{{ announcement }}
UK GDPR · DPIA · ROPA · DPbD

Simplify risk.
Protect privacy.
Drive confidence.

Simpriva turns the DPIA from a re-typing chore into a single governed loop. Answer once in triage — and your ROPA, risk register, by-design actions, evidence and audit-ready report build themselves.

UK-hosted
Per-tenant isolation
Append-only audit trail
Operational dashboard
Tameside Housing Trust · 12 live assessments
JUN 2026
12
Open assessments
3
High residual risks
5
Missing evidence
2
Overdue ROPA
Assessments by status
View all
DPIA-26-0142Tenant CCTV upgradeAwaiting DPOHigh
DPIA-26-0139Repairs contractor appIn progressMed
DPIA-26-0131Income management AIApprovedLow
Built for regulated UK organisations · Housing· NHS & Health· Local government· Finance· Education
The problem

A DPIA shouldn't mean re-typing the same answers into ten documents.

Privacy teams stitch assessments together by hand across spreadsheets, Word templates and email threads — then do it all again when the rules change. The detail gets lost; the audit trail doesn't exist.

Duplicated effort

The same processing details get re-entered into the DPIA, the ROPA, the risk register and the report — four chances to disagree with yourself.

?

No defensible trail

When a regulator or auditor asks "who decided this, and on what basis?", a folder of documents can't answer. Decisions live in inboxes.

Rules that drift

Guidance changes, templates fork, and last year's assessment is no longer readable against the rules that produced it. Consistency erodes quietly.

How it works

Input once. Reuse many times.

A configurable rules engine — not static forms. Triage answers flow into every downstream artefact. The system suggests; your DPO always decides.

DPIA-26-0142 · TRIAGEStep 4 of 6
Will the processing involve large-scale monitoring of individuals in a public space?
Yes — CCTV across communal areas
No
ROUTED OUTCOMEDPIA required
Because: large-scale systematic monitoring (severe trigger) combined with special category data inference. PECR flagged for advisory review.
DPIA-26-0142 · SECTIONS62% complete
Processing descriptionDONE
Necessity & proportionalityDONE
Automated decision-makingEDITING
Special category dataREQUIRED
International transfersN/A
DPIA-26-0142 · RISK REGISTER1 gate open
Unlawful facial-recognition inference
Suggested · accepted by reviewer
INITIAL
20
RESIDUAL
12
Excess retention of footage
Library risk · mitigated
INITIAL
12
RESIDUAL
4
🔒
High residual risk — senior acceptance required
Approval blocked until a Senior Risk Owner records a rationale.
DPIA-26-0142 · REPORTLocked · v2.0
DPIA Report — Tenant CCTV upgrade
Approved with conditions · 14 Jun 2026 · R. Hayes (DPO)
Question set v3.2 snapshotted
Risk matrix 5×5 (v1.1) recorded
ROPA record updated & linked
Audit trail sealed (hash verified)
Export PDF
New version
The platform

One governed loop — not a folder of templates

Everything in the MVP serves a single product loop: create → triage → routed outcomes → review → locked report → dashboard → audit.

Configurable rules engine

Questions, branching, scoring, routing and triggers are versioned configuration — not hard-coded forms. Sector packs filter one universal content bank.

Auto-populated ROPA

Personal-data processing drafts a ROPA record straight from triage and DPIA. The owner confirms or edits — with review dates and overdue flags.

Risk register & matrix

Suggested, library and custom risks scored on your configured matrix with initial and residual bands. High residual risk gates approval, by design.

By-design & evidence

Data Protection by Design actions and evidence requirements generate automatically — owners, due dates, statuses, and blockers that stop premature sign-off.

Locked, versioned reports

On approval, the report snapshots the exact question, rule and matrix versions in force. Historic reports stay readable forever; material changes create a new version.

Append-only audit trail

Every approval, answer change, evidence decision and config change is logged — clock-synced, exportable, and impossible to quietly edit.

Security & assurance

We treat Simpriva's own compliance as a feature

The platform holds sensitive descriptions of your high-risk processing. So it's built for public-sector procurement from day one — UK residency, isolation you can evidence, and an assurance roadmap toward Cyber Essentials Plus.

Read the security overview →
UK data residency
Azure UK — data, backups and telemetry.
Per-tenant isolation
Database-per-tenant — a one-line answer to "how is our data separated?"
Encrypted & MFA
TLS 1.2+ in transit, encryption at rest, Entra ID with mandatory MFA.
CE+ roadmap
Cyber Essentials → Plus, independent pen test, DSPT/DTAC aware.
Who it's for

Sector packs, not one-size-fits-all

Each pack filters the universal content bank to the questions, risks and evidence your sector actually faces. Switch packs on; nothing is duplicated.

🏘️
Housing
Tenancy, CCTV, repairs, income
🏥
NHS & Health
DSPT/DTAC-aware posture
🏛️
Local government
Public-space & data sharing
🏦
Finance
Profiling & automated decisions
🎓
Education
Children & vulnerable people
FAQ

Questions buyers ask first

Is Simpriva hosted in the UK?+

Yes. Simpriva runs as centrally-hosted SaaS in Azure UK South with paired UK West — including all backups and telemetry. We do not offer client-installed deployments for the MVP; per-tenant isolation answers the concern that usually motivates install requests.

How is our data kept separate from other customers?+

Each tenant gets its own database within a shared application tier, with evidence files in a per-tenant storage container. That means per-tenant backup, restore and deletion — and an isolation story you can evidence in procurement rather than explain away.

Does Simpriva give legal advice?+

No. Outputs are decision support, not legal advice. The engine suggests routings, risks and evidence; a human DPO or reviewer always decides and can override with a recorded rationale. PECR is handled as an advisory flag-and-review route.

What happens to old assessments when the rules change?+

On approval, an assessment snapshots the exact question, rule and matrix versions used, and renders a locked report. Historic reports never depend on re-evaluating today's rules. A material change after approval creates a new version, leaving the old one intact.

Which toolkits are covered at launch?+

The MVP focuses on the DPIA lifecycle, with auto-populated controller-mode ROPA and a Data Protection by Design checklist flowing from the same triage answers. Processor-mode ROPA, Word export and richer dashboards are on the near-term roadmap.

See the triage-to-report loop in 30 minutes

We're recruiting design partners to validate the loop on real assessments. If you run privacy for a regulated UK organisation, we'd like to talk.