In short
Thirty-one document areas become seventy-seven, split into six families: inform, appoint, record, assess, react, demonstrate. The archive page has been redesigned: above each family sits a mosaic that is the portrait of that client, and the family in the worst shape promotes itself to the top.
Where this comes from
A document archive with thirty-one boxes looks complete until you try it on a real case. Then you notice that collected consents end up in "Other documents", that the union agreement on CCTV has no home of its own, and that the transfer impact assessment — the one that accompanies every standard contractual clause after Schrems II — is nowhere. "Other documents" is the box where everything the designer failed to foresee goes to die.
The four that weighed most
- Automated decisions and profiling (Art. 22). With scoring, CV filters and anti-fraud systems it is everywhere, and the 825-million fine decided in the Netherlands these days is about exactly this. It had no box.
- Biometric processing. It calls for its own assessment and used to end up inside "Security measures", where nobody looks for it.
- Access and log register. It is the first evidence requested when unauthorised access is alleged, and it is also the duty that falls on system administrators.
- Anonymisation and pseudonymisation. Almost always claimed, almost never documented: it is the point on which authorities have dismantled the most defences in the past two years.
And then the rest
Union agreements and monitoring authorisations — without them CCTV and geolocation are unlawful upstream, before the GDPR even applies. The Article 33(5) breach register, an autonomous obligation that is not exhausted by handling a single incident. The DPO's resources and independence under Article 38, the first question in any review of the role. Collected consents and withdrawals, which are the proof Article 7(1) requires. And further: notices to candidates, to children, to whistleblowers; system administrators; the Union representative; the data flow map; data classification; vulnerability testing; privacy by design in projects; the incident response plan; Article 34 communications to data subjects; cyber insurance; the DPO's periodic report.
Why the page was rebuilt
Seventy-seven tiles in a grid are a wall, not a list. The areas now sit in six families matching the six things a controller must be able to demonstrate, and above each one there is a mosaic: one tile per area, filled when it holds documents. It is not an illustration pulled from a library — it is the portrait of that client, and it changes as you work. A stock photograph would be identical for everyone and would say nothing.
We do not choose the family in the worst shape: the code does, from the coverage, and it rises to the top with its own colour filled in and a button that opens the first empty area directly. The other five stay monochrome on purpose. Six colours for six families were six colours that said nothing; colour is used by one thing per screen, and that is why it registers.
One thing to know before you open it
On a new client the mosaic will be almost entirely empty and all six cards will say "empty". That is honest and it is uncomfortable. Not all seventy-seven areas apply to everyone: a medical practice and an estate agency together use fewer than twenty. Sector templates exist precisely so you start from the areas that concern that client instead of all of them.
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free