Article 35 screening on every new processing activity, a living DPIA register, and supplier links the ICO can follow.
A DPO needs to know whether privacy risk is actually linked to the suppliers, systems and processors that create it.
Most privacy programmes run on standalone DPIAs and a ROPA that drifts out of date - so when a new high-risk processing activity or sub-processor appears, nothing automatically connects it to the assessment, the supplier risk and the obligations that follow under UK GDPR.
E2ERisk keeps the DPIA register live and connected. Article 35 screening triggers when processing looks high-risk, every DPIA links to the suppliers, assets and ROPA entries behind it, and processor evidence sits inline - so privacy risk is visible, current and ICO-ready rather than a folder nobody has opened since sign-off.
The day-to-day of a DPO rarely matches the tidy diagram in the accountability framework: processing changes faster than the register, new processors appear after contracts are signed, and the DPIAs that should anchor it all sit in Word documents nobody revisits.
The two columns below are the gap we hear most - the privacy programme as it is run today, set against the same work when screening, the register and supplier evidence are connected and kept live.
When a new processing activity or processor is logged, E2ERisk runs the UK GDPR Article 35 threshold test automatically rather than waiting for someone to remember it.
The pipeline below follows one activity from intake through screening, a full DPIA, mitigations and dated sign-off - so nothing reaches an accountable decision without the evidence behind it.
No new activity slips through unscreened - and nothing reaches sign-off without the evidence behind it.
A DPIA is not a one-off document; it is a lifecycle that has to keep pace with the processing it describes. E2ERisk carries each assessment through six connected stages - from discovery and Article 35 screening to accountable sign-off and ongoing review.
The maintain stage is the one most programmes lose: review dates are tracked and owners reminded before an assessment lapses, so the register stays current instead of quietly going stale.
The contrast that matters to a DPO is not features against features; it is the working month with scattered Word files and a drifting ROPA, against the same month when screening, storage, supplier linkage and reviews are all in one place.
The table below reads down the tasks you are accountable for - and what each one looks like when an ICO request lands on a Friday afternoon.
| What you do | Spreadsheets & Word | E2ERisk |
|---|---|---|
| Article 35 screening | Ad hoc, if someone remembers | On every new activity, automatically |
| DPIA storage | Word files scattered across SharePoint | One register - versioned and searchable |
| Supplier linkage | A separate world entirely | Each DPIA tied to the assessed processor |
| ROPA alignment | Re-keyed by hand each year | Linked to assets, data and processing |
| Review cadence | Lapses silently between cycles | Dates tracked, owners reminded |
| An ICO request | A weekend of assembly | An evidence pack in minutes |
You do not have to adopt the whole platform at once. The four modules below are where a DPO sees value first, and each one connects to the others so privacy risk stays joined up rather than siloed.
Start with the DPO Centre, then bring in supplier assurance, GRC and threat intelligence as your processing and processor estate demands.
ICO-aligned, living register - Article 35 screening, mitigations and dated sign-off.
Assess the processors behind your data, and tie each one to the DPIAs it touches.
Carry residual privacy risk into one register - owned, tracked and reported to the board.
Know when a processor holding personal data is exposed, before it becomes a breach.
A DPIA has to stand up against more than one regime at once - the ICO's expectations, UK GDPR and the DPA 2018, alongside the security frameworks your organisation already answers to.
E2ERisk maps the work to all of them together, so one assessment becomes defensible evidence across the regimes below rather than a separate exercise for each. This is framework mapping and assurance evidence, not a certification claim.
A 30-minute walkthrough framed around what you’re accountable for.