Skip to content
Legiscope
Menu
AI-powered GDPR compliancefor DPOs, legal & IT

Welcome to
agentic compliance

Legiscope’s AI agents write your register of processings, review your processors, prepare your DPIAs and watch your websites — then file every decision with its evidence, the way a privacy lawyer with fifteen years of practice would.

340 hours saved per client, per yearGDPR & CCPAHosted in the EU
INCOMING
PROCESSOR
Stripe_DPA_2026.pdf
PROCESSOR
Stripe_DPA_2026.pdf
DPA
Slack_DPA_v4.pdf
DPA
Slack_DPA_v4.pdf
READING
LegiscopeART. 28 · 30 · 33
TRANSFERAWS_us-east-1.pdf
Transfer assessmentSCC missing
Art. 44Third-country flow
Art. 46(2)(c)SCC not on file
Art. 49No derogation
PREPARING DECISION
LEGISCOPE · PREPARING
STRUCTURED RECOMMENDATION
25 yearsof trust in privacy & GDPR compliance
DeloitteStarbucksNokiaSanofiAXAVinciSNCFOrangeMonoprixGaumontABN AMROPorscheAlcatel-LucentEDF
§ 1  Your register, kept current
Art. 30 GDPR

Your business changes. Your privacy programme catches up automatically.

A new vendor, application, cookie or processing activity starts somewhere in the business. Legiscope detects the change, connects its privacy impact, and prepares every affected record, assessment and decision.

What changes in the business
FinanceNew processor

Stripe approved for payments

Added
MarketingNew application

Typeform opened by the team

In use
WebsiteWebsite changed

Analytics script published

Changed
Vendor noticeSubprocessors changed

AWS added 2 providers

Received
LegiscopeReads · connects · recommends
What Legiscope prepares
New processorFiled
Amazon Web ServicesPR-041 · TR-014

The official DPA and subprocessor notice are retained with the relationship.

Art. 28contract
Official DPA kept
Subprocessorsdeclared
Current list recorded
TransferEU → US
Safeguard linked

Processor assessment and transfer filed together · source kept

New applicationFiled
StripeAPP-018 · P-021

Finance started using Stripe. No application record covered it.

ApplicationAPP-018
Owner and systems recorded
ActivityP-021
Payments linked
Databilling
Customer and transaction data

Application and processing activity filed together

§ 2  Why agentic compliance
From preparation to review

How agentic compliance transforms privacy management

Traditional privacy software gives teams forms, databases and task lists. Legiscope’s agents prepare the actual compliance work: they read source material, connect records, identify gaps, draft outputs and bring decisions requiring judgement to the right person.

BeforeThe old way
Weeksper record

Your team does the preparation: interviews, spreadsheets, chasing owners, assembling it by hand.

AfterWith Legiscope
Minutesper record

Your team does the deciding: the agent drafts from your own material and hands you the judgement calls.

Before and after comparison of GDPR compliance work
RegisterArt. 30BeforeFive weeksAfterThree minutesA sourced draft, every entry traced to the material it came from.
DPIAArt. 35BeforeSix weeksAfterSix minutesReview-ready, risks and mitigations already written up.
ProcessorsArt. 28BeforeTwo days a contractAfterFour minutesOne or a hundred, same Article 28 process, same depth.
IncidentsArt. 33Before72-hour clockAfterThree minutesFacts, deadline and notification drafts, with hours still on the clock.
EvidenceArt. 5(2)BeforeHours of diggingAfterAlready thereStays attached to the record it belongs to, from creation.
A year≈ 340 hours, spent preparing
340 hours, given back

See what agentic compliance could change for your team.

Book a demo
The platform

Features you’ll love.

You’ve seen the hours come back — here’s where they come from.

§ 3  Processor contracts, audited
Art. 28 GDPR

Analyse your processor’s compliance
with Article 28? Done in one click.

Name a vendor. Legiscope reads its data processing addendum against Article 28 and writes the assessment section by section — the wording it relies on, the reasoning, the verdict.

YouAssess AWS’s DPA and record it in our processor registerAsk Legiscope
The contractAWS Data Processing AddendumAmazon Web Services · processor
d1.awsstatic.com/legal/aws-gdpr/AWS_GDPR_DPA.pdf
  • 3Confidentiality of Customer Data
  • 5Security of Data Processing
  • 6Sub-processing
  • 10AWS Certifications and Audits
  • 11Customer Audits
  • 12Transfers of Personal Data
  • 14Return or Deletion of Data
  • +10further sections
All 17 sections assessed2 min 04 s
Legiscope assessment17of 17 sectionsArt. 28 GDPR
Section 6 — Sub-processingArt. 28(2) · Art. 28(4)
Compliant

Can they change who touches your data without telling you?

“At least 30 days before AWS engages a Sub-processor, AWS will update the applicable website and provide Customer with a mechanism to obtain notice of that update. To object to a Sub-processor, Customer can: (i) terminate the Agreement pursuant to its terms; (ii) cease using the Service for which AWS has engaged the Sub-processor; or (iii) move the relevant Customer Data to another Region…”

Article 28(2) allows a general authorisation on one condition: you are told before the change, and left a way to object. Thirty days’ notice, a mechanism that delivers it and three named exits meet it — but the notice is published to a website, so the window only runs if somebody on your side is subscribed to it. The clause is AWS’s to satisfy; the thirty days are yours to catch.

Seventeen sections, two minutes — against about forty-five by hand, per contract.Wording quoted verbatim from the AWS GDPR Data Processing Addendum.

§ 4  Every processor, in one go
Art. 28 GDPR

Your entire vendor list,
assessed for GDPR compliance in 90 seconds.

Not a security questionnaire — the contract itself. You send us nothing: Legiscope finds each vendor’s data processing addendum on its own legal pages, keeps a dated copy, and checks it against all eight requirements of Article 28(3).

No processors selected
ProcessorAddendum, and how currentArt. 28 complianceSub-processorsTransfersStatus
Amazon Web ServicesHosting · 14 activitiesAWS_GDPR_DPA.pdf12 Jun 2024 · on fileCompliantall 8 requirements met13230 days’ notice3 outside the EEASCCs, module twoLegal analysisDownload DPA
Microsoft AzureCloud & mail · 22 activitiesDPA_Products_and_Services.pdfchanged 6 days ago · on fileCompliantall 8 requirements met96polled weekly2 outside the EEASCCs · EU boundaryLegal analysisDownload DPA
Google CloudAnalytics · 9 activitiescloud-data-processing-addendum4 Mar 2025 · on fileCompliantall 8 requirements met4130 days’ notice2 outside the EEASCCs, module twoLegal analysisDownload DPA
SalesforceCRM · 11 activitiesSalesforce_DPA.pdf21 Jan 2025 · on fileCompliantall 8 requirements met2730 days’ notice1 outside the EEASCCs, module twoLegal analysisDownload DPA
HubSpotMarketing · 7 activitiesdpa.pdf8 Nov 2024 · on fileCompliantall 8 requirements met19polled weekly1 outside the EEASCCs · DPFLegal analysisDownload DPA
SlackMessaging · 4 activitiesSlack_DPA.pdfchanged 11 days ago · on fileCompliantall 8 requirements met1430 days’ notice1 outside the EEASCCs, module twoLegal analysisDownload DPA
StripePayments · 6 activitiesdpa.pdf3 Feb 2025 · on fileCompliantall 8 requirements met23polled weekly2 outside the EEASCCs · DPFLegal analysisDownload DPA
WorkdayHR · 19 activitiesWorkday_DPA.pdf17 Apr 2025 · on fileCompliantall 8 requirements met1130 days’ noticeNone — EEA onlystays in IrelandLegal analysisDownload DPA
8 of 8 processors363 of 363 sub-processors behind them7 with transfers outside the EEA1 min 28 s

Re-read whenever a vendor changes its paper — that is how you find out, rather than the regulator.

§ 5  Your register of processings
Art. 30 GDPR

Describe your business in three lines.
Get your Article 30 register in four minutes.

Not a list of activity names — the record itself. Legiscope reads the guidance, the statutes and the registers of comparable companies, then writes each activity out: what it is for, the lawful basis it stands on, how long you keep the data and who else sees it.

YouWe sell French kitchen equipment — a shop in Paris, an online store, cooking workshops and a loyalty programmeBuild my register
Legiscope assessment34activities writtenArt. 30 GDPR
Processing activityWhat it is for — Art. 30(1)(b)Lawful basisHow longWho else sees it
Retail salesShop · Paris 11eComplete the sale, issue the receipt and honour the legal warranty.Art. 6(1)(b)contract3 years10 for the accountsPayment provider
Online ordersE-commerceTake the order, collect payment and get the parcel to the customer.Art. 6(1)(b)contract3 yearsfrom the last orderCarrier · payments
Loyalty programmeLes Amis de CuisineAward and redeem points, and send members the offers they signed up for.Art. 6(1)(a)consent3 yearsafter last activityMarketing platform
Cooking workshopsShop · atelierManage bookings, allergies and attendance on the day.Art. 6(1)(b)contract1 yearallergies soonerBooking platform
Returns, after-salesShop · e-commerceHandle withdrawal, exchange and warranty claims, and manufacturer recalls.Art. 6(1)(c)legal obligation5 yearslimitation periodManufacturer
PayrollHR · 24 staffPay staff, file social declarations and keep the register of personnel.Art. 6(1)(c)legal obligation5 years50 for pensionsPayroll bureau
1–6 of 34 activities
§ 7  Human responsibility
Art. 5(2) GDPR

The agents prepare.
Your team decides.

Sources

Everything the agents write is drawn from your own material — contracts, registers, statutes — and cites where it came from.

Review

Work arrives as drafts and recommendations, laid out with what was read and what was concluded, ready to check.

Judgement

Questions of risk, necessity and proportionality are framed with the relevant facts and routed to your team to decide.

Accountability

Every decision is filed with its author, date, reasoning and evidence — the record Article 5(2) expects you to show.

The next step

See how agentic compliance can
transform your privacy programme.

Your own workflows, prepared, connected and review-ready.

Book your demo