GDPR Risk Assessment

Get an overview of your GDPR files

Sensitive content tends to be scattered across company systems — in emails, documents and images. A GDPR Risk Assessment doesn’t just give you the overview; it translates your data into a concrete risk score, a comparison with your industry, and an action plan. The assessment is produced from a scan with our DataMapper tool. You simply choose which systems you want to scan. You receive a report, ready for management, the DPO and the Data Protection Authority, that answers questions including:

Get a risk score from A to F
Benchmark yourself against your industry
AI-written executive summary and conclusion
Concrete recommendations with calculated impact
What-if simulator and cleanup ROI calculator
Article 30 draft for your Record of Processing Activities
Option to delete data (requires DataMapper)
Ongoing monitoring of data (requires DataMapper)

Some of the companies that have had a GDPR Risk Assessment drawn up

Get a risk score from A to F

At the heart of the report is a composite score from 0–100, translated into a grade from A to F. The score is built from four components: how much sensitive content you have, how sensitive it is, how concentrated the risk is, and how risk-exposed your industry is. The formula is documented and versioned, so you can always explain where the number comes from.

A report that explains — not just lists

You may have a hunch about what kind of personal data you hold. With a GDPR Risk Assessment, you finally get the answer — written as a coherent narrative, not a raw data dump. The AI writes an executive summary, a conclusion, and interpretations of your key charts — all grounded in your own numbers. The result is a report a DPO can read in 15 minutes — and a leadership team can act on.

See who and what poses the greatest risk

You’ll find out which employees, which data locations and which document types hold the most personal data. And you’ll see it in context: the report compares you with companies in the same industry, country and size band, so you know whether your situation is typical or cause for concern.

Get concrete recommendations — and see the gain from acting

You receive a prioritised set of recommendations on how to reduce your GDPR risk, based on your own data. Each recommendation links to the specific tool or process that can solve it — DataMapper for cleanup, ShareSimple for secure sharing, ComplyAgent for training and policies. Alongside the recommendations, a what-if simulator shows how much your risk score improves when you follow them — so you can see the gain before you spend an hour on the work.

Use the assessment as documentation

The report can be used with leadership, for DPO work, or as a response if the Data Protection Authority asks for a current risk assessment. PDF export in both English and Danish. Every report is saved, so you can show progress over time — from two reports onwards, you’ll automatically get a trend commentary. As part of the report, you can also have an Article 30 draft generated — the Record of Processing Activities that the GDPR requires. See a sample of the report here.

No cure, no pay

If the scan finds that your company inboxes do not contain GDPR risk data, that’s awesome! Your scan is free!

Get started in minutes

Our Customer Success Team, is ready to help you or your company’s Microsoft Admin set up, scan, and get a report for the whole company in just 30 minutes; with no further action needed from employees.

Pricing

-Most popular

Outlook, OneDrive or SharePoint -

One O365 location

From £700

Receive a GDPR Risk Assessment based on a scan of your Outlook, OneDrive, or SharePoint. You will get a report provides a clear overview of potential GDPR risks hidden within the selected data source. The scan takes only a few minutes and requires no involvement from your employees.

  • Scan of one O365 location
  • Report
  • Overview of sensitive data

Contact us

-Package price

Outlook, OneDrive AND SharePoint -

Three O365 locations

From £980

Receive a GDPR Risk Assessment based on a scan of Outlook, OneDrive, and SharePoint. For most businesses, these three O365 apps pose the highest GDPR risks that a company might have. The scan takes only a few minutes and requires no involvement from your employees.

  • Scan of three O365 locations
  • Report
  • Overview of sensitive data

Contact us

-Physical drives

Scan of network drives or local drives -

Network or local drives

From £1,210

Receive a GDPR Risk Assessment based on a scan of your network drives or local drives. These locations can also be added if you have already scanned another data source. In that case, the price starts from £280.-. The scan takes only a few minutes and requires no involvement from your employees.

  • Scan of a physical drive
  • Report
  • Overview of sensitive data

Contact us

DataMapper is a Data Discovery Tool