Skip to main content

All features

DPAkit covers the full GDPR lifecycle: from vendor management and data processing agreements to data breaches, DPIAs and non-EEA transfers.

Vendor management

GDPR article: Art. 28(1)

Central overview of all vendors processing personal data. Art. 28(1) requires you to only use processors providing sufficient guarantees — which starts with knowing who your processors are.

  • Type, criticality and processor role per vendor
  • CSV bulk import and export
  • Offboarding workflow with checklist
  • Contact details and contract periods

DPA Generator

GDPR article: Art. 28

Generate data processing agreements meeting all Art. 28 requirements.

  • Templates with all 12 mandatory Art. 28 provisions
  • Digital signing by both parties
  • Automatic PDF generation
  • Wet signature option for special category data (Art. 9)

Processing register

GDPR article: Art. 30

Automatically generated register compliant with Art. 30 GDPR.

  • Auto-populated from signed agreements
  • Retention periods, recipient categories and security measures
  • DPO contact details and employee count indicator
  • Internal processing activities (no external processor)
  • PDF export for auditors

Data breach register

GDPR article: Art. 33-34

Record, assess and report data breaches per Art. 33-34.

  • Risk categorisation (auto-detection of special categories)
  • 72-hour deadline tracking with reminders
  • Notification to DPA and to data subjects
  • Internal breach register for documentation

Data subject rights

GDPR article: Art. 12-22

Manage data subject requests with deadlines and status tracking.

  • Access, rectification, erasure, portability
  • Automatic deadline calculation (1 month)
  • Status workflow: received, in progress, completed, rejected
  • Automatic notification to processor

DPIAs

GDPR article: Art. 35-36

Data Protection Impact Assessments with risk matrix and approval workflow.

  • Risk matrix with likelihood x impact scoring
  • Draft, review, approval, rejection workflow
  • Automatic link to processing register
  • Art. 36 prior consultation workflow

Sub-processors

GDPR article: Art. 28

Manage sub-processor changes and objection periods.

  • Vendor portal: vendor can submit sub-processors directly
  • Approval/objection workflow per sub-processor
  • Automatic objection deadline enforcement
  • Notification to vendor upon decision

Non-EEA transfers

GDPR article: Art. 44-49

Document international transfers per Art. 46-47.

  • SCCs, adequacy decisions, BCRs as legal basis
  • Transfer Impact Assessment (TIA) workflow
  • Automatic expiry date tracking
  • Compliance check for Schrems II requirements

Renewal management

GDPR article: Art. 5(2), 28(3)

Automatic reminders for contract renewals and certificates. The accountability principle (Art. 5(2)) requires ongoing compliance — not just when signing an agreement, but throughout its duration.

  • Automatic email reminders for approaching deadlines
  • Periodic assessment cycles per vendor
  • Dashboard overview of upcoming renewals

Evidence vault

GDPR article: Art. 5(2), 24, 28(3)(h)

Store certificates and reports securely with expiry alerts. Art. 5(2) and Art. 24 require you to demonstrate that processing complies with the GDPR. Art. 28(3)(h) obliges the processor to make all information available for audits.

  • ISO 27001, SOC 2, pentest reports, policies
  • Automatic expiry notifications
  • Confidentiality levels per document

Questionnaires

GDPR article: Art. 28(1), 28(3)(h)

Send security questionnaires to vendors via a portal. Art. 28(1) requires processors to provide "sufficient guarantees" of appropriate measures — questionnaires are a recognised way to assess these guarantees.

  • Standard security questionnaire
  • Vendor fills in via magic link (no account needed)
  • Automatic scoring (green/yellow/red)
  • Notification to managers upon completion

Compliance scoring

GDPR article: Art. 24(1), 32

Automatic risk score per vendor. Art. 24(1) requires measures proportionate to the risk of processing. Art. 32 prescribes a risk-based approach to security. Compliance scoring makes this concrete and measurable.

  • Score based on DPA, certificates, questionnaire, sub-processors and breaches
  • Status: compliant, at risk, non-compliant
  • Action list per vendor with direct links
  • EEA transfer check and TIA status

Reports

GDPR article: Art. 5(2), 24

Export a complete audit pack with all documentation. The accountability principle (Art. 5(2) and Art. 24) requires you to demonstrate at any time that your processing complies with the GDPR.

  • Vendors, DPAs and evidence as CSV
  • ZIP export with all documents
  • Processing register as PDF

Ready to get started?

Try DPAkit for free and discover how to organise GDPR compliance with ease.

Start for free