COMPLIANCE INTELLIGENCE HUB

See Your Entire Compliance Posture in One Score

Your website says one thing. Your records say another. That gap is the first thing an inspection finds, and the last thing a checklist will ever show you. PrivaxisOS cross-checks both, turns every discrepancy into a finding with the evidence attached, and rolls it into one score.

50+
Compliance Rules
5
Automated Checkers
1
Unified Score
Compliance Overview
Organisation-wide posture, recomputed on every check
Run Audit
78
of 100
Needs Attention
2 critical findings are capping your status
Severity-weighted deductions. Resolve the critical findings to lift the status.
ROPA
82
Vendors
64
Web
71
Open findings 12 in queue
Critical
Processing activity has no documented legal basis
Law 124/2024 Art. 6 / GDPR Art. 6
High
Recipient named in ROPA is not in the vendor register
Law 124/2024 Art. 27 / GDPR Art. 30
Medium
Retention period recorded as "as needed"
Law 124/2024 Art. 27 / GDPR Art. 30

You Cannot Report on a Posture You Cannot See

For most organisations, compliance status lives in a self-assessment spreadsheet that was last updated at the previous audit. When the board asks where you stand today, answering takes a week of chasing rather than a click.

No Single Measure of Where You Stand

Web compliance sits with IT, the ROPA sits with the DPO, vendor contracts sit with legal. Nobody can answer the board's question: are we compliant, yes or no?

Audits Start with the Records

An inspection typically opens with a request for the records of processing activities. Every unpopulated mandatory field is a documented gap, found by the regulator rather than by you.

No Trail of Diligence

Point-in-time assessments prove nothing about the months in between. Without a history of checks, findings and fixes, there is no evidence that your posture is being maintained.

A Score You Can Defend in a Board Meeting

The hub produces a health score from 0 to 100 for each registered web domain and an organisation-wide roll-up, recomputed every time a check runs. The model is deliberately conservative, because a score you have to caveat is worse than no score at all.

Severity-Weighted

Deductions from 100 are weighted by severity, so a critical gap moves the number far more than a low-severity one. The team's attention follows the score.

Any Open Critical Means Non-Compliant

One unresolved critical finding forces a Non-Compliant status regardless of the number. You cannot average away a serious gap.

Self-Healing Posture

Fix the underlying record and the related finding resolves on the next check. The score reflects the work rather than the paperwork about the work.

Scored Over Time

Every recomputation is retained, so you can show a regulator or a board the direction of travel, not just today's snapshot.

How the status is derived

Illustrative example of a severity-weighted roll-up

Critical Caps status at Non-Compliant while open 2 open
High Heavy deduction, prioritised in the queue 4 open
Medium Moderate deduction, scheduled remediation 5 open
LOW Minor deduction, tracked for completeness 1 open
TRAIL Dismissals record a category and a reason Audit log

Five Checkers, One Score

Each checker looks at a different source of truth. They all write into the same findings queue and the same scoring engine, so there is one place to triage and one place to report from. Every rule is grounded in the regulation it comes from: GDPR, Law 124/2024, ePrivacy and CCPA.

Website and Cookie Scanning

Scans your live sites for cookies, trackers, third-party vendors, data-collection points and security posture, and flags what is out of line with what you have documented.

See the Web Scan module

Privacy Policy Analyzer

Reads your published privacy notice and checks it against the law: whether it is reachable, whether it carries every mandatory disclosure, whether it is written in plain language, and whether it is still current.

Turns a wall of legal text into a gap list

Data Rights Mechanism Check

Verifies that people can actually exercise their rights on your site: that a request route exists, that it is easy to find rather than buried, and that it works.

See the DSR module

Records of Processing Audit

Audits your processing records for completeness and consistency: missing legal bases, undocumented retention, recipients that do not correspond to a governed vendor. It runs on your own data with no external dependency.

See the ROPA module

Vendor and Sub-processor Governance

Checks your vendor register for the governance a review expects: processors without an agreement, missing mandatory clauses, unauthorised sub-processors, and transfers without a safeguard.

See the Vendors module

Reconciliation, Not a Checklist

A checklist asks whether you wrote something down. The hub cross-checks independent sources against each other, which is the only way to surface processing that nobody documented in the first place.

Sources checked against each other

Where the gaps between them become findings

SITE What your website actually does observed
RECORDS What your processing records say declared
VENDORS Who you have agreements with governed
POLICY What your privacy notice promises published
GAP Anything that appears in one and not the others a finding

One Unified Score

Every finding, from a cookie to a missing contract clause, feeds a single severity-weighted score, per domain and across the organisation. Not ten dashboards that disagree.

Undocumented Processing Surfaces

Cross-checking the site against the register is how you find the vendor nobody recorded and the collection point nobody declared. A paperwork audit alone cannot see either.

Evidence You Can Defend

Each finding captures the offending item at the moment it was found, with a timestamp. Point-in-time proof for a review, without re-running anything.

Self-Maintaining

Fix the underlying issue and the finding resolves on the next check. If it regresses, it reopens. The score reflects the estate rather than the last report.

The Hub Is Only as Good as What Feeds It

Because the modules share the same data, a vendor or a processing activity is recorded once and referenced everywhere. Fixing it in one place resolves the findings that depend on it.

ROPA

Records of processing activities

Assessments

DPIA, PIA and vendor risk

Vendors

Processors and DPA clauses

Web Scan

Cookies, trackers, third parties

Compliance Hub

One score, one findings queue

See Where You Actually Stand

Walk through the hub with your own obligations in mind, and see the score, the findings queue and the ROPA audit against a worked example.

Request a Demo Explore Vendor Management