Skip to content
Legiscope
Menu
Art. 35(7) · data protection impact assessmentnot the screening — the assessment

DPIA draft.
Done in minutes.

Legiscope turns your processing record into a review-ready DPIA draft, combining legal and information-security analysis.

§ 1  One risk, and the assessment behind it
Art. 35(7)(c) · risks to the rights and freedoms of natural persons
One automated workflow

Select the processing. About six minutes later, open the DPIA draft.

  • No blank page. No retyping.

    Legiscope reads the purposes, data, recipients, processors, transfers and measures from the processing record you already maintain.

  • The legal assessment, already drafted.

    Necessity and proportionality, lawful bases, information duties and data-subject rights are analysed in the correct order.

  • The security assessment, already connected.

    Systems, assets, threats, harms and measures are mapped together, with inherent and residual risks assessed separately.

  • One review-ready DPIA.

    Legal and security teams review one editable draft, record their conclusions and preserve each approved version.

DPIA · PROC-118 candidate scoring · risk R-4 · asset A-L2

Unfair exclusion of a candidate on a score nobody can explain

Art. 36 candidate
Threats considered for this asset
  • T-1Abnormal use of the scoring interface by an authorised operatorapplicable
  • T-2Espionage of the model inputs in transitapplicable
  • T-3Modification of the training corpusset aside
  • T-4Loss of the candidate export fileapplicable
  • T-5Overload of the scoring serviceset aside
Threat path — who, how, what they exploit

An operator with standing access to the scoring interface reads and reuses comparative scores outside the recruitment decision they were produced for — the interface exposes the ranking to every recruiter in the unit, and nothing records what was consulted.

Measures applied
  • MES-2Role-restricted access to scores, reviewed quarterly
  • MES-7Export blocked outside the applicant-tracking system
Inherent risk, then residual
Likelihood →Severity ↑
Inherent — before measures Residual — after MES-2, MES-7
Residual riskNot accepted

A corrective action is required before the assessment can be recorded — an unacceptable risk with no treatment is refused.

§ 2  The assessment, automated
CNIL PIA · ISO/IEC 29134 methodology

A hand-written DPIA used to take six weeks.
Watch Legiscope draft that in six minutes.

In about six minutes, Legiscope turns your register into a sourced DPIA draft— necessity assessed, threats identified and risks scored. Your team reviews, corrects and decides.

Week one

The assessment starts with a blank document.

Purposes, data, parties, transfers and measures are copied from registers, interviews and attachments before the assessment itself can even begin.

With LegiscopeLegiscope starts from the linked processing record and drafts the scope and context without asking your team to enter the same facts again.

Week three

Legal and security are working in separate documents.

Necessity and proportionality sit in one file; assets, threats and measures sit in another. Connecting the legal analysis to the actual risks becomes another manual exercise.

With LegiscopeOne structured draft connects purposes, systems, threats, harms, measures and residual risk so both teams review the same assessment.

Week six

The first draft finally reaches the people who must decide.

Most of the time was spent collecting and formatting information instead of challenging the analysis and deciding whether the remaining risk is acceptable.

With LegiscopeA sourced draft is ready in about six minutes. Legal and security review the work, the accountable owner decides, and the approved version stays on record.

From processing record to DPIA draft

See Legiscope draft your DPIA in minutes.

See how one processing record becomes a structured DPIA draft, bringing legal analysis, security risks, measures and evidence together for your team to review.

Book your demo