How it works

See how Veld runs a DPO practice.

One workspace for the work that keeps a data protection practice moving. From the first client to the final evidence record, Veld keeps the work, deadlines and decisions together.

Clients. DSARs. Breaches. ROPA. DPIAs. Documents. Evidence.

Opens on your machine · No account needed · Nothing to install

VELD · PRACTICE DASHBOARD
veld. DashboardClientsDSARsROPADPIAsBreachesEvidence
12Clients
7Open DSARs
9DPIAs
184ROPA records
3Due in 7 days
1Overdue
Clients & health
Harborview Housing92
Bryant & Mace74
Fernwell Clinic Group88
Ridgeway Academy Trust61
Next deadlines
Tenant DSAR — flat 12BHarborview Housing
2d over
Former employee — accessBryant & Mace
5d left
CCTV DPIA — reviewRidgeway Academy Trust
Medium risk
Misdirected email — 40 tenantsArticle 33 · notify by 17 Jun 09:20
19h

An illustration. The organisations and records shown are fictional.

The walkthrough

One practice. Six workflows.

Veld isn’t a process you adopt — it’s the process you already run, with the tracking handled.

01

Your clients

Keep every controller, contact and engagement in one place.

Each organisation you advise becomes a client in your workspace, with its own sector, data role and contact details. Everything that follows — requests, registers, assessments — hangs off the client it belongs to.

In the workspace
  • Controller, processor or joint controller per client
  • Notes for retainer terms and watch-outs
  • One-glance snapshot of open work per client
CLIENTS
Harborview Housing AssociationHousing · Controller
Tenant DSAR — flat 12B2d over
CCTV DPIA — communal areasSigned off
ROPA — tenancy managementCurrent

Choose a client to see the work hanging off it.

02

Your deadlines

Never lose the clock.

The moment a DSAR is logged, Veld applies the UK GDPR calendar-month rule — end-of-month quirks included — and starts the countdown. Apply an extension and the clock adjusts to the full three months. The deadline becomes operational rather than merely recorded.

In the workspace
  • Automatic statutory deadlines, no diary maths
  • Amber at seven days, red the moment it’s overdue
  • Every open clock across your whole book on one dashboard
DSAR · R. OKAFOR
  1. Received23 May
  2. Acknowledged24 May
  3. Due23 Jun
  4. Extensionto 23 Aug, if applied
  5. Complete—
21days remaining
2days overdue · Tenant DSAR, flat 12B

Demo data — the dates and counts are fictional.

03

Your breaches

The 72-hour clock, in view.

Article 33 gives you seventy-two hours from becoming aware — not from finishing the investigation, which is the mistake that costs people. Log the breach with the moment of awareness and Veld counts down in hours, through the night and the weekend. You assess and you decide; Veld records the decision either way.

In the workspace
  • Countdown from awareness, with the deadline shown as a date and time
  • The notify-or-not decision recorded either way, with your reasoning
  • Article 34 assessed separately — high risk to individuals is its own test
  • A breach you decide not to report still leaves a defensible record that you decided
BREACH · MISDIRECTED EMAIL
Article 33 · time to notify 41:28 remaining of 72 hours · aware 14 Jun 09:20
  1. Awareness14 Jun 14:32
  2. AssessmentScope and risk recorded
  3. DecisionYours to make
  4. NotificationDue 17 Jun 09:20

Demo data. Veld records the decision — it does not make it.

04

Your registers

ROPA and DPIA, connected to the client.

Article 30 records and DPIA logs live alongside the client they describe. Add an activity when you spot it, update a DPIA as it moves through review — the register is always the current one, never the one you’ll tidy up later. These are not isolated documents; they are connected records inside the client’s workspace.

In the workspace
  • ROPA entries with lawful basis, categories and retention
  • DPIAs tracked from draft to sign-off with residual risk
  • Recurring reviews on a cadence, so the register is revisited before it drifts
  • Nothing lives in a forgotten spreadsheet tab
RIDGEWAY ACADEMY TRUST
  1. ClientRidgeway Academy TrustEducation · Controller
  2. Processing activityCCTV — communal areasSafeguarding and site security
  3. ROPAArticle 30 recordLegitimate interests · 31 days retention
  4. DPIAArticle 35 assessmentRequired · signed off 12 May
  5. RiskResidual risk: lowSignage, retention limit, access log

One client, one activity, and the records that belong to it.

05

Your decisions

You decide. Veld documents it.

Veld doesn’t replace professional judgement. It gives you a structured place to record it. The response pack works backwards from your decisions: record which systems were searched, what the outcome is and which exemptions you rely on, and the letter assembles itself around those choices — every paragraph traceable to the decision that produced it.

In the workspace
  • Withholding grounds quoted in full, not summarised as “an exemption applies”
  • An on-device scan flags candidate personal data in the bundle before you send it
  • NHS and NI numbers checked against their own validation rules, not just matched
  • Nothing is model-generated, so every sentence is one you can stand behind
Practitioner decision
Veld records
  • DecisionDisclose
  • RationaleData subject’s own personal data
  • ProvisionArticle 15(3)
  • Evidence3 documents attached
  • TimestampLogged on decision
Response pack Disclosure letter, quoting Article 15(3) in full Assembled around your decision, not in place of it

Cited, not generated. Veld assembles the evidence and reasoning around your decision. It doesn’t pretend to make the decision for you.

06

Your evidence

The work becomes the record.

Every action, decision and supporting record becomes part of the evidence of what happened. When the auditor, the board or the renewing client asks, the answer is already assembled — because the administrative record was created as part of doing the work, not written up afterwards.

In the workspace
  • Evidence log built from the work itself, not written up afterwards
  • A health score you can recompute by hand and defend line by line
  • PDF, Word and Excel documents; full workspace export in open JSON
  • Per-client reporting for retainer conversations
EVIDENCE LOG
  1. DSAR received
  2. Identity verified
  3. Search completed
  4. Third-party data identified
  5. Disclosure decision recorded
  6. Response prepared
  7. Evidence exported

Demo data — one morning of a single request.

Before and after

From scattered work to one workspace.

veld.
  • Clients
  • DSARs
  • ROPA
  • DPIAs
  • Breaches
  • Evidence
Private by design

The workspace is private by design.

Veld is designed so that your client data remains unreadable to Veld.

Your device
Your workspaceReadable, on your machine
Veld
████████████Ciphertext, and no key that opens it

Explore the security architecture →

That page sets out both settings in full, what the design does not protect against, and how to verify it yourself.

07 — The one you cannot try yet

Asking your book a question

The six above are the practice, and every one of them runs today. There is a seventh thing Veld can do: an optional assistant that answers questions about your workspace without ever being shown it.

Built, not switched on. No model provider is engaged and nobody can use it yet. The tools it would use are read-only and run in your browser, so what reaches a model is a pseudonymous reference rather than your client — which is the part worth assessing before it ships rather than afterwards. How the assistant works.

Ready to run your practice
differently?

Start with a private workspace. Add sync when you need it.