Records & DPIA depth
How this is scored
The DSMS core: records of processing (RoPA/VVT), data protection impact assessments, processor/DPA management and TOMs — how deeply the legal artifacts are modeled and connected.
0 — Document templates in a folder tree; the "register" is a Word file with version numbers in the filename.
3 — A structured RoPA with basic fields and a DPIA questionnaire, but processors, TOMs and legal bases live outside the system.
5 — RoPA and DPIA as linked modules with templates; processor management and TOM assignment exist but are shallow, and group reuse is copy-paste.
8 — A connected data model — processing activities linked to systems, processors, TOMs and legal bases — with DPIA triggers derived from the record, reusable group templates, and outputs a supervisory authority accepts.
10 — Privacy records as a system of record: the RoPA drives DPIAs, processor management and TOM coverage from one data model, multi-client/mandate capability included, and the documentation is audit-ready without manual assembly.
The External DPO
The record of processing is a genuinely connected model: activities carry their systems, safeguards and data processing agreements as a graphical relationship view, recipients without a contract surface as marked-missing rows, and every approval freezes a PDF revision with checksum. For my practice the mandate story is real — connected documents inherit content across clients, new tenants are created in minutes with per-tenant module configuration, and the Bavarian authority's questionnaire plus status reports and procedure files are generated at the push of a button. The one step short of full marks: I found no public information on a completeness view that drives technical and organizational measure coverage from the record itself. 16 17 11 2 2