No tracking. No cookie wall.·EU-hosted (Hetzner) · Cloudflare edge under SCCs
    Workflow · DPIA

    DPIA — Data Protection Impact Assessment

    One processing activity, screened against Article 35 and carried through to a prior-consultation decision — each risk scored for severity and likelihood before any safeguard is credited.

    Ansvar is a gateway for the AI assistant your team already uses — Claude, Microsoft Copilot, any MCP client. Connect it and your agent runs the workflow; the server enforces the stages and fetches every citation.

    Article 35screened first — a run can conclude that no DPIA is required
    CNIL scaleseverity and likelihood per risk, before safeguards are credited
    Article 36a prior-consultation determination, with its basis recorded

    A DPIA here is a staged interview, not a template you fill in. The run screens first: does Article 35 require an assessment at all, and on what basis. Then it takes the processing description, the DPO's position and your necessity-and-proportionality reasoning, enumerates the risks to data subjects for you to confirm, and scores each one on the CNIL severity and likelihood scale before crediting a single safeguard — and only safeguards you have actually built, since a planned control belongs in the recommendations rather than in the residual score. It closes on transfers, processors and an Article 36 determination: prior consultation, or not, with the reason recorded. The variants change the context the run reasons in — a supervisory authority's practice, or the aviation regime over aerial capture; the assessment itself is the same.

    the family

    One DPIA spine, a variant per supervisory context

    Data Protection Impact Assessment (GDPR Article 35)

    The base: GDPR Article 35 for one processing activity, any sector.

    Germany (BDSG-aware)

    German practice, with competence split between the Land authority under § 40 BDSG and the BfDI.

    Sweden (GDPR Art. 35 + IMY supervisory practice)

    Swedish practice, reasoned against IMY as supervisory authority.

    Drone / UAS Aerial Data Capture (GDPR Art. 35 + Reg (EU) 2019/947)

    Aerial capture, where Article 35 meets Regulation (EU) 2019/947.

    The supervisory authority a variant reasons against is part of its configuration, and each conclusion cites the provision it rests on. Where an authority publishes a mandatory-processing list we do not serve, the screening records that gap instead of reproducing the list from memory.

    how a run works

    Five stages the server enforces

    1. 1
      Screening & scope

      whether Article 35 bites, the processing description, the DPO's position, necessity and proportionality

    2. 2
      Risk identification

      data-subject views recorded, risks enumerated, and the list confirmed by you before anything is scored

    3. 3
      Per-risk analysis

      one step per risk: the rights affected, CNIL severity and likelihood, then the safeguards that reduce it

    4. 4
      Consultation & compliance

      transfers, processors, and the Article 36 determination on prior consultation

    5. 5
      Report

      the assessment and its risk register — structured for your agent, rendered for your auditor

    ask your agent

    Paste one of these to start

    Using Ansvar, run a GDPR Article 35 DPIA for our new HR analytics platform. Screen it first, then take it through to the prior-consultation determination.
    Using Ansvar, which DPIA workflow types can I start, and which supervisory authority does each one reason against?

    Free gets one workflow run a month and Solo two, spendable on the base DPIA against a processing activity you describe, and a Free or Solo run can also return a render carrying a self-asserted banner. Premium adds the German, Swedish and drone variants on five runs a month. Team and Company run them against records you upload and add unwatermarked HTML, PDF and DOCX exports. Run allowances and what each tier adds live on the pricing page.

    Questions buyers ask first

    Which plan do I need to run one?
    Any of them, for part of the family. Free gets one workflow run a month and Solo two, spendable on the base DPIA against a processing activity you describe. The German, Swedish and drone variants start at Premium. Team and Company add runs grounded in records you upload. The pricing page carries the allowances.
    Will our supervisory authority accept this as our DPIA?
    The document is yours, not ours. A run produces the Article 35 record — processing description, necessity and proportionality, the scored risk register, the safeguards and the Article 36 determination — with each conclusion cited to the provision it rests on. A controller still signs it and a DPO still reviews it. Ansvar issues no approval and makes no finding of compliance.
    Do we have to upload our records?
    No. On Free, Solo and Premium the run interviews you and assesses what you describe. Uploading your own records is what Team adds: the assessment then anchors to the exact paragraph it came from, with a content hash, so a reviewer can check a conclusion against your document.
    What happens when a supervisory authority's own list is not in a corpus you serve?
    The screening records the gap and marks the basis unresolved. Several authorities publish an Article 35(4) list of processing that always requires a DPIA; where we do not serve that list, the run says so rather than reproducing it from model memory. A DPIA you hand to a regulator has to be honest about what it could not ground.
    Does it decide whether we need prior consultation?
    It makes the Article 36 determination and records what the determination rests on: the residual risk after safeguards, measured against your own thresholds. Whether you then contact the authority stays your call.
    as a service

    Prefer we run it?

    Every workflow here is also an expert-run service: we run it against your systems, review the output as practitioners, and hand over the finished deliverable. See the services page for how engagements work, or contact us to scope one.

    Related: Free DPIA template · Worked DPIA run · STRIDE threat model · Privacy sector · Drone & UAS sector · Vendor DPA directory · Workflow docs · Have us run it

    Run it against your own systems

    Connect the AI client you already use and ask your first cited question — Free, Solo, Premium and Team are self-serve.