Saltar al contenido
DSA Compliance DSA Compliance Regulatory compliance · Spain and Latin America

Compliance, under control.

You comply on paper and nobody can prove it on inspection day. Every obligation with its control, its owner and its dated evidence. The rule changed in March and your procedure is still the 2023 one. The rule changes and the platform tells you what you have to change.

DSA Compliance turns a legal obligation into a live control: sixteen compliance areas in Spain and Latin America, in a single framework and with the evidence always findable.

Client access · tenant login
DSA Compliance dashboard showing the status of each compliance area
Whistleblowing channel inbox with the statutory deadlines tracked by the system
Criminal risk map with its controls and the status of each one
Time tracking dashboard with the exceptions that get inspected
DSA Compliance dashboard showing the status of each compliance area
Dashboard
Whistleblowing channel
Criminal risk
Time tracking
The premise

Complying and being able to prove it are two different problems. The second one is what costs money.

WHAT ACTUALLY GETS DONE Training delivered Control executed Supplier reviewed WHAT CAN BE PROVEN IN AN INSPECTION no evidence no evidence evidence · 12/03/26 It is done. It cannot be proven. And in front of the inspector, the second is the only thing that counts.
WHAT ACTUALLY GETS DONE
Training delivered · control executed · supplier reviewed
WHAT CAN BE PROVEN
No evidence · no evidence · evidence dated 12/03/26

It is done. It cannot be proven.

Almost every company complies. The problem comes when proving it: the evidence sits in someone’s inbox and the control existed, but nobody recorded it.

DSA Compliance is not a document repository. It gives every obligation a control, an owner, a deadline and dated evidence.

Who is behind the platform →
The starting point

Compliance spread across five places nobody looks at together

Before
With DSA Compliance
the expiry alert never arrives Shared folder hundreds of PDFs with no validity date Expiry spreadsheet kept by a single person Email from the advisers the ruling lives in a thread Annual audit one snapshot a year Suppliers checked once there is already trouble The evidence exists. Finding it does not. Every audit starts by rebuilding it by hand.
Shared folderHundreds of PDFs with no validity date. Nobody knows which one is current.
Expiry spreadsheetOne person keeps it. When that person is away, nobody raises the alert.
Email from the advisersThe legal ruling exists, but it lives in an email thread from eight months ago.
Annual auditOne snapshot a year. The remaining eleven months are blind.
SuppliersIt is required of them by contract and checked once there is already a problem.
The evidence exists. Finding it does not.
And the expiry alert gets lost along the way.

Five places nobody looks at together. The control was done, but the proof that it was done is scattered, undated and unowned.

Penalty risk
It is done, but it cannot be proven.
Key-person dependency
The control lives in one person’s head.
Audit cost
Every review starts by rebuilding the evidence.
Outdated rules
The procedure ages without anyone noticing.
1 Obligation what applies to you and why 2 Control owner and frequency 3 Evidence dated and timestamped 4 Monitoring expiry dates and regulatory change 5 Proof case file in one click

A single framework. Behind every obligation there is a control with an owner and dated evidence, and the day the inspection arrives the case file assembles itself.

The cycle

From the rule to the proof, without going through the folder

Click each phase to see what the platform does, what gets recorded and what stops depending on a person.

01
Obligation
02
Control
03
Evidence
04
Monitoring
05
Proof
What the platform does

It determines what applies to you based on your activity, your size, the countries you operate in and the data you process. Not a generic list: your framework.

What gets recorded

The obligation with its legal basis, the reason it applies to you and the authority that enforces it.

What stops depending on a person

Knowing which regulations affect you. It stops being an annual conversation with your advisers.

What the platform does

It turns the obligation into concrete controls with an owner, a frequency and an alert threshold. What has to be done, by whom and how often.

What gets recorded

The control, its named owner, the next due date and its real status today.

What stops depending on a person

The reminder. The control chases the right person on its own.

What the platform does

It captures the proof at the moment the control is executed: the clock-in, the completed training, the minutes, the consent, the signed review.

What gets recorded

The document with its timestamp, its version, who provided it and which control it answers to.

What stops depending on a person

Remembering where it was filed. Evidence is born already filed where it belongs.

What the platform does

It watches two clocks: your own expiry dates and the regulation. When the rules change, it flags which controls and which documents need reviewing.

What gets recorded

The alert, who received it, what was done with it and how long it took to close.

What stops depending on a person

Finding out. Regulatory change arrives as a task, not as news.

What the platform does

It assembles the case file for whichever area is asked of you, with the full history and in the format it is submitted in.

What gets recorded

Full traceability: what was checked, when, with what result and with what proof behind it.

What stops depending on a person

The three weeks of rebuilding the evidence every time someone asks for it.

The platform, from the inside

A dashboard, not a filing cabinet

See the areas in detail at dsacompliance.net →
Dashboard
3 screens
Overall compliance status
Personal data
3 screens
Record of processing activities
Whistleblowing channel
3 screens
Report inbox with deadlines
Criminal compliance
3 screens
Risk and control map
Time tracking
3 screens
Working time records and absence
AI governance
3 screens
System inventory and risk
Each area cycles through its screens on its own. Click one to see it full size.
DSA Compliance dashboard
Status by area

The first screen answers the only question that matters in a committee: which areas are under control, which fall due this month and what is stalled waiting for someone.

Roles and permissions in DSA Compliance
Who sees what

Permissions by area and by group entity. The whistleblowing channel is seen by the compliance body; time tracking, by HR. Nobody sees what is not theirs.

DSA Compliance integrations
Where the data comes from

Corporate identity, HR, electronic signature and DSA Core. Evidence comes in from where it is already generated, without asking for it again.

DSA Compliance dashboard
Status by area

The first screen answers the only question that matters in a committee: which areas are under control, which fall due this month and what is stalled waiting for someone.

Record of processing activities in DSA Compliance
A living RoPA

The record of processing activities with its lawful basis, its retention periods and the associated processors. It stops being a consultancy document and becomes a register that is actually maintained.

Data subject rights in DSA Compliance
Rights

Every request with its statutory deadline tracked by the system, its owner and the response issued. Not a spreadsheet with dates typed in by hand.

Breach register in DSA Compliance
Breaches

The 72-hour clock starts the moment the breach is logged, with the risk assessment and the decision to notify both documented.

Record of processing activities in DSA Compliance
A living RoPA

The record of processing activities with its lawful basis, its retention periods and the associated processors. It stops being a consultancy document and becomes a register that is actually maintained.

DSA Compliance whistleblowing channel inbox
Inbox

The whistleblowing channel with real confidentiality, statutory deadlines tracked by the system and traceability of every action taken.

DSA Compliance whistleblowing case file
Case file

Every case with its investigator, its actions, its proposed measures and the acknowledgement sent within seven days.

DSA Compliance whistleblower portal
Whistleblower portal

With anonymous tracking by code: the whistleblower checks the status without revealing their identity or depending on anyone.

DSA Compliance whistleblowing channel inbox
Inbox

The whistleblowing channel with real confidentiality, statutory deadlines tracked by the system and traceability of every action taken.

Criminal risk map in DSA Compliance
Risk map

The criminal risk map with its assessment, the controls that mitigate it and the real status of each control. It is what you show to prove a prevention model that works.

Prevention model controls in DSA Compliance
Controls

Every control with its owner, its frequency and its last proven execution. A model with no executed controls exempts you from nothing.

Compliance body report in DSA Compliance
Report to the board

The periodic report to the board is assembled with the evidence behind it, not written up after the fact.

Criminal risk map in DSA Compliance
Risk map

The criminal risk map with its assessment, the controls that mitigate it and the real status of each control. It is what you show to prove a prevention model that works.

Time tracking dashboard in DSA Compliance
Exceptions

Working time records with the exceptions that really do get inspected: excess hours, rest between shifts and incomplete clock-ins, flagged before they become a problem.

Clock-in in DSA Compliance
The clock-in

With its time, its source and its traceability. Unalterable afterwards: any correction is logged as an exception with a reason and an author.

Absence and leave in DSA Compliance
Absence

Holiday, leave and sick leave in the same calendar as working time. Half of the requests in an inspection come from here.

Time tracking dashboard in DSA Compliance
Exceptions

Working time records with the exceptions that really do get inspected: excess hours, rest between shifts and incomplete clock-ins, flagged before they become a problem.

AI system inventory in DSA Compliance
Inventory

The inventory of AI systems with their risk classification and the obligations each one carries. The newest area and the one changing fastest.

AI impact assessment in DSA Compliance
Impact assessment

Every system with its assessment, its mitigation measures and the human oversight declared in writing.

AI incidents in DSA Compliance
Incidents

The incident log with its remediation, its deadline and who answers for it. Without this, AI governance is a policy with no practice.

AI system inventory in DSA Compliance
Inventory

The inventory of AI systems with their risk classification and the obligations each one carries. The newest area and the one changing fastest.

Coverage

Sixteen areas, a single control framework

Only what applies to you is switched on; the rest stays out of the way. Each area with its real screen behind it: click any of them to see it full size.

Request a guided demo →
Personal data dashboard: RoPA status, rights requests in progress and open breaches
Enlarge
Personal data

RoPA, lawful basis, data subject rights, breaches and impact assessments.

The 72-hour breach clock is counted by the system, not by a person.
Whistleblowing channel dashboard: open cases, acknowledgement deadlines and the status of each case file
Enlarge
Whistleblowing channel

Confidential inbox, statutory deadlines and a case file for every report.

With anonymous tracking: the whistleblower checks the status without identifying themselves.
Criminal risk assessment by process, with likelihood, impact and residual risk
Enlarge
Criminal compliance

Risk map, controls, compliance body and periodic report.

A prevention model with no executed controls exempts you from nothing.
Clock-in with its time, its source and its full traceability
Enlarge
Time tracking

Working time records, absence and inspectable exceptions.

The clock-in is unalterable: any correction is logged with a reason and an author.
Environmental permits with their validity, their issuing authority and their conditions
Enlarge
Environmental

Permits, emission points, waste and carbon footprint.

A permit about to expire warns you in advance, not when the inspection arrives.
ESG project portfolio with its milestones, indicators and progress
Enlarge
ESG and sustainability

Project portfolio, indicators and reporting with the evidence behind it.

Every reported indicator points to the document that supports it.
The supplier's geolocated plots, checked against satellite imagery
Enlarge
EUDR — deforestation

Due diligence statement, geolocated plots and batch passport.

Plots checked against satellite imagery, not against a supplier’s certificate.
AI governance dashboard: inventoried systems, risk and incidents
Enlarge
AI governance

System inventory, risk classification, incidents and remediation.

The newest area and the one changing fastest.
Training campaigns by area, with coverage and who is still outstanding
Enlarge
Mandatory training

Campaigns by area, recorded completion and training passport.

Who is still to be trained is visible before it becomes a finding.
Document file for an area, with versions and timestamping
Enlarge
Document manager

A file per area, versions, timestamping and retention policy.

Evidence is born filed where it belongs, with its date stamped.
Supplier dashboard with its vetting and documentation traffic light
Enlarge
Supplier chain

Vetting, supplier portal and verifiable documentary requirements.

The supplier maintains their own documentation in their portal.
Questionnaire centre: active campaigns, responses received and outstanding
Enlarge
Questionnaires and campaigns

Bulk information gathering with tracking of who is missing.

You launch it once and the system chases whoever has not replied.
Regulatory change lands on the dashboard as a task with an owner and a deadline
Enlarge
Regulatory monitoring

Regulatory change arrives as a concrete task, not as a circular.

It lands on the dashboard with an owner, a deadline and the document to review.
Compliance assistant answering within the organisation's own documentation
Enlarge
Compliance assistant

AI with guardrails: it drafts and classifies within your data, it never decides alone.

It answers citing your own documentation, and what you asked is recorded.
Access and identity: group entities, users and isolation by organisation
Enlarge
Multi-organisation

Group, subsidiaries and countries with isolation by entity and a consolidated view.

Each subsidiary sees its own; the parent sees the consolidated view. With nothing duplicated.
Active integrations with corporate identity, HR, electronic signature and DSA Core
Enlarge
Integrations

Corporate identity, HR, electronic signature and DSA Core.

Evidence comes in from where it is already generated, without asking for it again.
DSA Compliance screens with demonstration data.
The day that matters

The request arrives. The case file assembles itself.

No favours to ask, no folders to rebuild and no depending on who was around that month.

REQUEST Labour Inspectorate «Produce the March working time records.» DSA COMPLIANCE CASE FILE ASSEMBLED Current procedure · v3.2 approved 14/01/26 Working time records 01–31/03 1.284 clock-ins Exceptions detected and resolved 12 of 12 Manager validation signed 02/04/26 READY TO SUBMIT · 1 CLICK
REQUEST
Labour Inspectorate
«Produce the March working time records.»
CASE FILE ASSEMBLED
Current procedure · v3.2approved 14/01/26
Working time records 01–31/031.284 clock-ins
Exceptions detected and resolved12 of 12
Manager validationsigned 02/04/26
READY TO SUBMIT · 1 CLICK
Ecosystem

Two sister platforms under DSA Nexus

Compliance constrains operations and operations feed compliance. It is the same data crossing the bridge in both directions.

DSA Compliance
Compliance

It sets the constraint: which technician is cleared, which supplier is vetted and which documents expire this week.

www.dsacompliance.net →
DSA Nexus
Data
bridge
DSA Core
Operations

It generates the fact —who worked, where and with what evidence— and returns it as proof of compliance, without asking for it again.

See DSA Core →

This is the thirty-second view. The detail lives on the product website.

Areas in detail, pricing, guided demo and client access are all at dsacompliance.net. If what you need is someone to review your real situation before talking about software, that we do here.

Next step

Tell me what the last inspection asked you for. With that we know where to start.

The session is led by the person who would run the rollout. No cost, no sales pitch and a written conclusion, even if the conclusion is that two areas are enough for you.

Close
DSA Compliance screen with demonstration data.
DSA Nexus

Process consulting and custom software engineering for mid-sized companies in Spain and Latin America.

Based in Madrid · Projects in Spain and Latin America
Services
Platforms
Company
DSA Nexus S.L. © 2026. All rights reserved. · ISO 9001:2015 certified by LRQA