
Acompli
Acompli is an Irish GDPR and EU AI Act governance platform for privacy teams. Assessments, risk registers, Article 30 records, third-party oversight and data mapping share one knowledge base, with AI drafting and named people approving every published record.
What is Acompli?
Acompli is a privacy and AI governance platform published by Acompli Ltd, based in Maynooth, County Kildare. It brings GDPR, UK GDPR, PECR and the EU AI Act into a single system where assessments, risks, Article 30 records, supplier files and data maps sit on one knowledge base, one review process and one audit trail. Its stated argument is that point tools create records while Acompli connects them.
Five core modules are licensed together: Assessments, Risk, RoPA Governance, Third-Party Risk and Data Mapping. Around them sit an EU AI Act AI System Register offered on opt-in early access, a paid Code Scan add-on, conversational Assistants, a PECR marketing review and a rapid onboarding service.
What distinguishes the product is the write path. Work begins by importing existing DPIAs, spreadsheet registers, supplier lists, policies and system inventories. Three read-only agents - one searching the organisational registry, one the project documents and images, one past approved assessments - compile a structured intelligence brief before any answer is written. The model then drafts with that context in front of it, and each claim is verified against two layers of the customer's own data: named systems and vendors against the entity registry, and retention, safeguards and legal mechanisms against uploaded documents. Claims touching Article 6, Article 9, international transfers or data subject rights receive mandatory extra scrutiny. Anything ungrounded is flagged into a review queue rather than passed through silently.
Only after a named person approves does the record become a platform fact. That single approval then writes the risk entries, the Article 30 fields, the searchable archive summary and the precedent candidates at once, each carrying provenance back to the source question. AI never writes directly to the record of truth.
The same governed tool registry is reachable from the web application, Microsoft Teams, Slack and Microsoft 365 Copilot, all under an eight-level role hierarchy and one immutable audit log. A German jurisdiction overlay adapts the interface, validation and export format for BDSG and DSK expectations.
What it does
- Draft DPIAs, legitimate interests assessments, transfer impact assessments, processor reviews and EU AI Act conformity assessments from templates or a plain-language description
- Populate Article 30 controller and processor registers automatically from approved assessments, with per-field confidence scores
- Check every generated claim against the entity registry and uploaded documents, and flag the ones that are not grounded
- Extract risks with provenance from approved evidence, then track treatment plans, owners and residual exposure
- Record suppliers and processors once and reuse them across assessments, RoPA, risk and data mapping
- Build a living data map of systems, locations, data categories and transfers, in graph, geographic and lineage views
- Scan nominated GitHub repositories for personal data and AI components, and route the findings into governed review
When to use Acompli / When not to
A quick filter to help you decide if Acompli is the right fit.
When to use Acompli
- Data protection officers and privacy leads who must keep an Article 30 record of processing that will stand up to a DPC or ICO request
- Compliance teams operating across several jurisdictions, with separate controller and processor registers and engines for the DPC, ICO, CNIL, BfDI, AEPD, AP and APD
- Organisations migrating a RoPA out of spreadsheets, since Excel and CSV registers import directly and are mapped onto Article 30 fields
- DACH groups needing a German Verzeichnis, with Loeschkonzept, DSK-categorised technical and organisational measures, works council tracking and a seven-sheet export
- Security and engineering leads who want repository findings, vendor due diligence and AI system documentation to feed the same evidence trail
When not to use Acompli
- Anyone wanting to sign up and start unaided, because every deployment begins with a booked walkthrough followed by scoping and guided onboarding
- Teams that need a published price before talking to a vendor, as no amount, bracket or entry tier appears anywhere on the site
- Buyers looking for a permanently free tier or a self-service trial, since the site states there is no entry-level version
- Organisations that want legal advice from the tool, which the publisher explicitly declines to provide
- Teams whose workflow depends on pushing records into ServiceNow or Jira, which the publisher lists among the things not included today
How to use Acompli
A typical end-to-end flow, from setup to results.
- Book a thirty-minute walkthrough through the contact page, bringing one real workflow, register or risk process rather than accepting a generic demo
- Work through scoping with the team, which sizes the agreement on your data controllers, legal entities, jurisdictions, integrations and security requirements
- Sign the annual agreement, then start guided onboarding, which the publisher says reaches an operational state in days rather than months
- Import your existing material in bulk: DPIAs, RoPA spreadsheets, supplier lists, contracts, policies, system inventories and architecture diagrams
- Connect single sign-on, SCIM provisioning and directory synchronisation as part of the included security baseline
- Choose an assessment from the library, or describe the processing activity in plain language and let the template builder generate one with RoPA fields pre-tagged
- Let the agents assemble the evidence brief and the model draft the answers, then work the review priority queue where flagged claims are ranked
- Approve the assessment as a named reviewer, which simultaneously drafts the risk entries, Article 30 fields, archive summary and precedent candidates
- Invite contributors by email, who respond without needing an account on a separate portal, and give stakeholders unlimited free viewer access
- Export the Evidence Pack, the jurisdiction-specific register or the GRC feed when an auditor or supervisory authority asks
Pros & Cons
Pros
- Every record stays linked to the source evidence and the reviewer decision behind it, so the same assessment answers the RoPA, the risk register and the AI inventory
- Grounding verification is explicit rather than implied: unsupported claims are flagged into a queue instead of being published quietly
- Pricing is based on the compliance estate rather than seats, so adding colleagues does not change the price and viewer access is unlimited and free
- There are no feature tiers to negotiate: every jurisdiction engine, both RoPA registers, the GRC export API, SCIM provisioning and named support are standard
- Native dual coverage of Irish and UK requirements, extended by a genuinely detailed German overlay for BDSG and DSK expectations
- The no-training and no-data-sale commitments are stated unconditionally and repeated across the homepage, the about page and the security page
- An unusually large public comparison library, spanning 169 pages and dozens of named competitors, that the publisher says is honest about where rivals are stronger
Cons
- No price is published anywhere: no amount, no bracket, no entry point, so budgeting requires a sales conversation
- No free plan and no self-service trial; evaluation access is only arranged after the vendor understands your modules and rollout
- The publisher is very young, incorporated on 21 January 2026, with the domain first archived in June 2026
- No security certification is claimed at all, neither ISO 27001 nor SOC 2, and no audit report is offered for download
- No subprocessor list is published; the privacy notice gives categories and names only OpenAI
- No hosting location is disclosed, so data residency has to be established during scoping rather than read from the site
- No terms and conditions are published, and part of the EU AI Act offering remains opt-in early access rather than generally available
Pricing & Plans
There is no free plan and no published price. Acompli is sold as a single enterprise platform under a custom annual agreement, scoped during procurement on the customer's compliance estate - the data controllers and legal entities the platform works for - together with jurisdictions, onboarding complexity, integrations and security requirements. The publisher states explicitly that it does not charge per seat, that viewer access is unlimited and free, and that there is no entry-level version. Code Scan and the EU AI Act AI Register are priced separately from the five-module platform. Because no amount, bracket or currency appears anywhere on the site, no starting price can be quoted here, and prospective buyers must request a quote.
- the core platform on a custom annual agreement
- covering all five modules
- the full AI pipeline
- unlimited assessments
- every jurisdiction engine
- controller and processor RoPA registers
- SCIM and single sign-on
- the GRC export API and SLA-backed priority support
- a paid add-on to any platform plan
- available today and scoped separately to the repository scanning workflow
- price on request
- the EU AI Act module
- offered on opt-in early access alongside the platform agreement and scoped to entities
- integrations and conformity template volume
- price on request
- unlimited and free within any agreement
- for stakeholders who read dashboards and reports without authoring
Data, GDPR & hosting
A consolidated view of how Acompli handles your data.
GDPR overview
Implementation is concrete and documented. Acompli Ltd is established in Ireland, so it falls directly under the GDPR, and its privacy notice of 15 July 2026 names its legal bases (contract, legitimate interests, consent, legal obligation), separates its controller and processor roles, and lists data subject rights with privacy@acompli.ie as the contact. Transfers rely on adequacy decisions or standard contractual clauses with supplementary measures. Security measures are itemised: encryption in transit and, where applicable, at rest, role-based access, audit logging, tenant segregation and vulnerability management. Both supervisory authorities are named with full postal addresses - the Data Protection Commission in Dublin and the ICO in Wilmslow - and a dpo@acompli.ie address appears, though qualified as applying only where relevant. Notably, the site never claims GDPR compliance for itself, and holds no security certification.
Who owns the data?
Acompli splits its role in two. It acts as controller for website visitors, sales contacts, account administration and its own security logging. For everything customers put into the platform - DPIAs, risk registers, RoPA entries, tasks, documents, third-party assessments and attachments, together called Customer Content - it acts only as processor, working on the customer's documented instructions under a data processing agreement. Customer Content stays under the customer's rights. Where an end user was invited by a client organisation, that organisation is the controller and the first point of contact. Acompli states that its staff do not routinely access Customer Content, that access is restricted and logged, and that it does not sell personal data.
Reuse rights
Customers keep control of what they put in and can reuse it freely: the platform is built so an approved answer flows into the RoPA entry, the risk register, the data map and the AI system record without being re-keyed, and every workflow ends in an exportable Evidence Pack carrying the source material, the AI draft, the reviewer's decision and the audit history. Records can be exported through branded templates, a read-only GRC integration feed and the standard reporting views. Acompli's own reuse is narrower and stated as such: it processes Customer Content only on the customer's instructions, does not use it to train its own general-purpose models, and does not sell personal data. Inputs to AI features may pass to a provider such as OpenAI, which the publisher says does not train on API traffic by default. A change of contractual scope leaves the knowledge base, risk register and assessment archive untouched.
Data retention & training
Hosting summary
Acompli does not disclose where the platform is hosted. The privacy notice makes only one statement about location: personal data may be processed in the EEA and the UK and, depending on customer configuration and the subprocessors used including AI processing, may be processed in other jurisdictions, which can include the United States. That is a transfer clause rather than a data residency commitment. Where transfers occur, the publisher says it relies on adequacy decisions or standard contractual clauses with supplementary measures where required. Stated security controls include encryption in transit and, where applicable, at rest, role-based access with least privilege, audit logging and monitoring, and tenant and organisational segregation. No subprocessor list is published: the notice names categories such as hosting, infrastructure, monitoring, support tooling, email delivery, analytics and AI processing, and identifies only OpenAI. Buyers with data residency obligations should settle this in writing during scoping.
Things to keep in mind
Risks and trade-offs to weigh before adopting Acompli.
- Automation bias is the central risk: the workflow asks a named person to approve AI-drafted records, and a reviewer who clicks through confidence scores without reading inherits legal accountability for text they never checked
- Compliance work is where judgement is built, so a team that stops drafting its own assessments may gradually lose the reasoning skill it needs when a supervisory authority asks why a decision was made
- Grounding scores can create false confidence, since a claim can be traceable to an internal document and still be wrong if that document is outdated or was itself drafted with assistance
- The publisher was incorporated in January 2026, so continuity of the vendor is a real consideration for records an organisation must keep and produce for years
- No security certification, no subprocessor list and no stated hosting location are published, which leaves an evidence gap for a tool whose whole purpose is producing evidence
- AI features may route extracts of highly sensitive material, including special category data placed in DPIAs, to an external provider, so configuration and zero data retention eligibility deserve close attention
- Records approved once become citable platform facts reused by later modules, so an early mistake can propagate quietly across the RoPA, the risk register and the AI inventory
Setup & Integrations
Technical difficulty
Low effort for the customer, because the vendor does the work. There is no self-service sign-up: every deployment starts with a walkthrough, then scoping, then guided onboarding, which the publisher says reaches an operational state in days rather than months. Implementation, training, a single sign-on and security baseline and a dedicated implementation partnership are included in every annual agreement. Migration is handled by bulk import of Excel and CSV registers, live connectors and diagram extraction. Contributors respond by email without needing a separate portal account. The real effort is organisational rather than technical: agreeing scope, approval chains and jurisdictions.
Deployment
Integrations
Supported languages
Behind Acompli
Resources
All the official URLs gathered for verification and reference.
Alternatives
Tools that compete with or complement Acompli.
Frequently asked questions
What does Acompli actually do?
How much does it cost?
Is there a free plan or a trial?
Does Acompli train AI models on customer data?
How does it stop the AI inventing things?
Can it work inside Microsoft Teams or Slack?
Can we move our RoPA out of Excel?
Does it cover German requirements?
Where is the data hosted?
Who is behind Acompli?
Should you pick Acompli?
Acompli makes a clear and unusually disciplined argument: compliance records are only worth having if they are connected and defensible, so the AI is allowed to draft, extract and classify but never to publish. Grounding verification against the customer's own registry and documents, mandatory scrutiny of sensitive claims, and a named human approval that simultaneously writes the risk entries and the Article 30 fields, all add up to a product built around evidence rather than speed. For a privacy team in Ireland or the UK that has to show its working to the DPC or the ICO, and for DACH groups needing a proper German Verzeichnis, the fit is good. Pricing on the compliance estate rather than per seat is a genuine differentiator when the whole point is to automate work people used to do.
The reservations are mostly about maturity and disclosure rather than design. Acompli Ltd was incorporated on 21 January 2026 and the site first appeared in the Wayback Machine that June, so this is an early-stage vendor. Nothing is priced publicly, there is no free plan and no self-service trial. More pointedly for a vendor selling assurance, the site publishes no security certification, no subprocessor list and no hosting location, and it never claims GDPR compliance for itself - an abstention that is honest, but leaves due diligence to the buyer. Part of the EU AI Act offering is still opt-in early access. Treat the walkthrough as the moment to pin down hosting, subprocessors and audit evidence, and judge the product on the record it produces.
- Choosing a selection results in a full page refresh.
- Opens in a new window.