Your website says one thing. Your records say another. That gap is the first thing an inspection finds, and the last thing a checklist will ever show you. PrivaxisOS cross-checks both, turns every discrepancy into a finding with the evidence attached, and rolls it into one score.
For most organisations, compliance status lives in a self-assessment spreadsheet that was last updated at the previous audit. When the board asks where you stand today, answering takes a week of chasing rather than a click.
Web compliance sits with IT, the ROPA sits with the DPO, vendor contracts sit with legal. Nobody can answer the board's question: are we compliant, yes or no?
An inspection typically opens with a request for the records of processing activities. Every unpopulated mandatory field is a documented gap, found by the regulator rather than by you.
Point-in-time assessments prove nothing about the months in between. Without a history of checks, findings and fixes, there is no evidence that your posture is being maintained.
The hub produces a health score from 0 to 100 for each registered web domain and an organisation-wide roll-up, recomputed every time a check runs. The model is deliberately conservative, because a score you have to caveat is worse than no score at all.
Deductions from 100 are weighted by severity, so a critical gap moves the number far more than a low-severity one. The team's attention follows the score.
One unresolved critical finding forces a Non-Compliant status regardless of the number. You cannot average away a serious gap.
Fix the underlying record and the related finding resolves on the next check. The score reflects the work rather than the paperwork about the work.
Every recomputation is retained, so you can show a regulator or a board the direction of travel, not just today's snapshot.
Illustrative example of a severity-weighted roll-up
Each checker looks at a different source of truth. They all write into the same findings queue and the same scoring engine, so there is one place to triage and one place to report from. Every rule is grounded in the regulation it comes from: GDPR, Law 124/2024, ePrivacy and CCPA.
Scans your live sites for cookies, trackers, third-party vendors, data-collection points and security posture, and flags what is out of line with what you have documented.
See the Web Scan moduleReads your published privacy notice and checks it against the law: whether it is reachable, whether it carries every mandatory disclosure, whether it is written in plain language, and whether it is still current.
Turns a wall of legal text into a gap listVerifies that people can actually exercise their rights on your site: that a request route exists, that it is easy to find rather than buried, and that it works.
See the DSR moduleAudits your processing records for completeness and consistency: missing legal bases, undocumented retention, recipients that do not correspond to a governed vendor. It runs on your own data with no external dependency.
See the ROPA moduleChecks your vendor register for the governance a review expects: processors without an agreement, missing mandatory clauses, unauthorised sub-processors, and transfers without a safeguard.
See the Vendors moduleA checklist asks whether you wrote something down. The hub cross-checks independent sources against each other, which is the only way to surface processing that nobody documented in the first place.
Where the gaps between them become findings
Every finding, from a cookie to a missing contract clause, feeds a single severity-weighted score, per domain and across the organisation. Not ten dashboards that disagree.
Cross-checking the site against the register is how you find the vendor nobody recorded and the collection point nobody declared. A paperwork audit alone cannot see either.
Each finding captures the offending item at the moment it was found, with a timestamp. Point-in-time proof for a review, without re-running anything.
Fix the underlying issue and the finding resolves on the next check. If it regresses, it reopens. The score reflects the estate rather than the last report.
Because the modules share the same data, a vendor or a processing activity is recorded once and referenced everywhere. Fixing it in one place resolves the findings that depend on it.
Records of processing activities
DPIA, PIA and vendor risk
Processors and DPA clauses
Cookies, trackers, third parties
One score, one findings queue
Walk through the hub with your own obligations in mind, and see the score, the findings queue and the ROPA audit against a worked example.