Assessments · DPIA · PIA · TIA · EU AI Act

Privacy assessment software your reviewers can stand behind

Assess new processing, vendors, transfers and AI systems before they become regulatory problems — one governed workflow from template to approved decision record, with the evidence trail attached.

01Templates02Context03Drafting04Review05Outputs06Continuity

Download the assessments brochure (PDF) →

On this page
01
DPIA, PIA and TIA workflows

DPIA, PIA and TIA workflows in one place

Privacy teams often run assessments across email, spreadsheets, Word documents and shared drives. Acompli turns assessment work into a governed workflow for templates, owners, evidence, risk scoring, approvals, RoPA links and exportable decision records.

For the surrounding guidance, see the types of privacy assessment, how to conduct a DPIA, the DPIA template, the legitimate interests assessment template, and privacy assessment software compared.

  1. 01Choose assessment
  2. 02Contextual completion
  3. 03AI-assisted drafting
  4. 04Review & approval
  5. 05Connected outputs
  6. 06Continuity

Start / choose your assessment

Pre-built templates or build your own

Start with a structured template for DPIAs, LIAs, TIAs, processor reviews, AI governance workflows and related regulatory assessments, or generate a tailored assessment from scratch. Each template in Acompli carries owners, evidence fields, risk scoring and approval stages from the first question.

Acompli's AI template builder tags RoPA-affiliated questions as it generates your template, so Article 30 fields are mapped before a single answer is written.

02Contextual Completion

Work from real organisational context

Contributors complete assessments with access to the systems, suppliers, locations, documents, and organisational records that matter — so the assessment starts from real context rather than a blank page. Acompli draws that context from the registers the rest of the programme already maintains — the system inventory, the managed supplier list and the parsed document library.

Certain question types connect directly to your Knowledge Base. When an assessment asks which IT systems are involved, respondents select from your actual system inventory. The assessment and the data map stay in sync through mapped fields and review.

Context
Systems & ProcessorsSelect from your registered IT estate and managed supplier list.
Project DocumentsContracts, DPAs, retention schedules, vendor questionnaires — parsed and indexed.
Locations & TransfersRegistered locations, transfer mechanisms, and safeguards.
03AI-Assisted Drafting

Better drafts before they reach the reviewer

AI co-pilots help contributors produce clearer and more complete responses. Advisory explains what “good” looks like for each question. Refinement improves wording on demand — per question or in bulk. Both co-pilots work inside Acompli's assessment record, so drafting help never leaves the governed workflow.

Every suggestion is optional, versioned, and traceable. The DPO sees exactly what the AI proposed and what the human accepted. Confidence scoring identifies low-certainty responses before they reach review.

DPIA — Employee Monitoring System
Processing purpose & lawful basisEnhanced
Data categories & retention periodsEnhanced
Necessity & proportionalityReview
Transfer impact assessmentPrecedent
Rights & freedoms risk analysisEnhanced
Risk mitigation measuresFlagged
Advisory co-pilotExplains what “good” looks like for every question
Refinement co-pilotPolishes wording on demand, in bulk or per question
04Review & Approval

Human judgement stays in the loop

Assessments move through a structured workflow with comments, tasks, approvals, and audit history. Nothing becomes a published record without human review and sign-off. In Acompli, comments, tasks and approvals attach to the specific responses they concern, so the review trail stays on the record.

Role-based permissions give contributors, reviewers, and decision-makers the views and controls appropriate to their role. Compliance gating prevents publication of incomplete or unreviewed work.

Comments & Tasks

Reviewers leave targeted feedback on specific responses. Tasks track open actions with assignees and due dates.

Structured Approval

Assessments pass through defined approval stages. Each step is recorded with timestamp, approver, and decision.

Audit History

Every comment, change, approval, and review action is linked to the assessment with a full audit trail.

Principle →AI drafts the starting point. Humans make the decisions.
05Connected Outputs

Approved work feeds the wider compliance record

Once approved, assessment outputs support connected risk records, Article 30 records, a searchable archive, and curated precedents — within a single connected platform. Acompli writes each output into the connected module — the risk register, the Article 30 RoPA and the archive share one platform record rather than an export.

Every output carries provenance: which question contributed the value, the answer text that was the source, what extraction logic was applied, and who approved the assessment. Trace from a RoPA record back to the original evidence in one click.

Risk Register

Risks extracted with provenance

Severity, category, source assessment, and a link to the original question and answer.

RoPA Records

Article 30 fields auto-populated

Legal basis, data categories, recipients, retention — populated from tagged responses.

Archive

Searchable assessment archive

AI-generated summary, structured tags, and risk levels — indexed for future reference.

Precedents

Best answers become standards

High-quality answers surfaced as candidates. The DPO curates which become authoritative.

06Continuity

Every assessment makes the next one better

The next assessment benefits from the updated registry, the expanded document library, the enriched archive, and any newly approved precedents. Context survives people changes. Institutional knowledge compounds. Acompli holds those assets — registry, document library, archive and precedents — at programme level rather than in personal files.

Past assessments remain available for future reference, helping teams reuse relevant context, prior analysis, and approved records when similar projects arise again. The programme improves through the compliance work your organisation is already conducting.

Compound
Registry
Archive
Precedents
Docs

How privacy assessments work, in five steps

  1. Contextual CompletionContributors complete assessments with the systems, suppliers and records already in context.
  2. AI-Assisted DraftingAcompli's AI co-pilots help produce clearer, more complete responses before review.
  3. Review & ApprovalAssessments move through comments, tasks, approvals and audit history; nothing self-publishes.
  4. Connected OutputsApproved work feeds risk records, Article 30 records and a searchable archive.
  5. ContinuityEach assessment leaves the next one better, on an enriched shared registry.
02

Assessment routing

Which assessment is created from which fact?

This explains the practical routing logic behind the assessment product: new processing, lawful-basis decisions, transfers, processors and AI systems each need a different review path and output record.

  • New processing activityDPIA screeningArticle 35 decision record
  • Legitimate-interest basisLIABalancing-test record
  • Third-country transferTIAChapter V evidence
  • New processorArticle 28 reviewVendor due-diligence file
  • AI systemAI Act assessmentAI system record
03

Evidence lineage

Approved answers become reusable compliance facts

Assessment answers are not just form text. They become cited, reusable evidence that can feed DPIAs, RoPA fields, risk records, transfer reviews and vendor files without re-keying.

Captured once

  • Structured answer
  • Attached evidence
  • Reviewer approval
Approved factCited · versioned · reusable

Reused by

  • DPIA answers
  • RoPA fields
  • Risk records
  • Transfer reviews
  • Vendor files

Approved answers become platform facts — no re-keying between modules.

04

The privacy assessment answer

What is privacy assessment software?

Privacy assessment software is the tool a privacy team uses to run, review and record the assessments that govern new processing — the Data Protection Impact Assessment (DPIA) required under GDPR Article 35, the Legitimate Interests Assessment (LIA) behind an Article 6(1)(f) lawful basis, the Transfer Impact Assessment (TIA) for restricted transfers, the Article 28 processor review, and the broader Privacy Impact Assessment (PIA).

What separates a privacy assessment platform from a folder of templates is provenance. In Acompli each assessment runs through a controlled workflow, is approved by a named reviewer, and is kept as a decision record rather than a static document. The approved outcome feeds the connected Article 30 RoPA and risk register, so the assessment that justifies a processing activity stays attached to it — AI may draft, classify or flag, but a person approves the result.

Key takeaways

Privacy assessment software, in four points

  • Assessments should start early before high-risk processing begins, not after launch.
  • Templates and questionnaires reduce inconsistency, but approvals and evidence make the result defensible.
  • Acompli links assessments to RoPA, data mapping, vendors, risks and evidence so the assessment does not become a disconnected document.
  • AI can draft and flag, but a human approves the final assessment outcome.

What GDPR and EU AI Act assessments does Acompli support?

Acompli supports structured privacy and governance assessments, including DPIAs, PIAs, TIAs, AI risk assessments and vendor assessments. Each assessment can have owners, questions, evidence, risk scoring, approvals and a decision record.

Assessment workflows with one decision trail

Start from a template, assign business, legal, privacy, security and vendor owners, collect evidence, score risks, record approvals, link the assessment to RoPA and export the decision record.

05

Which assessment

Which privacy assessment do you need?

Privacy law turns on a handful of distinct assessments, each with its own trigger and legal basis. Acompli runs all of them through one workflow, and the approved output of each feeds the same connected record.

AssessmentWhat it checksLegal basis / triggerStatusFeeds
DPIA — Data Protection Impact AssessmentRisk to people’s rights and freedoms from a high-risk processing operation, and the measures to reduce it.GDPR Article 35 — high-risk processing (Art 35(3): large-scale special-category data, systematic profiling, large-scale monitoring).MandatoryA decision record → Article 30 RoPA and risk register.
LIA — Legitimate Interests AssessmentWhether legitimate interests can be the lawful basis — the purpose, necessity and balancing tests.Grounded in GDPR Article 6(1)(f); the three-part test is ICO and EDPB guidance.Required to rely on the basisThe lawful-basis record in the RoPA.
TIA — Transfer Impact AssessmentWhether a restricted transfer keeps protection essentially equivalent to the EU standard.Derived from Schrems II and GDPR Chapter V / Article 46; EDPB Recommendations 01/2020.Required for Article 46 transfers without adequacyThe transfer-safeguard record.
Article 28 processor reviewWhether a processor offers “sufficient guarantees”, evidenced in a written contract.GDPR Article 28(1) and (3).Required before engaging a processorThe vendor decision record.
PIA — Privacy Impact AssessmentBroader privacy risk of a new project, before a high-risk threshold is reached.Not a GDPR instrument; best practice, closest to privacy by design (Article 25).Voluntary / best practiceAn early screen that escalates to a DPIA if needed.
FRIA — Fundamental Rights Impact AssessmentImpact on fundamental rights of deploying a high-risk AI system.EU AI Act (Regulation (EU) 2024/1689) Article 27 — certain deployers of high-risk AI.Mandatory for in-scope EU deployers (not the UK)The AI-governance record; complements a DPIA.
06

Which tool

Which type of privacy assessment software fits you?

Teams choosing assessment software meet four broad types. The right one turns less on feature count than on whether one workflow runs every assessment and the approved output stays connected to the Article 30 record.

Type of toolBest forStrengthsWatch-out
All-in-one privacy suiteLarge enterprises running many assessment types at scaleBreadth across modules in one platformAssessments are often disconnected from the RoPA and risk register, and heavier to run
Single-assessment point toolTeams that need only one assessment type (e.g. DPIA only)Focused and simpleDoesn’t run DPIA, LIA, TIA and Article 28 in one workflow — work is re-keyed across tools
Spreadsheet or template packOccasional assessments, or first-timersCheap and quick to startStatic, with no approval trail — the output is a document, not a living record
Assessment-fed, provenance-led platform (where Acompli sits)Privacy and DPO teams running DPIA, LIA, TIA and Article 28 in one governed workflowOne workflow across every assessment type, with human-approved decision records that auto-flow into the Article 30 RoPABuilt for the governed-provenance use case
07

Connected guides

Collaborative privacy assessments without email chains

Acompli helps teams collect assessment answers from the people closest to the project while keeping privacy control over the workflow. That means fewer long interviews, fewer lost spreadsheets and a clearer record of who said what, when and with what evidence.

Last reviewed: June 11, 2026. Each assessment page keeps a distinct job and links to the relevant deeper answer.

Recent assessment and accountability updates

Regulatory signals that shape your assessments

Recent enforcement, transfer and AI-governance developments are exactly what a DPIA, TIA or EU AI Act assessment is meant to anticipate.

Assessment FAQ

Frequently Asked Questions

Privacy assessment software runs structured assessments - DPIAs, PIAs, TIAs, legitimate-interest and vendor reviews - as governed workflows instead of documents. In Acompli, each assessment starts from a template, drafts answers from your organisational knowledge base with every AI draft flagged for review, and ends with a named approver, so the outcome is a decision record, not a Word file.

More assessment operations questions

See assessments in action

Run structured assessments connected to your systems, documents, and records. Keep answers, reviewer approvals and downstream outputs in one governed workflow.

See how Acompli is packaged and priced on the pricing page.