About Legiscope
Every part of this product started as a job somebody was doing by hand.
Legiscope has been sold as software since 2017 — the second attempt. The first build was deleted in 2016, because the team behind it had not implemented the security controls the product exists to enforce. Everything since was added when a recurring job proved worth simplifying, and kept because it still removes work.
- First prototype
- 2014
- Rebuilt from zero
- 2016
- Sold as software
- 2017
Each layer removed a different kind of customer work.
Guidance reduced dependence on specialist interpretation. Shared records reduced reconstruction. Relationships preserved context, evidence supported the answer, and review controls kept the final decision with the customer.
Angular prototypes built inside client engagements
First platform build — deleted after a security failure
Register of processing activities
Guided compliance workflows
Processor and subprocessor records
50 documented standard activities
Reusable process templates and audits
Automated register building
Accounts, groups and subscriptions
Documents and assisted work
Multi-controller workflows
Applications and vendor enrichment
Article 28 assessment, done by hand
AI-supported compliance evaluation
Recorded justifications
Document ingestion
DPA discovery and assessment
Product-security analysis
Validation steps and controlled usage
Structured DPIAs
Article 28 contract work
Transfers, incidents and rights requests
What that buys — the same job, before and after
A register of processing activities
- Before 20175 weeksEvery processing activity written from a blank page.
- From 20172 daysFifty fully documented standard activities, added with a button.
- From 20255 minutesThe register drafted by the system, then corrected by a reviewer.
An Article 28 assessment of a processor
- By hand5 hoursOne DPA, read clause by clause against Article 28.
- With AI3 minutesPaste the DPA in and read the assessment.
- In version 520 at onceName the processors. The system finds each DPA online and assesses them in minutes.
The eight moments that changed what the software could do.
- 2014–15Make GDPR actionable
Teams could begin without turning every task into a legal consultation.
During a GDPR implementation for a CAC 40 company, Angular prototypes turned legal requirements into guided assessments. Project leaders could collect the right facts, see what needed attention and move work forward without first becoming privacy specialists.
- 2016Start again, properly
The first platform was deleted rather than shipped.
The team building it had not implemented proper IT security controls. The team was let go, the entire codebase was deleted, and Legiscope started again from nothing rather than sell a privacy product that could not meet its own standard.
- 2017Run compliance in one place
Five weeks of register work became two days. Article 28 assessments were in the product from the same release, read clause by clause at about five hours per processor.
Legiscope began selling its rebuilt Angular-based cloud service. Fifty fully documented standard activities meant a register was assembled by selecting what an organisation actually did, instead of writing every entry from a blank page — five weeks of work became two days.
- 2022Connect the core programme
Records, vendor relationships and access controls became one workspace.
The current repository opens during the move from Angular to React 17 and React 18. Processing records, audits, reusable templates, processor and subprocessor records, accounts and groups reduced duplicate work and kept access beside the records it governed.
- 2023Explain the assessment
Customers received an evaluation they could understand and challenge.
The React interface moved into Next.js as Legiscope added AI-supported evaluations. Recorded justifications and validation steps helped teams identify possible gaps earlier, inspect the reasoning and decide what should be accepted. A processor DPA pasted into the assessment came back in three minutes instead of five hours.
- 2024Bring context to the work
Documents, tasks and controller boundaries stopped living outside the record.
Automated processing creation and field-level audits reduced blank-form work. Document processing and assisted updates reduced re-entry, while tasks and multi-controller permissions put follow-up with the right people without losing organisational boundaries.
- 2025Turn evidence into structured work
The register that took two days took five minutes.
Legiscope built the first automated register: the system drafts the processing activities and the reviewer corrects them, taking the same register from two days to five minutes. Background jobs, document ingestion, application enrichment, product-security analysis, DPA discovery and modular audits prepared the rest of the context so reviewers could focus on exceptions.
- 2026Reach review-ready decisions
Customers can move from evidence to accountable decisions without losing the links between them.
Article 28 assessment stopped needing the document: name twenty processors and the system finds each DPA online and assesses them in minutes. Structured DPIAs, transfers, incidents and rights requests reuse existing programme context. Source evidence, reassessment, acceptance, dismissal and versioned decisions keep automation useful while the customer retains accountable judgment.
The chronology comes from the earlier Legiscope site and the current code history. The first product generation used Angular; React 17 and 18 appear in the 2022 repository transfer, followed by the Next.js interface in 2023.

The automation is new. The judgment behind it is 25 years old.
Legiscope was founded by Dr. Thiébaut Devergranne — a doctor of law and former legal counsel in the French Prime Minister’s SGDN/DCSSI services, now ANSSI, the French national cybersecurity agency. The assessments the product runs are the ones he spent 25 years running for organisations by hand, which is why they are written as rules that survive contact with real records rather than as generic guidance.
- Legal research
- Ph.D., Université Paris II Panthéon-Assas, 2007Très honorable avec les félicitations du jury et autorisation de publication — the highest distinction awarded.
- Public service
- Six years at SGDN/DCSSI, now ANSSIThe French national cybersecurity agency.
- Practice
- 25 years across data protection and cybersecurity
Bring one recurring privacy task.
We will show you how twelve years of iteration handles it — the record it creates, the evidence it keeps, and the decision it leaves for you to sign.
Book a tailored demo