Article 30 record, both roles
Covers article 30(1) as controller and 30(2) as processor in the same place, and exports to PDF or Excel when someone asks to see it.
Your GDPR documentation probably already exists. It just lives in spreadsheets, Word files and a few inboxes. Export what you have and we structure it in .legal for you, so the record has one home and stays current.
Unlimited users • Free onboarding and migration • No commitment
Sofie Bruhn is group DPO at Meridian Nordic. Her Article 30 record was spread across twelve spreadsheets, a folder of Word documents, and a few email threads where the actual decisions had been made. She knew it was out of date. She just couldn't tell you which parts. So she exported everything, sent it over, and .legal structured it in the platform for her. Two weeks later she had one record, and the awkward job of filling the gaps it had made visible.
One record, one truth
The Article 30 record lives in one place, versioned, with a change log, so nobody has to ask which file is current.
We move it for you
You export your spreadsheets and Word documents. We do the structuring, typically inside two weeks, at no extra cost.
Templates, not a blank page
Predefined templates for systems, policies and processing activities, so you edit rather than invent.
It stops going stale
Process validation flags what needs reviewing and the annual wheel turns recurring work into owned tasks.
Spreadsheets aren't the problem on the day you write them. They're the problem eighteen months later, when the file has four versions and the person who understood it has moved on.
This is the part most teams dread, and it's the part we take off you. You send us what exists today. We match the fields from your export to the platform by hand.
Article 30 has two halves and most spreadsheets only really handle one. In .legal the controller record and the processor record sit in the same place, built to the same requirements.
A blank documentation field is where good intentions go to die. You start from predefined templates for systems, policies and processing activities, and edit from there.
Risk assessment in a spreadsheet tends to mean whoever filled the cell decided what "medium" meant. One shared scale makes the answers comparable.
We'll give you the structure, the templates and a migration team. We won't pretend that makes you compliant.
Covers article 30(1) as controller and 30(2) as processor in the same place, and exports to PDF or Excel when someone asks to see it.
Every change is registered, so several colleagues can work in the same documentation without anyone losing the thread.
The platform tells you when a processing activity needs reviewing, instead of you noticing it two years too late.
Assess each processing activity from a catalogue of common risk scenarios and see the whole spread in one matrix.
Templates for systems, policies and processing activities, with a notification when we update one so yours doesn't drift.
Recurring data protection work becomes scheduled tasks with an owner and a notification, documented by file, link or entry.
One record, built to the requirements it has to meet.
GDPR
The predefined GDPR framework covers the operational requirements, processing principles, data subject rights and the obligations that follow your role as controller or processor, so the record you move in has something to be measured against.
Document GDPR, keep Article 30 records current and stay audit-ready, with templates, risk assessment and an annual wheel around the record.
Explore GDPR / Data ProtectionGive each company in the group its own record while you extract documentation across the whole group.
Explore Group Companiescompanies
users
contracts
processing activities
Bech-Bruun
Mikkel Friis Rossa (Partner)
Fenerum
Rasmus Boutrup (Financial Controller)
Lægeforeningen
Michael Berner (Lawyer)
Molecule Consultancy
Nanna Rodian Christensen (HR & Operational Manager)
Plum Safety
Ulrik Dueholm Beckmann (QC, CM og ESG Lead)
Bech-Bruun
Mikkel Friis Rossa (Partner)
Fenerum
Rasmus Boutrup (Financial Controller)
Lægeforeningen
Michael Berner (Lawyer)
Molecule Consultancy
Nanna Rodian Christensen (HR & Operational Manager)
Plum Safety
Ulrik Dueholm Beckmann (QC, CM og ESG Lead)
Novicell
Julie Oxenvad (Legal Consultant)
Min By Media
Tinna Schultz (HR Manager)
DMJX
Kaspar Rochholz (GDPR Coordinator)
Axel Kaufmann ApS
Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)
NRGi
Mette Mühlendorph (Compliance Specialist)
Novicell
Julie Oxenvad (Legal Consultant)
Min By Media
Tinna Schultz (HR Manager)
DMJX
Kaspar Rochholz (GDPR Coordinator)
Axel Kaufmann ApS
Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)
NRGi
Mette Mühlendorph (Compliance Specialist)
Every use case is a real piece of compliance work, told the way it actually runs in the platform. Filter by who you are, what you work with, and which frameworks you answer to.
4 use cases
No use cases match that combination yet. Try removing a filter.
No. You export what you have and we structure it in .legal for you. Excel and Word are both fine. We review the data first, usually within one to two working days, and tell you what looks thin before anything is moved.
Typically within two weeks, depending on how complex your documentation is. It costs nothing extra, it is part of the deal. We have run more than 50 migrations, most of them from home-built setups in Excel and Word rather than from another platform.
Make sure your documentation is accessible and can be exported, and set aside roughly one to two hours of meetings across the process. The onboarding session itself takes 45 to 60 minutes and walks you through the imported environment.
No, and we would rather say so. We assess the data quality and point out the gaps, but filling them is still your call. Moving the documentation makes the gaps visible, which is usually the useful part.
Two things do most of the work. Process validation notifies you when a processing activity needs reviewing, and the annual wheel turns the recurring activities and policies into tasks with an owner and a reminder. It still needs doing, it just stops depending on somebody remembering.
Yes. The Article 30 record exports to PDF or Excel, and risk assessments export individually or as one combined report. In a group you can pull the record for a single company or across the group.
What the Danish Data Protection Agency can ask to seeNo. Users are unlimited, so the system owners and colleagues who actually hold the facts can be given a task and answer it themselves. That is usually what breaks the chasing habit.
It is handled with the Group Companies add-on, which lets each company keep its own record while you extract across the group. If that is your main challenge, the group compliance use case goes into it properly.
Read the group compliance use caseNo. We give you the structure, the templates and the rails, and we move what you already have into them. Deciding what your processing activities are, how risky they are and what your policies say stays with you.
What a DPO is accountable for
Info
.legal A/S
hello@dotlegal.com
+45 7027 0127
VAT-no: DK40888888
Support
support@dotlegal.com
+45 7027 0127
Need help?
Let me help you get started
.legal is not a law firm and is therefore not under the supervision of the Bar Council.