Solutions · By role

The privacy program you're accountable for, in one system

PIAs and AIAs, breach response, complaints, an ISO 31000 risk register, and your ROPA — every module writing to the same hash-chained audit ledger, inside your own Microsoft 365 tenant. One place to look, one record to defend.

You're accountable for the whole privacy program, but the program itself is scattered: PIA templates in Word, a breach log in Excel, complaint files in shared folders, risk noted in whichever document last discussed it. AccessPoint replaces that scatter with one operating platform — assessments, incidents, complaints, risks, and processing records all run in the same governed system, so the question "where does our program stand?" finally has a single answer.

Each module operates the work rather than templating it. The assessment engine runs PIAs and AIAs with screeners, section delegation to subject-matter experts, and regulator-ready summaries. Breach response computes the notification obligations from the incident's legal authority — who must be told, by when, what each notice must contain. Complaints get statutory clocks, allegations, and findings. And everything that raises risk rolls up into an ISO 31000 register with inherent and residual scoring, Key Risk Indicators, and tracked commitments, beside a ROPA and vendor register that stay current because they're attached to the work.

The part that matters most arrives years later, when a decision is challenged. Every action across every module is written to an append-only, hash-chained audit ledger — nothing edited away, exportable as court-ready evidence. And because AccessPoint runs inside your own Microsoft 365 and Azure tenant, the program's most sensitive records never move to a vendor's cloud on your watch.

What a privacy officer actually needs from a platform

Not features for their own sake — the capabilities that change what you can answer for, and how fast.

The whole mandate, not one module Assessments, breaches, complaints, risks, and ROPA in one system. Every tool that covers only a slice leaves the rest of your program back in Word and Excel.
A risk view that rolls up Risks raised by assessments and incidents should land in one ISO 31000 register with inherent and residual scoring — not stay buried in the documents that found them.
Breach obligations computed, not researched At 4 p.m. on breach day, you need the notification checklist derived from the incident's legal authority — not a statute open in another tab.
Evidence that outlives the decision You'll defend today's calls years from now, possibly after the people who made them have left. An append-only, tamper-evident ledger is the difference between a record and a recollection.
A ROPA that stays true Article 30 records maintained as durable subjects the assessments attach to — exportable on demand, with vendor DPA status and review cadence beside them.
Reporting you don't hand-build Statutory report templates for the regulator, and a Report Studio for everything leadership asks that the statute doesn't.

How AccessPoint runs a privacy program

Five registers, one platform, one ledger — these are the pieces that carry the mandate.

PIA & AIA engine

A configurable questionnaire engine with preliminary screeners, section delegation to subject-matter experts who see only their part, an embedded risk register, and a regulator-ready summary export — the same engine runs your PIAs and your AIAs.

Live breach-notification calculator

A real-risk-of-significant-harm evaluation drives a live obligations checklist computed from the incident's legal authority — who must be told, by when, and what each notice must contain — with remediation measures tracked to closure.

Complaints & appeals

Commissioner complaints, appeals, and direct complaints through one kind-aware intake — statutory clocks, per-allegation findings, delegated investigation workstreams, and regulator recommendations tracked as commitments.

ISO 31000 risk register

Inherent and residual scoring, treatment strategies, and governed acceptance — over-appetite sign-offs require a justification and an expiry date. Risks surface from assessments and incidents and roll up across the whole program.

ROPA & vendor register

Every assessment attaches to a durable privacy subject carrying its GDPR Article 30 record — lawful basis, categories, retention, safeguards, transfers — with a vendor register tracking each processor's DPA status, review cadence, and risk level.

KRIs, commitments & Report Studio

Key Risk Indicators with thresholds and RAG status, commitments tracked to completion with recurring check-ins, and a Report Studio where you compose your own dashboards for leadership — no SQL required.

The accountability difference

Defensible in the year you'll actually be asked

Privacy decisions get challenged long after they're made. AccessPoint is built so the record proves itself — without depending on anyone's memory or a folder of draft versions.

One hash-chained ledger Every action across every module lands on an append-only, hash-chained audit ledger with integrity verification, exportable as court-ready case audit exports.
Governed sign-offs One configurable review engine gates assessments, findings, and representations — who approved what, when, and in what sequence is part of the record, not an email thread.
In your tenant, under your control The program's records live in your own Microsoft 365 and Azure environment. No vendor cloud holds your breach files, and the publisher has no runtime access.

Privacy Officers & CPOs Questions

Is there software that manages PIAs, breaches, and complaints together?

Yes — that's AccessPoint's design premise. Most tools cover one slice: an assessment tool here, a breach log there, complaints in email. AccessPoint runs privacy and algorithmic impact assessments, breach and incident response, complaints and appeals, an ISO 31000 risk register, and your ROPA as modules of one platform, sharing one identity model, one review engine, one reporting layer, and one hash-chained audit ledger. It also covers the access-to-information side of the same office, if your mandate includes it.

How do I get a single view of privacy risk across my organization?

In AccessPoint, risk isn't a separate spreadsheet you maintain by hand. Assessments and incidents raise entries on a shared ISO 31000 register with inherent and residual scoring; risks can also stand alone. Key Risk Indicators add thresholds, RAG status, and a readings history, and commitments arising from assessments and complaints are tracked to completion with recurring check-ins. The register rolls up across the whole program, so the board question — what are our top privacy risks and what are we doing about them — has a live answer.

Can I replace our Word PIA templates and Excel breach log?

Yes, and you can bring the history with you. AccessPoint's guided import uses an Excel workbook generated with your tenant's own type codes to load historical assessments, incidents, complaints, and risk and vendor registers, with per-row validation before anything imports. Imported records arrive marked historical — no notifications fire, and every record carries Imported provenance in the audit trail. From then on, the questionnaire engine, breach calculator, and complaint clocks operate the work the templates only described.

How does AccessPoint help me defend a decision years later?

Every action across every module is written to an append-only, hash-chained audit ledger with integrity verification — who did what, when, in what order, including any AI involvement. Review workflows capture sign-offs as part of the record, risk acceptances carry a justification and an expiry, and case audit exports produce court-ready evidence on demand. When a commissioner or a court asks how a decision was made, you export the record instead of reconstructing it from email.

Do we have to adopt the FOI side too, or can we run the privacy modules we need?

Every module runs on one platform but is enabled through configuration, so you run the pieces your mandate needs and turn on the rest when you're ready — no migration, no new system. Offices that hold both mandates get the further benefit of requests, assessments, incidents, and complaints sharing one audit ledger and one reporting layer.

What does privacy program software like this cost?

AccessPoint is priced flat per organization by size — USD $2,990, $7,990, or $14,990 per year, published on the pricing page — with no per-user fees, billed through the Microsoft commercial marketplace on your existing Microsoft invoice. The Azure resources it runs on bill directly to you, typically around $175 per month, and there's a 30-day free trial in your own tenant.

One Program. One Ledger. One Place to Look.

Try AccessPoint free for 30 days in your own Microsoft 365 tenant — the whole privacy mandate, configured for your jurisdiction.

Start Free Trial