Introduction to the Risk Module
The Risk Management module helps you assess threats to your organisation’s compliance and operations — whether it’s GDPR-related data risks or broader security risks under NIS2.
The Risk Module in dot.legal supports:
- Risk assessments on processing activities (typically related to personal data)
- Risk assessments on assets (typically IT/OT systems or infrastructure)
You can also assign each risk to a compliance domain, such as GDPR, NIS2 or internal frameworks.

What Is the dot.legal Risk Module Used For?
- Identify and assess risks across the organisation
- Prioritise which threats to act on
- Document likelihood, impact and mitigating actions
- Create tasks directly from risks
- Monitor changes over time with version history
Whether you’re preparing for an audit, tracking threats from vendors, or ensuring your systems meet your own InfoSec policies — the dot.legal Risk Module is your central hub for managing it all.
GDPR vs. NIS2 Focus
Each risk template lets you define whether it applies to GDPR, NIS2, or another compliance framework. This means you can tailor your risk assessments to the specific regulatory obligations most relevant to your organisation, and report on them separately.