Skip to main content
Best for: gap analysis over privacy policies and DPAs against CCPA, CPRA, VCDPA, and CPA, plus federal HIPAA, GLBA, COPPA, and FCRA where applicable. US state-privacy aware, covering the 20+ state laws live in 2026 alongside the federal sector regimes. Produces specific remediation drafting suggestions tied to statutory provisions rather than generic advice.
Screenshot of the Privacy and Data Protection Audit launcher showing its document slots and input form

The Privacy and Data Protection Audit launcher: document slots, inputs, and what you get

What you need

Inputs

How it runs

A matrix-review pipeline: prepare → extract → wait for extraction → normalize and score → synthesize → render. The matrix columns are the specific statutory requirements implied by your state selection, company role, sector, and sensitive-data categories, so a controller in California with biometric data gets a materially different column set than a B2B processor in Texas. Findings are scored per document, then synthesized into the portfolio gap analysis and verified.

What you get

What this will not do

  • Replace privacy counsel review for final remediation decisions or the breach-notification call.
  • Confirm regime applicability, such as HIPAA covered-entity status or CCPA thresholds, when the facts are ambiguous. Consult counsel.
  • File regulatory submissions, register a data broker, or send breach notices on your behalf.
  • Audit your actual data flows or vendor sub-processor chain beyond what the uploaded documents describe.
  • Run a technical security review: penetration testing, code audit, SOC 2 readiness.

Compliance Scan Agent

Wider net: works out which regimes apply, then dispatches the right checks.

DPA Reviewer

Deeper on the DPAs specifically.