Preview — demo-ready MVP
Data mapping · Records of Processing Activities · Data PORTABILITY
Praxis Schema is the intake layer that documents the type of data assets, tracks its whereabouts, formats it for portability and mapping for full traceability. A shared PDPA/GDPR sensitivity taxonomy with sector packs, a row-per-activity register, an automatic flow map that flags cross-border and sensitive flows, and exports built to feed a DPIA, a transfer assessment or a breach response. A zero-install register you can start today; a client-portal version in build.

A register kept in a spreadsheet is out of date the week after it is finished, has no notion of sensitivity beyond a colour, and cannot be handed to anything downstream.
The controller's own staff know what data they hold. Asking them by email produces a dozen half-answers and a document the firm has to reconcile by hand.
Cross-border and sensitive flows are the ones the Act cares about most — and the ones a flat list makes hardest to see.
Structured, pre-classified records — sensitivity is looked up from a shared PDPA/GDPR taxonomy, not researched from scratch each time.
Healthcare, telco, retail, education, manufacturing, insurance, government and more — sector-relevant elements and worked examples reduce generic-checklist fatigue.
A built-in sources → systems → recipients flow map with automatic cross-border and sensitive-flow flags — no separate diagramming.
Exports are built to feed DPIA scoping, Frontier's cross-border analysis and breach response, so the register is the start of the record.
The 72-hour breach workflow, DPO-appointment threshold hints, the revised s.129 cross-border mechanism picker and processor contract checks are built into the intake.
The zero-install register lets a firm start building a real ROPA now with no DevOps; the full version is architected for client-portal delegation at scale.
The MVP register runs in the browser today. The full version adds a client portal and a firm-side validate-and-return cycle.
Start from the 11 common categories and add the sector pack that matches the controller — healthcare, retail, hospitality, telco and more.
One row per processing activity: purpose, data elements, subjects, sources, systems, recipients, retention and legal basis — sensitivity classified from the taxonomy as you go.
An SVG sources → systems → recipients map is drawn automatically, with cross-border and sensitive-data flows highlighted.
Breach workflow readiness, DPO-appointment thresholds, the s.129 cross-border mechanism and processor contract checks, prompted in context.
PDF for the client, JSON or XML for the suite — designed to seed a Praxis DPIA, a Frontier transfer assessment or a Breach response.
Invite the controller's staff through tokenised links; they answer plain-language questions in a client portal and the firm validates, returns or locks — with re-attestation on amendment.
PDPA/GDPR taxonomy: 11 common categories (46 elements) plus 12 sector packs (120 elements). Shared between the MVP and the full version, pending counsel sign-off before a v1.0 freeze.
A structured ROPA with sensitivity pre-classified from the taxonomy rather than typed in.
Sources → systems → recipients drawn as SVG, highlighting cross-border and sensitive-data flows.
72-hour breach workflow, DPO-appointment threshold hints, revised s.129 mechanism picker and processor contract checks.
Explicitly designed to feed Praxis DPIA, Frontier, Breach and Privacy Audit handoffs.
Tokenised invitation links, per-element answers and a firm-side validate / return round-trip with a re-attestation gate on amendment.
invited → in progress → submitted ⇄ returned → validated → locked.
Login gate, workspace autosave, immutable hashed report archiving and full audit logging — the identity pattern reused across the suite.
Organisation isolation enforced in the database itself; the audit log has no update or delete grants.
Run client intake once, in a structure the rest of the engagement can reuse — and hand the controller's own staff the questions instead of an email thread.
A single register across entities with sensitivity classified consistently, and a flow map that shows the cross-border and sensitive flows the board will ask about.
A sector pack that already lists the data a clinic, a store or a hotel actually holds — so the register is a morning's work, not a project.
The zero-install register is available now for demonstrations and design partners. Praxis Schema is included in every suite plan as it ships.
Bring one real processing activity. We will build it in the register with you, draw the flow map and export it into a DPIA. Show you plainly what the full client-portal version adds and what is still in build.
Praxis Schema structures and evidences professional analysis. It does not provide legal advice, and it does not replace the review and approval of an appropriately qualified person before reliance or issue.
Every suite plan includes all seven applications as each ships — licensed by client workspace, never by seat. See plans.
Praxis DPIAImpact assessments on the 2026 DPIA Guideline
Praxis Frontiers.129 cross-border transfer assessments
Praxis Privacy AuditPrivacy-notice audit against statutory text
Praxis Breachs.12B breach notification with a live 72-hour clock
Praxis SchemaData mapping and Records of Processing Activities
Praxis PassportCitation-backed adequacy reference across jurisdictions
Praxis IntegrityPublic verification registry for every issued report