ADEQUACY EXPERT

Privacy by Design Software: drive compliance across your business projects

Driving your Privacy by Design strategy isn't a checkbox exercise in a spreadsheet. Adequacy Expert's Privacy Project module enables DPOs and legal teams to structure, track, and document the integration of data protection into every business project. With configurable milestones, an automated status workflow, and full traceability, you can confidently meet the GDPR's accountability requirements.

Included in the Expert plan

Configurable milestones and deliverables

Automated status workflow

Multi-entity ready

Project Management / IS Roadmap — Compliance Initiative

Next-Generation CRM Platform

IS Project
M1 Initial Qualification 100% Approved
Qualification form completed Completed
Data Protection Officer assigned Completed
M2 Data Inventory 66% In Progress
Data flow mapping Completed
Legal basis identification In Progress
DPIA necessity assessment To Do
M3 Data Protection Impact Assessment (DPIA) 0% Upcoming
Key benefits of the Privacy Project module

Structure your Privacy by Design strategy, project by project

Accessible from the Project Management / Project menu in the Expert plan, this end-to-end tool enables DPOs to drive, document, and demonstrate data protection within every business project. It provides a clear way to prove effective integration — right from the design stage of every initiative.

Project workflow modeling

Build a Privacy by Design workflow tailored to each project type — R&D, software procurement, new processing activity, partnership. Each workflow reflects the operational realities of the targeted activity.

Configurable milestones and deliverables

Each workflow is a sequence of milestones. For every milestone, specific deliverables must be completed and justified by business teams before moving to the next step.

Automated status workflow

When a deliverable moves to "Completed", the following deliverables automatically transition from "To Do" to "In Progress". Business teams are naturally guided through the process, with no manual intervention from the DPO.

Multi-entity and multi-workflow

Define multiple workflow templates — IS, HR, marketing, partnerships — and make them available to one or several business units within your organization.

DPO oversight at a glance

Monitor progress across all active projects from a centralized dashboard. Instantly identify delayed projects or unjustified deliverables.

Project instantiation

Create a project for each business initiative, assign a configured workflow, and designate the accountable owners. Each project follows its own milestone and deliverable path.

Traceability and demonstration

Every deliverable approval is timestamped and consultable. Demonstrate at any time — during an audit or a CNIL inspection — that every expected step was completed.

Justification via Adequacy objects

To approve a deliverable, directly link an existing object in your Adequacy workspace as proof of completion — no duplicate data entry or external attachment required.

Configuration — Project templates

Configure workflows tailored to every project type

Template management is available under Settings / Project Templates. For each project type, you define the sequence of milestones and the associated deliverables. These templates are then instantiated for every new business project declared on the platform.

The flexibility of the configuration covers very different project types: IS projects, HR projects, marketing projects, partnerships involving data transfers, and rollouts of new tools.

Create and manage multiple workflows in parallel

Freely define milestones and their regulatory deliverables

Draft the expected content and required justifications

Granular template assignment to one or several entities

Update templates without impacting ongoing projects

Settings / Project Templates

4 configured workflows

  • Information Systems Project

    5 milestones14 deliverablesAll business units

  • Human Resources Project

    4 milestones9 deliverablesCHRO & HR teams

  • Marketing & Digital Project

    4 milestones11 deliverablesMarketing division

  • Partnerships & Data Transfers

    3 milestones7 deliverablesLegal department

Tracking — Milestones and deliverables

Track progress milestone by milestone, deliverable by deliverable

For every instantiated project, business users record the completion status of each deliverable and provide the corresponding justification. The DPO can monitor workflow progress across the entire project portfolio in real time.

This granular tracking ensures nothing slips through the cracks and that every approval is backed by documented evidence.

Detailed view of milestones and their deliverables for each project

Status updates entered by business teams

Free-form justification field to document each deliverable

Automatic progress calculation per milestone and per project

Complete history of changes and approvals

Project Tracking — E-commerce Platform

Milestone 2/4 · 50%
M1 Scope & Qualification 100% Approved
Project description & purposes Completed
Data processing scope Completed
M2 Risk Assessment 50% In Progress
Privacy risk identification Completed
Technical safeguards planning In Progress
DPIA required / not required ruling To Do
DPO sign-off on safeguards To Do
M3 Documentation & Compliance 0% Locked
Automation — Status workflow

Automate task progression to streamline the journey

The module lets you set up a status workflow for deliverables. When a deliverable moves to "Completed", the next deliverables automatically transition from "To do" to "In progress".

This logic streamlines tracking and naturally guides business teams without requiring DPO intervention at every step.

The platform administrator configures these progression rules within the workflow template — no custom development needed. The result is a structured, progressive journey aligned with your organization's logic.

Easy transition rules configured by the administrator

Automatic "To do → In progress" transition on trigger

Logical, ordered sequencing of deliverables within a milestone

Natural guidance for business teams without DPO intervention

Full traceability of automated workflow transitions

Workflow — Milestone 2: Risk Assessment

Active rule: when a deliverable moves to "Completed", the next deliverable automatically transitions to "In Progress"

Privacy risk identification

Justification submitted by Mr. Bernard on Apr 12, 2025

↓ Automatically triggers →

Technical safeguards planning

Automatically transitioned from "To Do" to "In Progress"

Automated transition · Apr 12, 2025, 2:38 PM

↓ Will automatically trigger →

DPIA required / not required ruling

Will move to "In Progress" once the previous deliverable is approved

DPO sign-off on safeguards

Awaiting completion of deliverable 3

Regulatory context

GDPR Article 25: Pprivacy by Design, an obligation with no instruction manual

Article 25 of the GDPR enshrines the principles of Privacy by Design (data protection from the design stage) and Privacy by Default (protection by default). These obligations apply to every organization that designs or deploys a product, service, or system processing personal data.

Yet no national supervisory authority has published an operational guide. The EDPB Guidelines 4/2019 outline principles but offer no practical answer for organizational implementation.

The outcome: every organization that has rolled out a Privacy by Design strategy has built it custom — with its own tools, its own stages, its own methods. Privacy Project was designed to adapt to any existing strategy: whether already formalized or still under construction, the module supports and structures the integration of data protection without imposing a single method.

GDPR Art. 25

The data controller must implement appropriate technical and organizational measures from the design stage of processing and by default.

EDPB Guidelines 4/2019

The EDPB has published guidelines on GDPR Article 25, clarifying the legal concepts but providing no operational method ready for use by tech or product teams.

The demonstration challenge

Accountability requires being able to demonstrate compliance. The Privacy Project module delivers the traceability needed to prove that a project has integrated these principles from day one.

Accountability — Full traceability

GDPR accountability: demonstrate the compliance of every project

One of the GDPR's core requirements is accountability (Article 5.2): it isn't enough to be compliant — you must be able to prove it. Privacy Project archives every action, every approval, every status transition with its timestamp and author.

In the event of a CNIL inspection or audit, the DPO can produce the full history of the Privacy by Design strategy applied to each project in just a few clicks.

Timestamped audit log for every project

Recorded author for every deliverable approval

Centralized retention of justifications submitted by business teams

Transparent history of automated workflow transitions

Full export of the compliance journey per project

Audit Log — CRM IS Project

Milestone 1 approved by DPO

Apr 14, 2025 · 10:12 AM

S. Martin (DPO) approved the "Initial Qualification" milestone. All deliverables are marked as Completed.

Evidence archived

Automated workflow transition

Apr 12, 2025 · 2:38 PM

Deliverable "Technical safeguards" moved to "In Progress" following approval of "Privacy risk identification" by Mr. Bernard.

Automated transition logged

Deliverable documented

Apr 12, 2025 · 11:05 AM

Mr. Bernard completed the "Privacy risk identification" deliverable with full supporting documentation.

Justification recorded

Project initialized

Apr 02, 2025 · 9:20 AM

"Next-Generation CRM Platform" project created by T. Leclerc. Associated template: Information Systems Project (5 milestones, 14 deliverables).

Frequently asked questions

FAQ - Privacy by Design and compliance software

Privacy by Design (data protection from the design stage) is a principle enshrined in Article 25 of the GDPR. It requires data controllers to integrate the protection of personal data from the design phase of any new product, service, or system — not after the fact. This obligation applies to every project likely to process personal data. It is complemented by the principle of Privacy by Default, which requires that only the data strictly necessary to the project be processed by default.

The module is available from the Project management / Project menu. The platform administrator first configures workflow templates under Settings / Project templates: each template is a sequence of milestones, and each milestone contains deliverables to complete and justify. These templates are then assigned to the relevant entities. Business teams instantiate a project, and the DPO drives progress milestone by milestone, approving each completed step.

Privacy Project is included in the Adequacy Expert plan. If you already have an Adequacy Expert account, the module sits in the Project Management section of your workspace. If you're not yet a customer, request a demo to evaluate the full Expert offering.

Yes. That's precisely one of the module's strengths. You can declare multiple distinct, custom workflows (IS project, HR project, marketing project, partnership involving data transfers, etc.). Each workflow can be assigned to one or several specific entities within your organization to fit operational realities and internal processes.

The status workflow automates deliverable progression within a project. For example, when a deliverable moves to "Completed", the following deliverables automatically transition from "To Do" to "In Progress". These transition rules are configured by the administrator within the workflow template. They naturally guide business teams through the journey without requiring manual DPO intervention at every step. Every automated transition is logged in the audit trail.

The accountability principle (GDPR Article 5.2) requires you to document and prove your compliance with the GDPR. The Privacy Project module builds a complete audit trail for every project: every approved deliverable, every submitted justification, every workflow transition is archived with its date and author. In the event of a CNIL inspection or audit, the DPO instantly has the required evidence, proving that every project has followed the Privacy by Design strategy (GDPR Article 25) defined by the organization.

Ready to embed Privacy by Design into your projects?

Privacy Project is natively connected to your entire Adequacy Expert workspace. Records of processing activities, impact assessments, rights management: everything is connected for 360° collaborative oversight of your GDPR compliance.