Rapid Onboarding
From scattered records to a working privacy platform in days
Bring existing DPIAs, RoPA registers, supplier lists, system inventories, policies and documents into Acompli. Import, connect, enrich and start running assessments from a governed compliance foundation.
Six stages from raw data to a governed compliance programme
Bring your data in any format — Word DPIAs, Excel registers, ServiceNow exports, SharePoint policies, architecture diagrams. Each import triggers a chain of downstream automation that populates registers, generates data flows, and classifies every entity.
Bring your existing compliance estate
Upload up to 50 existing DPIAs and import your RoPA register with AI-powered column mapping. Bulk-load IT systems, vendors, and locations from any spreadsheet format.
AI extracts question-answer pairs from documents, detects frameworks (GDPR, EU AI Act, ISO 27701), and proposes matching templates or tailored drafts for review. Duplicate detection via file hashing prevents re-imports. Acompli hash- and time-stamps every imported file, so the trail back to source is preserved from the first upload.
Assessment import
50 files per batch. PDF, DOCX, DOC. AI Q&A extraction with OCR for scanned documents.
RoPA spreadsheet import
Excel or CSV. AI maps columns to regulatory compliance fields with confidence scores.
Knowledge base bulk load
Up to 10,000 rows. IT systems, vendors, and locations from any spreadsheet or URL.
Pull live data from the systems you already use
Connect ServiceNow, Jira, HubSpot, Salesforce, or Microsoft Graph. Browse and import directly from Google Drive, OneDrive, and SharePoint without downloading files locally.
Scheduled auto-sync keeps everything current with incremental updates. Every imported entity is tagged with its source for full provenance. In Acompli, that source tag stays on the record, so a reviewer can trace any register entry back to the connector or file it came from.
ServiceNow
CMDB CIs, vendors, locations, contracts
Jira
Projects and JQL-filtered issues
HubSpot / Salesforce
CRM contacts and companies
Microsoft Graph
Azure AD, tenant info, M365 search
Google Drive
Browse, auto-export native formats
OneDrive / SharePoint
Browse drives and SharePoint sites
AI classifies every entity with regulatory metadata
Every KB entity imported — whether from spreadsheet, connector, or manual entry — is enriched with data categories, data subjects, risk levels, and processing purposes.
Enrichment runs in batches for cost efficiency. Confidence scores accompany every classification. User edits are never overwritten — AI only fills empty fields. Acompli's enrichment drafts the classification; your team reviews and confirms before it stands as part of the record.
Data flows are drafted from imported entities
After KB entities are imported, Acompli creates draft nodes for every system, vendor, and location, then proposes flows from supplier relationships, shared data categories, and assessment linkages.
Seven diagram types generated from reviewable inputs: full landscape, international transfers, third-party relationships, IT interconnections, data category flow, process map, and customer journey.
Drafted nodes
Every imported entity becomes a node in the data map — systems, vendors, locations, departments.
Inferred flows
Supplier relationships, shared data categories, and assessment linkages become directional data flows.
Vision extraction
Upload architecture diagrams or whiteboard photos — GPT Vision extracts systems and relationships.
Seven diagram types
Full landscape, international transfers, third-party, IT interconnections, and more — generated from imported records.
Every import starts a reviewed downstream workflow
Upload your DPIAs and Acompli drafts RoPA records, extracts candidate risks, and builds data flow maps for review. One import, multiple compliance artefacts.
Assessment imports produce RoPA records. KB imports generate data-flow maps and trigger AI enrichment. Templates unlock new assessments. Vendor names trigger AI contract research that locates their DPAs and privacy policies.
Fully operational in days, with a knowledge base that keeps growing
By day three, your IT systems, vendors, RoPA register, assessment library, data flow maps, and document library are populated, searchable, and AI-enhanced. Your team is working. Scheduled sync keeps external data current.
As your team answers new assessment questions, Acompli detects every system, vendor, and location mentioned and suggests KB entries for review. The knowledge base grows from ongoing work.
Foundation
Setup wizard, KB import, connector setup, RoPA import, assessment batch upload, data flow maps generated.
Enhancement
AI template generation, assessment enhancement pipeline, vendor contract discovery, risk review, workflow configuration.
Operational
Team members log in to their tasks. DPO reviews dashboards. Scheduled sync runs. First new assessment launched.
How onboarding works, in six steps
- Import — Upload existing DPIAs and import your RoPA register with AI-assisted column mapping.
- Connect — Pull live data from ServiceNow, Jira, HubSpot, Salesforce or Microsoft Graph.
- Enrich — Every imported entity is classified with data categories and regulatory metadata.
- Map — Draft data-flow nodes and flows are proposed from the imported systems and vendors.
- Cascade — Each import drafts downstream RoPA records, candidate risks and data-flow maps for review.
- Operate — A working programme in days, with a knowledge base that keeps growing.
Onboarding answer
How fast can a privacy team be operational with Acompli?
Because Acompli imports your existing Article 30 RoPA export, your Word/PDF DPIAs, and your CMDB or vendor inventory and maps each field for review — rather than asking you to rebuild from a blank tenant — a regulated Irish or UK firm can be operational in days. The DPC (Ireland) and the ICO (UK) both expect a current Article 30 record at the moment of inquiry, so onboarding speed is an accountability question, not just a procurement one.
AI enrichment classifies and maps the imported entities; a person reviews and approves before anything becomes an official record, and every import is hash- and time-stamped for a defensible trail back to source.
Key takeaways
- Operational in days, not months — you upload existing records (RoPA in XLSX/CSV, DPIAs in Word/PDF, a CMDB or vendor list) and AI enrichment maps them for human review.
- No schema rewrite or rekeying — an Article 30 import preserves all seven controller fields the DPC and ICO look for under Article 30(1)(a)–(g), and Word/PDF DPIAs keep their Article 35(7) narrative verbatim with the original file hash- and time-stamped as evidence. See what a RoPA must contain.
- Transfers and AI systems are surfaced for review — flows to non-EEA countries are flagged as Schrems II items (SCCs, an adequacy decision, or an Article 49 derogation), and imported AI systems are flagged against EU AI Act Annex III; the high-risk determination stays human-approved. Read the Schrems II / TIA guide · EU AI Act module (AI System Register available on opt-in (early access)).
- Every import is auditable — each file is hash- and time-stamped with who imported what, so the trail back to source is defensible under the Data Protection Act 2018 (Ireland) and the UK GDPR (ICO).
Primary sources
What a migrated programme must preserve for the DPC and ICO
An Article 30 import preserves the seven controller fields under Article 30(1)(a)–(g); Word/PDF DPIAs keep their Article 35(7) narrative verbatim; transfers to non-EEA countries are surfaced as Schrems II items for review. The high-risk EU AI Act determination stays human-approved.
Last reviewed: 3 June 2026.
Connected Acompli pages
What a RoPA must contain details the Article 30 fields; the Schrems II / TIA guide covers transfers; EU AI Actowns the Annex III classification (AI System Register on opt-in / early access).
How does Acompli onboarding compare to migrating from OneTrust or TrustArc?
OneTrust and TrustArc migrations typically run a 6–18 week professional-services engagement because the destination expects records in its own schema. Acompli inverts that: you upload your existing exports and AI enrichment maps each field into the governed register for human review. When comparing onboarding, score each vendor on the criteria the DPC and ICO would actually care about.
| Onboarding criterion (what a DPC/ICO audit needs) | Typical OneTrust / TrustArc migration | Acompli rapid onboarding |
|---|---|---|
| Time to a current Article 30 register | 6–18 week services engagement | Operational by Day 3 when source records exist |
| Importing your existing RoPA | Re-mapped into the vendor’s fixed schema | XLSX/CSV or vendor-native export mapped to Article 30(1)(a)–(g) for review |
| Existing Word/PDF DPIAs | Often retyped into a fixed form | Bulk-imported; Article 35(7) narrative kept verbatim, original kept as evidence |
| International transfers (Schrems II) | Manual discovery exercise | Non-EEA flows flagged for an SCC / adequacy / Article 49 review |
| Audit trail of the import itself | Varies by engagement | Every file hash- and time-stamped: who imported what, and what it produced |
The high-risk and legal classifications above remain the controller’s decision — AI drafts, maps, and flags; a human approves. For the underlying obligations see RoPA requirements guide (Ireland & UK), when a DPIA is required, and Transfer Impact Assessments.
Common questions
Onboarding questions answered
See rapid onboarding in action
Bring the records you already have and your platform is operational in days, not months. No re-keying. No consultants. No migration project.
See how Acompli is packaged and priced on the pricing page.