The GDPR is not a folder of documents. It is a file that holds up.
Processing register, DPIAs, data breaches with their notification clock, data subject requests and processor agreements in one coherent file per organisation. The registers reference each other, so a processing activity without a DPIA or a deadline about to lapse becomes visible instead of forgotten.
From now to next
From loose documents to one file that keeps itself current
The processing register lives in a spreadsheet, the DPIAs in Word, the breaches in a mail folder and the processor agreements in the contract cabinet. Each part is correct on its own; together they do not tell you whether the organisation is in control.
The register is a spreadsheet
Nobody sees which processing activity lacks a DPIA, which retention period has lapsed, or what changed since last year.
Registers that reference each other
A processing activity carries its DPIA, its processors, its documents and its retention period. What is missing shows up as a deduction on the dashboard.
The 72 hours start without a clock
During a breach you have to work out under time pressure whether you must notify, whom, and when the deadline expires.
The clock runs from the moment of discovery
Every breach carries the three duties from articles 33 and 34 with their own deadlines, plus an assessment and a draft notification as a starting point.
Policy on paper, behaviour unknown
You know what the privacy policy says, not whether the shop floor acts on it. The annual e-learning measures knowledge, not behaviour.
The knowing-doing gap, measured pseudonymously
The compliance meter asks staff and managers about knowing, awareness and doing, and shows per measure where those three diverge.
This is what it looks like
A selection from Privorium
Click a thumbnail for that screen, or the image itself for the full-size view.
The core registers
Four registers that keep each other honest
Not a set of separate modules, but four registers that reference each other. What is missing in one becomes a deduction in the other.
Processing activities
Purpose, legal basis, data subjects, recipients and retention, with a version per change.
DPIAs and FRIA
Six steps from context to conclusion, with the fundamental rights assessment attached to the same DPIA.
Data breaches
The clock from articles 33 and 34, the breach register, and the measures as tracked actions.
Processors
Term, sub-processor chain, transfer safeguards and retention periods in one calendar.
What Privorium offers
From obligation to demonstrable compliance
The GDPR does not only ask you to do it right, but to be able to show that you do. Privorium is built around that second part.
A register with version history
Every change to a processing activity is a version. The relationship view shows everything attached to it in one picture: DPIA, processors, documents and actions.
A DPIA without rounds of Word files
The process owner supplies the facts through a personal link, at one of three depths. The privacy office walks the six steps, with the DPO advice as a step of its own.
A clock that does its own arithmetic
From the date of discovery the deadlines run for the supervisory authority, the data subjects and the breach register, with a draft assessment and notification text as a starting point.
The knowing-doing gap made visible
The compliance meter scores six measures on knowing, awareness and doing, pseudonymously, per role. Not what the policy says, but what actually happens.
Beyond the GDPR alone
The Wpg audit register follows the audit cycle against the NOREA framework; the AI register tracks AI systems with their risk class under the AI Act, with a FRIA or IAMA attached to the same assessment.
Confidential per organisation
Sensitive fields are encrypted with a key per organisation, every change is in the log, and everything runs inside the European Union.
How it works
From register to accountability in five steps
Fill the processing register
Record purpose, legal basis, data subjects and recipients per activity. The assistant proposes a risk class and says whether a DPIA is indicated; you decide.
Screen 2Send out the DPIA and assess it
The process owner supplies the facts through a personal link. The privacy office walks the six steps from context to conclusion.
Screen 3Handle incidents and requests
A breach gets its clock from the moment of discovery; requests run on their deadlines and measures become actions with an owner.
Screen 4Measure what happens on the shop floor
The compliance meter goes out pseudonymously to staff and managers and scores six measures on knowing, awareness and doing.
Screen 5Account for it
The compliance score counts what is going wrong now; the DPO annual report counts from the registers themselves. No separate reporting alongside the work.
Screen 1Who it is for
For the DPO, the privacy officer and the CISO who also holds privacy
For those who have to oversee an organisation's privacy obligations and demonstrate them, even when that means several organisations at once.
Fractional too: a DPO serving several organisations keeps the files strictly separated and still works in one environment.
Taking part without an account: process owners and staff contribute through a personal link, for the DPIA intake and the compliance meter.
Measures become actions: with an owner, a deadline and a priority, in the same shared follow-up as the rest of the suite.
Privorium at a glance
Curious how your own privacy file holds up?
Privorium is in its acceptance phase: in use at organisations with real data, not yet generally available. Get in touch for a demo on your own registers.