Privacy & AI Governance Self-Assessment

Six practitioner-built assessments, modeled on the kind of tools used in real privacy, AI governance and third-party risk programs. The Privacy Assessment screens a process end to end - what data, whose, for what purposes, on what lawful basis, with what retention, who it is shared with and where it goes - and tells you whether a DPIA is needed; if it is, it hands over to the Full DPIA - necessity and proportionality, individual rights, transfers, and a risk assessment of the three feared events plotted on a severity × likelihood matrix. Where a process relies on legitimate interests, the Legitimate Interest Test works through the purpose, necessity and balancing tests and shows both sides of the balance. The AI Risk Assessment classifies an AI system against the EU AI Act, and the Incident & Breach Severity Assessment records an incident and calculates its severity score using the published ENISA method, with an analysis of what drives the score and what would change it. The Third-Party Security Assessment is a detailed vendor security questionnaire - governance, people, assets, development, access, operations, cryptography, incident response, physical security, continuity, compliance, and an AI/ML supplement - scored as inherent risk tempered by control maturity, with a full list of gaps to close. Everything runs in your browser - nothing is submitted anywhere, and your saved assessments stay on your own device, exportable as JSON or CSV.