Release notes · 5.1

What changed, and when.

Releases are listed newest first. Where a release changes how a record behaves, the walkthrough that covers it is updated in the same release.

Version 1.6

5 August 2026

The risk programme held to automated checks before anything is published.

  • The rating method, the path a risk takes and the gaps a risk raises are verified by an automated suite on every change, so a rating that averages the two consequences, a state reached out of order or a gap that fails to clear is caught before release.
  • The workspace is verified on a telephone as well as on a desktop: the register does not spill sideways, a record fits the screen, and the reference and title of an open record stay in view while its answers are scrolled.
  • The ordered route out of the gaps is checked to be numbered from one and to state, for every step, the action owed and why it is owed.

Version 1.5

3 August 2026

Privacy risk assessed on two consequences, and one record from identification to closure.

  • A risk is read on the consequence for data subjects and, separately, on the consequence for the organisation. The two readings are never averaged, and each is derived on a five by five scale rather than typed in.
  • The register moves through identified, under assessment, treatment required, treatment in progress, awaiting acceptance, monitored, accepted and closed, on one record rather than a copy for each stage.
  • The matrix is read one consequence at a time, before or after treatment, and selecting a cell filters the register below it. Risks with no assessment on that reading can be listed on their own.
  • The context an assessment was made in is recorded with it, so an assessment overtaken by a change in the processing or the measures is marked as no longer current and returned for reassessment, with earlier assessments retained as written.
  • A residual high risk to data subjects requires an authorised acceptance, and prior consultation under Article 36 where it stands.
  • The lawful condition under Article 9(2) and the authority under Article 10 are asked of the processing activity rather than of the risk raised about it.

Version 1.4

2 August 2026

Documentation rebuilt as a manual, and the compliance guide brought inside it.

  • The documentation is now organised as introduction, guides, walkthroughs, reference and release notes, with a persistent contents list.
  • The GDPR compliance guide sits under Reference rather than in the site navigation.
  • Figures show the part of the screen a step refers to, rather than the whole window.

Version 1.3

July 2026

Impact assessments guided end to end.

  • The assessment is conducted in six stages, from scope inherited from the activities in use to a frozen baseline.
  • Risks are matched to the activities they arise from, and treatment records the measure, the owner, the deadline, the evidence and the rating that remains.
  • Changes to a scoped activity after the baseline are reported as drift.

Version 1.2

June 2026

Gaps became work rather than warnings.

  • Every gap carries the article behind it and a remedy that opens the exact record and highlights the field.
  • Where a gap is a missing record, it can be linked or created from the same dialog.
  • Outstanding work is ordered into a route, so each step is possible when you reach it.

Version 1.1

May 2026

Risk and security separated from governance.

  • A risk register with ratings before and after treatment on a four by four scale.
  • Technical and organisational measures record their state of implementation and how effectiveness was tested, as Article 32(1)(d) asks.
  • Treatment wording follows ISO/IEC 27005.

Version 1.0

April 2026

First release.

  • The Article 30 record of processing, the governance documents, the operational registers and the reference records.
  • Statutory clocks for data subject requests and personal data breaches.
  • An audit trail on every record, and PDF export.