Preview — demo-ready MVP Data mapping · Records of Processing Activities · Data PORTABILITY

Stop researching sensitivity from scratch. Build a register that already knows what is sensitive, tracks where it flows, and provides portable-ready formats for data portability.

Praxis Schema is the intake layer that documents the type of data assets, tracks its whereabouts, formats it for portability and mapping for full traceability. A shared PDPA/GDPR sensitivity taxonomy with sector packs, a row-per-activity register, an automatic flow map that flags cross-border and sensitive flows, and exports built to feed a DPIA, a transfer assessment or a breach response. A zero-install register you can start today; a client-portal version in build.

Zero-install register available today 166 taxonomy elements across 11 common categories and 12 sector packs Exports feed DPIA, Frontier and Breach
46elements in 11 common data categories
120elements across 12 sector packs
PDF · JSON · XMLexports built for downstream handoff
s.129cross-border mechanism picker built in
The problem

Data mapping is where privacy programmes stall.

The spreadsheet nobody trusts

A register kept in a spreadsheet is out of date the week after it is finished, has no notion of sensitivity beyond a colour, and cannot be handed to anything downstream.

The people who know are not the people who write

The controller's own staff know what data they hold. Asking them by email produces a dozen half-answers and a document the firm has to reconcile by hand.

No picture of where it flows

Cross-border and sensitive flows are the ones the Act cares about most — and the ones a flat list makes hardest to see.

What you get

A register that classifies itself and feeds everything after it.

Sensitivity looked up, not researched

Structured, pre-classified records — sensitivity is looked up from a shared PDPA/GDPR taxonomy, not researched from scratch each time.

Sector packs that speak the client's language

Healthcare, telco, retail, education, manufacturing, insurance, government and more — sector-relevant elements and worked examples reduce generic-checklist fatigue.

Risk visible at a glance

A built-in sources → systems → recipients flow map with automatic cross-border and sensitive-flow flags — no separate diagramming.

Not a dead-end report

Exports are built to feed DPIA scoping, Frontier's cross-border analysis and breach response, so the register is the start of the record.

Amendment-era content baked in

The 72-hour breach workflow, DPO-appointment threshold hints, the revised s.129 cross-border mechanism picker and processor contract checks are built into the intake.

Start today, scale later

The zero-install register lets a firm start building a real ROPA now with no DevOps; the full version is architected for client-portal delegation at scale.

How it works

From intake to a register the suite can use.

The MVP register runs in the browser today. The full version adds a client portal and a firm-side validate-and-return cycle.

01
Choose the sector pack

Start from the 11 common categories and add the sector pack that matches the controller — healthcare, retail, hospitality, telco and more.

02
Record each activity

One row per processing activity: purpose, data elements, subjects, sources, systems, recipients, retention and legal basis — sensitivity classified from the taxonomy as you go.

03
See the flow

An SVG sources → systems → recipients map is drawn automatically, with cross-border and sensitive-data flows highlighted.

04
Resolve the amendment-era questions

Breach workflow readiness, DPO-appointment thresholds, the s.129 cross-border mechanism and processor contract checks, prompted in context.

05
Export for the next step

PDF for the client, JSON or XML for the suite — designed to seed a Praxis DPIA, a Frontier transfer assessment or a Breach response.

06
Delegate intake (full version)

Invite the controller's staff through tokenised links; they answer plain-language questions in a client portal and the firm validates, returns or locks — with re-attestation on amendment.

What is inside

Taxonomy, register, flow map, export.

Shared sensitivity taxonomy

PDPA/GDPR taxonomy: 11 common categories (46 elements) plus 12 sector packs (120 elements). Shared between the MVP and the full version, pending counsel sign-off before a v1.0 freeze.

Row-per-activity register

A structured ROPA with sensitivity pre-classified from the taxonomy rather than typed in.

Automatic flow map

Sources → systems → recipients drawn as SVG, highlighting cross-border and sensitive-data flows.

Amendment-era content

72-hour breach workflow, DPO-appointment threshold hints, revised s.129 mechanism picker and processor contract checks.

PDF, JSON and XML export

Explicitly designed to feed Praxis DPIA, Frontier, Breach and Privacy Audit handoffs.

Client portal (full version)

Tokenised invitation links, per-element answers and a firm-side validate / return round-trip with a re-attestation gate on amendment.

Intake state machine (full version)

invited → in progress → submitted ⇄ returned → validated → locked.

Praxis Accounts integration

Login gate, workspace autosave, immutable hashed report archiving and full audit logging — the identity pattern reused across the suite.

Row-level isolation (full version)

Organisation isolation enforced in the database itself; the audit log has no update or delete grants.

Built to be defended

Built to be the first record, not the last.

Status
The zero-install register is a working, demo-ready application today. The full multi-tenant version is a runnable scaffold with named unfinished pieces, and we describe it that way.
Isolation
In the full version, organisation isolation is enforced by row-level security in the database — even a query that omits its scope cannot cross tenants.
Audit
Immutable, hashed report archiving and full audit logging through Praxis Accounts; the audit log cannot be updated or deleted.
Taxonomy governance
One taxonomy, shared rather than duplicated, versioned and awaiting counsel sign-off before a v1.0 freeze.
Handoff
Exports are shaped for the suite: a Schema register seeds DPIA scoping, Frontier's cross-border analysis and a Breach response.
Deployment
Self-hosted, containerised, behind a tunnel — with a staged hardening and backup runbook.

Who runs it

Law firms

Run client intake once, in a structure the rest of the engagement can reuse — and hand the controller's own staff the questions instead of an email thread.

Enterprise DPOs

A single register across entities with sensitivity classified consistently, and a flow map that shows the cross-border and sensitive flows the board will ask about.

Clinics, e-commerce, hotels & rentals

A sector pack that already lists the data a clinic, a store or a hotel actually holds — so the register is a morning's work, not a project.

How to get it

Preview — see it on your own data.

The zero-install register is available now for demonstrations and design partners. Praxis Schema is included in every suite plan as it ships.

Preview · demo-ready MVP

Request a demonstration

Bring one real processing activity. We will build it in the register with you, draw the flow map and export it into a DPIA. Show you plainly what the full client-portal version adds and what is still in build.

  • Zero-install register, working today
  • Full multi-tenant version in build — a scaffold, described as such
  • Included in every suite plan as it ships
Common questions

Before you commit.

Yes — the zero-install register runs in the browser now and is what we demonstrate. The client portal, intake state machine and multi-tenant isolation belong to the full version, which is in build.

It is versioned at v0.9 and shared between both versions. It is pending counsel sign-off before we freeze it as v1.0.

By design. Exports are shaped to seed a Praxis DPIA's scoping, a Frontier transfer assessment's cross-border analysis and a Breach response, so the register is the first record of the engagement rather than a separate deliverable.

The taxonomy covers PDPA and GDPR sensitivity categories; the amendment-era content — breach workflow, DPO thresholds, s.129 mechanism — is Malaysian.

Request a demonstration, or apply to the Design Partner Programme for founding-cohort terms. Praxis Schema is included in every suite plan as it ships.

No. Praxis Schema structures the record. Classification and legal basis remain the judgment of an appropriately qualified person.

Praxis Schema structures and evidences professional analysis. It does not provide legal advice, and it does not replace the review and approval of an appropriately qualified person before reliance or issue.

PDPA Act 709 (Act A1727 amendments)GDPR sensitivity categoriesROPA · s.129 · s.12B
Part of the Praxis suite

One subscription. Every application.

Every suite plan includes all seven applications as each ships — licensed by client workspace, never by seat. See plans.

Register, flow map, export — and where it goes next.

See Praxis Schema on one real processing activity.

Praxis SchemaRequest a demonstration