Compliance, under control.
DSA Compliance turns a legal obligation into a live control: sixteen compliance areas in Spain and Latin America, in a single framework and with the evidence always findable.
Client access · tenant login




Complying and being able to prove it are two different problems. The second one is what costs money.
It is done. It cannot be proven.
Almost every company complies. The problem comes when proving it: the evidence sits in someone’s inbox and the control existed, but nobody recorded it.
DSA Compliance is not a document repository. It gives every obligation a control, an owner, a deadline and dated evidence.
Who is behind the platform →Compliance spread across five places nobody looks at together
Five places nobody looks at together. The control was done, but the proof that it was done is scattered, undated and unowned.
A single framework. Behind every obligation there is a control with an owner and dated evidence, and the day the inspection arrives the case file assembles itself.
From the rule to the proof, without going through the folder
Click each phase to see what the platform does, what gets recorded and what stops depending on a person.
It determines what applies to you based on your activity, your size, the countries you operate in and the data you process. Not a generic list: your framework.
The obligation with its legal basis, the reason it applies to you and the authority that enforces it.
Knowing which regulations affect you. It stops being an annual conversation with your advisers.
It turns the obligation into concrete controls with an owner, a frequency and an alert threshold. What has to be done, by whom and how often.
The control, its named owner, the next due date and its real status today.
The reminder. The control chases the right person on its own.
It captures the proof at the moment the control is executed: the clock-in, the completed training, the minutes, the consent, the signed review.
The document with its timestamp, its version, who provided it and which control it answers to.
Remembering where it was filed. Evidence is born already filed where it belongs.
It watches two clocks: your own expiry dates and the regulation. When the rules change, it flags which controls and which documents need reviewing.
The alert, who received it, what was done with it and how long it took to close.
Finding out. Regulatory change arrives as a task, not as news.
It assembles the case file for whichever area is asked of you, with the full history and in the format it is submitted in.
Full traceability: what was checked, when, with what result and with what proof behind it.
The three weeks of rebuilding the evidence every time someone asks for it.
A dashboard, not a filing cabinet
The first screen answers the only question that matters in a committee: which areas are under control, which fall due this month and what is stalled waiting for someone.
Permissions by area and by group entity. The whistleblowing channel is seen by the compliance body; time tracking, by HR. Nobody sees what is not theirs.
Corporate identity, HR, electronic signature and DSA Core. Evidence comes in from where it is already generated, without asking for it again.
The first screen answers the only question that matters in a committee: which areas are under control, which fall due this month and what is stalled waiting for someone.
The record of processing activities with its lawful basis, its retention periods and the associated processors. It stops being a consultancy document and becomes a register that is actually maintained.
Every request with its statutory deadline tracked by the system, its owner and the response issued. Not a spreadsheet with dates typed in by hand.
The 72-hour clock starts the moment the breach is logged, with the risk assessment and the decision to notify both documented.
The record of processing activities with its lawful basis, its retention periods and the associated processors. It stops being a consultancy document and becomes a register that is actually maintained.
The whistleblowing channel with real confidentiality, statutory deadlines tracked by the system and traceability of every action taken.
Every case with its investigator, its actions, its proposed measures and the acknowledgement sent within seven days.
With anonymous tracking by code: the whistleblower checks the status without revealing their identity or depending on anyone.
The whistleblowing channel with real confidentiality, statutory deadlines tracked by the system and traceability of every action taken.
The criminal risk map with its assessment, the controls that mitigate it and the real status of each control. It is what you show to prove a prevention model that works.
Every control with its owner, its frequency and its last proven execution. A model with no executed controls exempts you from nothing.
The periodic report to the board is assembled with the evidence behind it, not written up after the fact.
The criminal risk map with its assessment, the controls that mitigate it and the real status of each control. It is what you show to prove a prevention model that works.
Working time records with the exceptions that really do get inspected: excess hours, rest between shifts and incomplete clock-ins, flagged before they become a problem.
With its time, its source and its traceability. Unalterable afterwards: any correction is logged as an exception with a reason and an author.
Holiday, leave and sick leave in the same calendar as working time. Half of the requests in an inspection come from here.
Working time records with the exceptions that really do get inspected: excess hours, rest between shifts and incomplete clock-ins, flagged before they become a problem.
The inventory of AI systems with their risk classification and the obligations each one carries. The newest area and the one changing fastest.
Every system with its assessment, its mitigation measures and the human oversight declared in writing.
The incident log with its remediation, its deadline and who answers for it. Without this, AI governance is a policy with no practice.
The inventory of AI systems with their risk classification and the obligations each one carries. The newest area and the one changing fastest.
Sixteen areas, a single control framework
Only what applies to you is switched on; the rest stays out of the way. Each area with its real screen behind it: click any of them to see it full size.
RoPA, lawful basis, data subject rights, breaches and impact assessments.
Confidential inbox, statutory deadlines and a case file for every report.
Risk map, controls, compliance body and periodic report.
Working time records, absence and inspectable exceptions.
Permits, emission points, waste and carbon footprint.
Project portfolio, indicators and reporting with the evidence behind it.
Due diligence statement, geolocated plots and batch passport.
System inventory, risk classification, incidents and remediation.
Campaigns by area, recorded completion and training passport.
A file per area, versions, timestamping and retention policy.
Vetting, supplier portal and verifiable documentary requirements.
Bulk information gathering with tracking of who is missing.
Regulatory change arrives as a concrete task, not as a circular.
AI with guardrails: it drafts and classifies within your data, it never decides alone.
Group, subsidiaries and countries with isolation by entity and a consolidated view.
Corporate identity, HR, electronic signature and DSA Core.
The request arrives. The case file assembles itself.
No favours to ask, no folders to rebuild and no depending on who was around that month.
Two sister platforms under DSA Nexus
Compliance constrains operations and operations feed compliance. It is the same data crossing the bridge in both directions.
It sets the constraint: which technician is cleared, which supplier is vetted and which documents expire this week.
www.dsacompliance.net →bridge
It generates the fact —who worked, where and with what evidence— and returns it as proof of compliance, without asking for it again.
See DSA Core →This is the thirty-second view. The detail lives on the product website.
Areas in detail, pricing, guided demo and client access are all at dsacompliance.net. If what you need is someone to review your real situation before talking about software, that we do here.
Tell me what the last inspection asked you for. With that we know where to start.
The session is led by the person who would run the rollout. No cost, no sales pitch and a written conclusion, even if the conclusion is that two areas are enough for you.