Home/Privacy & compliance/Privacy Impact Assessment
Privacy compliance
GDPR Art. 35 · high-risk

Privacy Impact Assessment. Required before high-risk launches.

GDPR Article 35 requires a Data Protection Impact Assessment (DPIA) before any processing 'likely to result in a high risk to the rights and freedoms of natural persons.' Trigger examples: AI-driven decisions, biometric identification, large-scale monitoring, special category data at scale, profiling minors. We run a 7-step DPIA: describe processing, assess necessity + proportionality, identify risks, mitigations, residual risk, consultation, document. If residual high risk remains, we prepare the supervisory authority consultation package.

All 50 states + DC 60-day money-back SOC 2 Type II
How it works

How we handle Conservation Easement, end-to-end.

A conservation easement is a permanent restriction on the use of land, typically donated to a qualified land trust to preserve the land's natural or open-space character.

1

Eligibility review

Land must have conservation value: scenic, ecological, historic, open-space, or recreational. We assess whether your land qualifies. Most rural and undeveloped properties do; urban properties rarely.

2

Land trust selection

Donation must be to a qualified land trust (501(c)(3)). We refer to local and national land trusts (Land Trust Alliance, The Nature Conservancy, regional trusts). They accept the easement and hold the restriction in perpetuity.

3

Engineering + appraisal

Engineering work documents the conservation value. Qualified appraisal determines diminished land value (the deduction amount). IRS scrutinizes appraisals; we use highly credentialed appraisers with conservation easement experience.

4

Legal documentation + closing

Easement document recorded with county recorder. Permanent restriction runs with the land. Donor receives appraisal-supported deduction. Coordination with attorney specializing in conservation easements.

What we'll set up for you

A clean handoff, in four steps.

You give us the basics. We handle the state, the IRS, and the compliance clock so you can focus on the business.

01 · Name + Brand

A name that's actually available.

Real-time check against the state register, USPTO trademark database, and matching domains.

02 · State filing

Filed with the Secretary of State.

We submit your Articles, pay the state fee on your behalf, and return the stamped certificate.

03 · Federal IDs

EIN + the right tax setup.

Federal Employer ID with the IRS, plus state tax accounts when your business needs them.

04 · Stay compliant

Registered Agent + deadline tracking.

Your agent on file in every state, with every renewal and annual report tracked in one calendar.

Pricing

Transparent conservation easement pricing.

Government fees pass through at cost. No upsells.

Trigger assessment + scoping

$899
Do you need a DPIA?

Determines whether Article 35 mandates a DPIA. Outputs scoping memo + workplan. Useful before committing to full DPIA effort.

Get started

DPIA + consultation package

$5,499
If high residual risk

Standard DPIA + Article 36 supervisory authority consultation package + response strategy. For genuinely high-risk processing (AI bias, biometric, large-scale monitoring).

Get started
FAQ

About the Conservation Easement Service.

When is a DPIA mandatory?
Article 35: any processing 'likely to result in a high risk to the rights and freedoms of natural persons.' Article 35(3) lists: systematic profiling with legal effects, large-scale special categories, large-scale public area monitoring. Plus the ICO + CNIL lists (~14 categories each).
Is the DPO required to sign off?
DPO must be consulted (Article 35(2)). Controller may proceed despite DPO objection but should document reasons. Controller (not DPO) is ultimately accountable. We include the consultation step + sign-off line.
Can a DPIA cover multiple processing activities?
Yes if they share similar risks. Example: a single DPIA covering CCTV across multiple branch offices, or a single DPIA covering an AI fraud detection model used across products. We scope at the start.
What if I do not do a DPIA when required?
Article 83 - administrative fine up to €10M or 2% global revenue. Plus authority can require post-hoc DPIA, suspend processing, or issue corrective orders. Spanish AEPD + Italian Garante both have fined companies specifically for missing DPIAs.
Does CCPA require DPIAs?
CPRA (effective 2023) adds 'risk assessment' requirements similar to DPIAs for high-risk processing. California Privacy Protection Agency (CPPA) is drafting specific rules. Colorado, Connecticut, Virginia all have similar 'data protection assessment' requirements. We can do combined GDPR DPIA + US state assessments.
How long does the supervisory authority consultation take?
Article 36 - 8 weeks normally, extendable by 6 weeks for complex cases. Authority can request additional info, suspending the clock. We manage the dialog + responses on your behalf.
Why File.Business

Premium compliance, no service-fee markup.

Trust you can verify

SOC 2 Type II audited platform. 220,000+ businesses served. 60-day money-back on service fees. State fees passed through at cost with no hidden markup. Explicit AUP on restricted industries.

A compliance partner, not a transaction

Most providers go quiet after checkout. We auto-track every annual report, registered agent renewal, and license deadline across your entities. The Business OS dashboard keeps your compliance score visible year-round.

Premium experience competitors cannot match

Premium positioning, transparent pricing, no service-fee markup on state or federal filings. Premium positioning, transparent pricing, no service-fee markup on state filings.

Start your business in the next 5 minutes.

No state-fee markup. Pay only the state fee. 60-day money-back guarantee.

No state-fee markup 60-day money-back Cancel anytime
$0 + state fee Start my business