Skip to main content
preeco | data protection

Risk Analysis and Impact Assessments

Assess risks systematically and conduct Data Protection Impact Assessments under Art. 35 GDPR as well as Transfer Impact Assessments (TIA) under Schrems II in a guided and structured manner. Graphical risk mapping visualizes your assessments.

DPIA

Data Protection Impact Assessment under Art. 35 GDPR

Create DPIAs for high-risk processing activities. The structured form guides you through all required steps. Link the DPIA with processing activities and automatically adopt numerous details. Automatic revision of all approved documents.

  • Guided process under Art. 35 GDPR
  • Linking with processing activities
  • Automatic adoption of relevant details
  • Revision of approved documents
  • The AI suggests the assessment of necessity according to Art. 35 para. 1 GDPR, a structured risk catalogue and appropriate countermeasures for the risks – the linked processing activities, processor arrangements and technical and organisational measures (TOMs) serve as the basis
app.preeco.de
Data Protection Impact Assessment under Art. 35 GDPR

Transfer Impact Assessment

TIA under Schrems II for Third-Country Transfers

Conduct Transfer Impact Assessments for data transfers to third countries. Assess the legal situation in the destination country, verify the effectiveness of SCCs and BCRs, and document additional safeguards. The form follows the recommendations of the European Data Protection Board. On approval, an immutable revision is created that you can export as PDF or DOCX – ready to use as evidence for supervisory authorities.

  • EDPB-compliant assessment steps
  • Assessment of SCCs and BCRs under Art. 46 GDPR
  • Document supplementary measures
  • Automatic linking with recipients
  • AI-supported creation and revision; suggestions for risks and additional measures – the assessment of the legal situation in the third country as a neutral draft for own review
app.preeco.de
TIA under Schrems II for Third-Country Transfers

Risk Analyses

Flexible Risk Analyses and Risk Mapping

Create risk analyses for various purposes – from protection needs assessments to threshold analyses to supplier qualifications. Graphical risk mapping visualizes likelihood and severity in a risk matrix. Define risk mitigation measures with responsible persons and deadlines.

  • Graphical risk mapping as a risk matrix
  • Flexible events and damage categories
  • Measure tracking with responsible persons and deadlines
  • Standalone or linked with documents
app.preeco.de
Flexible Risk Analyses and Risk Mapping

Features

All Features at a Glance

From DPIA to TIA to free-form risk analysis – all the tools for systematic risk assessment.

Linking with Processing Activities and Recipients

Automatic adoption of data categories, affected persons, and legal bases. No duplicate data maintenance.

Additional Safeguards (Supplementary Measures)

Documentation of end-to-end encryption, pseudonymization, or contractual supplementary agreements with effectiveness assessment.

Filterable Overviews

All DPIAs, TIAs, and risk analyses centrally in filterable overviews. Status, destination country, risk assessment, and last review at a glance.

Automatic Revision and Follow-Ups

Upon approval or signing, a new revision is automatically created. Follow-ups remind you of regular reviews when the legal situation changes. Automatic status categorization (Acceptable, Act/Review, Unacceptable) for DPIA and TIA.

Export and Documentation

Export as PDF or DOCX with all assessments and graphical risk mapping. Directly usable for audits and authority evidence.

FAQ

Frequently asked questions

Yes. The structured form guides you step by step through the DPIA, adopts data categories and legal bases from the linked processing activity, and uses AI to suggest an assessment of necessity under Art. 35(1) GDPR, a risk catalogue, and appropriate countermeasures. A graphical risk matrix visualises likelihood and severity; on approval an immutable revision is created as PDF or DOCX. In addition, a TIA form following the EDPB recommendations guides third-country transfers including the Schrems II assessment.

A suitable DPIA tool should map the impact assessment as a guided process under Art. 35 GDPR, adopt data from the record of processing activities instead of duplicating it, and document the result in a revision-safe way. preeco | data protection delivers all of this: the DPIA is directly linked to the processing activity, an integrated threshold analysis supports the prior check of necessity, the AI suggests a risk catalogue and countermeasures, and the graphical risk matrix makes likelihood and severity visible. Every approval creates an immutable revision – auditable for supervisory authorities.

A DPIA is required when the planned processing is likely to result in a high risk to the rights and freedoms of natural persons – for example with systematic and extensive automated decision-making with legal effect, large-scale processing of special categories under Art. 9 GDPR, or far-reaching scoring. preeco | data protection supports the prior check with an integrated threshold analysis; the AI additionally suggests an assessment of necessity under Art. 35(1) GDPR. The final legal assessment remains with the controller.

Get Started Now

We will show you how preeco | data protection fully covers your risk analyses and impact assessments.