage
Inizia gratis
Più scelto

Pro

Most chosen plan

€39/mese

Primo mese gratuito

  • Unlimited clients
  • 1 user
  • Everything in Solo
  • DPIA Wizard (WP248)
  • OCR full-text search
  • PDF client report
  • Sector templates
  • Monthly ZIP backup
  • Public DPO profile
  • Weekly digest
  • 25 GB storage
Inizia gratis

Studio

For small firms

€79/mese

Primo mese gratuito

  • Unlimited clients
  • Up to 5 users
  • Everything in Pro
  • Client relations map
  • Annual PDF Audit Pack
  • Read-only REST API
  • Granular roles
  • Priority support
  • 100 GB storage
Inizia gratis

VAT excluded where applicable.

PRIVACY NEWS

Latest rulings and updates

Analysis from a working DPO's perspective. Italian DPA, EDPB, fines and regulatory updates.

See all news
Regulation
26the article nobody signs before broadcasting

Who answers for the live stream of the under-14 match? Sweden answers the question nobody asks

On 25 August the Swedish authority published guidance on streaming youth sport. Many clubs stream children's matches online, and the guidance sets out the factors that decide what is allowed. But the part worth reading is the other one: responsibility when the municipality owns the venue and the club wants to install cameras.

Aug 25, 2026New 5 min
Regulation
24months after which a past incident should not be used

The score they refuse your credit with can be requested, and it has to be explained

On 19 August the CNIL translated for the public its May 2026 recommendation on assessing creditworthiness. Inside are three numbers and one principle that concern anyone doing scoring: twenty-four months for past incidents, six months for the data of a refused application, and a right of access to the score that cannot be dismissed by invoking trade secrecy.

Aug 19, 2026New 6 min
Regulation
2EDPB criteria and the DPIA becomes mandatory

In schools, advertising trackers are prohibited — and consent has nothing to do with it

On 24 August the CNIL published its rules for the digital workspaces used in schools. The decisive point is not the protection of minors but a principle of administrative law: the neutrality of the public education service includes commercial neutrality, so trackers used for advertising or profiling are prohibited in principle. If the tool has them, the controller must switch them off.

Aug 24, 2026New 6 min
Frequently asked questions

How does the free trial work?

+

30 full days, no credit card required. After that you can activate a plan or let it expire — your data is kept for 90 days.

Does DPO Workspace replace the DPO?

+

No. DPO Workspace is an operational tool that supports the DPO in their activities. It does not replace professional judgment nor the responsibility of the data controller.

Is the data secure?

+

Yes. EU hosting (europe-west1), TLS 1.3 encryption in transit, AES-256 at rest. Daily backups. GDPR Art. 28 DPA available on request.

Can I export my data?

+

Yes, anytime. Client export to CSV/Excel, Article 30 record to PDF/Word.

Is it suitable for my small practice?

+

Yes, the tool is designed exactly for independent DPOs, small professional firms and privacy consultants managing 30-50 clients at a time.

What happens if I cancel?

+

Your plan stays active until the end of the period already paid. After that, access is blocked until you reactivate. Data is kept for 90 days post-cancellation.