All news
Platform August 23, 2026 5 min

Risk is assessed inside the register, and every feature is one word away

The processing record gains the Art. 32 risk assessment across three dimensions; the whole application gains a search that opens with Ctrl K and reaches 29 destinations, including the ones that live inside a client's file

TL;DR

In the processing record you now assess risk across three dimensions — illegitimate access, unwanted modification, loss or unavailability — each for likelihood and severity. The summary takes the highest grade, not the average. And wherever you are, Ctrl K opens a search that reaches 29 destinations from a single word.

Four missing features, three of which were there

A DPO used the platform for a few days and sent a list of things that, in her view, were not there: the breach register, the risk assessment, document upload and pricing. Three of those four had been there for months. Pricing sits on a page reachable from the menu; breaches and documents sit inside the client's file, which is the right place, because a breach concerns a controller and not the practice.

We could have replied by explaining where they are. That would have been the wrong answer. If an experienced professional looks and does not find, the problem is not the professional: it is that sections nested inside a client appear nowhere until you open a client. So two things came out of it: the feature that really was missing, and a way to find all the others.

Art. 32 risk, in the register where it belongs

Art. 32(1) requires appropriate measures «taking into account» the risk «of varying likelihood and severity», and paragraph 2 names the events to look at: unauthorised destruction, loss, alteration, disclosure or access. Until yesterday the register recorded measures without saying what they protected against. Now every activity has three rows — illegitimate access to the data, unwanted modification, loss or unavailability — and for each you state how likely it is and how severe it would be, on four grades: negligible, limited, significant, maximum.

  • The summary takes the highest of the three dimensions, not the average: a maximum risk of data loss is not offset by a negligible risk of modification, and an average would hide it.
  • Residual risk — what remains after the measures — is filled in only if you want to: it sits behind a checkbox, because declaring it without having genuinely estimated it is worse than leaving it empty.
  • If the risk comes out high and no measure has been recorded for the activity, the form says so. It does not block you: it says so.
  • When the risk is significant or maximum, a pointer to the Art. 35 impact assessment appears, and the assessment you have already made is carried into the DPIA module instead of being filled in again.

One word, and you are there

Ctrl K, or Cmd K on a Mac, opens a search window over any page; there is also a button at the top of the menu, and one in the top bar on a phone. You type any word and the matching entries appear, ranked, with a line underneath saying where they live. There are 29 destinations: 19 menu sections and 10 topics that sit inside the client's file. When you pick one of those ten, the search asks which client and takes you there; if there is only one client, it asks nothing.

  • It searches the label in all nine languages, not only the active one: someone who learned the trade from English texts types «breach» and finds the breach register even with the interface in Italian.
  • It understands article numbers and acronyms: «Art. 30», «Art. 33», «72», «DPIA», «DSAR», «SCC», «RoPA», «Schrems».
  • It is not fussy about singular and plural: «breach» finds «Data breaches».
  • It also finds clients by name and by sector.
  • It does not add a single database read: the client list is the one the menu already keeps in memory to count deadlines.

What the platform does not do

It does not establish whether the risk is high within the meaning of Art. 35(1): the «high risk» threshold is a legal assessment, it rests on the WP248 rev.01 criteria, and it belongs to whoever signs. It does not derive measures from the risk level, and it does not decide whether a DPIA is mandatory: it flags that the case deserves to be examined. The estimate you enter is yours, and it is recorded in the register as such.

Both additions came out of a free trial and one person who took the trouble to write down what was not working. If something slows you down while you work, saying so genuinely helps.

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free