Client Management

Invite clients, monitor their compliance status, and provide ongoing support

6 min readUpdated 26 February 2026
Reseller AdminReseller Member

Managing Your Client Portfolio

Effective client management is at the heart of a successful reseller operation. GDPR4All provides you with a dedicated client management portal that lets you invite new organisations, monitor their compliance posture, assign resources, and deliver ongoing support — all from a single dashboard.

This guide covers the full client lifecycle, from initial invitation through to day-to-day compliance monitoring and support.

Inviting and Onboarding New Clients

Adding a new client to your portfolio is a straightforward process that takes just a few minutes.

Sending an Invitation

From your reseller dashboard, navigate to the Clients section and click "Invite Client". You will be prompted to enter the client organisation's name, the primary contact's email address, and an optional note that will be included in the invitation email. Once submitted, the client receives an automated email with a secure link to activate their workspace.

Client Activation

When your client clicks the activation link, they are guided through a short setup wizard. This includes setting their password, confirming their organisation details, and choosing their preferred language (English or French). Upon completion, a dedicated workspace is created for that organisation with its own isolated data environment.

Post-Activation Setup

After activation, we recommend scheduling a brief onboarding call with your client to walk them through the platform. During this call, you can help them configure their initial settings, import any existing compliance records, and set up their team members. A smooth onboarding experience sets the tone for a productive, long-term relationship.

Client Workspace Overview — What Each Client Gets

Every client workspace is a fully isolated environment within the GDPR4All platform. Each client has access to the complete suite of GDPR compliance modules.

  • ROPA — Records of Processing Activities register, with status tracking and legal basis documentation.
  • Breach Notifications — Incident logging with a 72-hour countdown timer for supervisory authority notification.
  • Consent Management — Consent record tracking with automatic expiry detection and withdrawal support.
  • DPIA — Data Protection Impact Assessments with risk scoring, approval workflows, and linked processing activities.
  • DSR — Data Subject Request management with 30-day and 90-day deadline tracking.
  • Document Generator — Automated generation of privacy policies, breach notifications, DPIA reports, cookie policies, and more, with a full approval workflow.
  • Training Academy — Courses, modules, quizzes, and webinar sessions to keep client teams trained on GDPR requirements.
  • Vendor Management — Third-party vendor register with DPA tracking, compliance assessments, and sub-processor mapping.

Each module operates independently within the client's workspace, and all data is strictly tenant-isolated. You, as the reseller, have read access to your clients' compliance data for support and oversight purposes, but you cannot modify their records directly.

Monitoring Client Compliance Status

Your reseller dashboard provides a consolidated compliance overview across your entire client portfolio.

Compliance Scores

Each client is assigned an overall compliance score based on the completeness of their ROPA register, the status of their breach notifications, DPIA progress, consent record health, and DSR response times. These scores are displayed on your client list and can be sorted to quickly identify organisations that may need attention.

Alerts and Notifications

The platform surfaces alerts for critical compliance events across your client base. These include breach incidents approaching the 72-hour notification deadline, overdue Data Subject Requests, expiring DPAs with vendors, and DPIAs awaiting approval. These alerts appear on your reseller dashboard and can also be sent to you via email.

Over time, you can track how each client's compliance posture evolves. The dashboard displays trend indicators — such as improvements in ROPA completeness or reductions in overdue DSRs — helping you demonstrate the value of your services during review meetings.

Client Roles

Each client workspace supports three distinct user roles, each with different levels of access and responsibility.

CLIENT_ADMIN

The Client Admin has full control over their organisation's workspace. They can manage users, configure settings, create and edit compliance records across all modules, approve DPIAs and documents, and view audit logs. Typically, this role is assigned to the organisation's compliance lead or data protection manager.

COMPLIANCE_OFFICER

The Compliance Officer has operational access to all compliance modules. They can create, edit, and manage ROPA entries, breach incidents, consent records, DPIAs, DSRs, documents, and vendor records. However, they cannot manage users, change organisation settings, or perform certain approval actions that are reserved for the Client Admin.

CLIENT_USER

The Client User has limited, read-oriented access. They can view compliance records, complete assigned training courses, and submit DSRs. This role is appropriate for general staff members who need awareness of the organisation's compliance activities without the ability to modify records.

When onboarding a new client, the primary contact is automatically assigned the CLIENT_ADMIN role. They can then invite additional users and assign roles as needed.

Assigning a DPO to Client Organisations

As a RESELLER_ADMIN, you have the ability to assign a Data Protection Officer (DPO) to any client organisation in your portfolio. This is particularly valuable for clients who do not have an in-house DPO and rely on your team to fulfil that function.

How DPO Assignment Works

Navigate to the client's detail page and select "Assign DPO". You can assign any user with the DPO role — including external DPOs from your own team. The assigned DPO gains access to the client's compliance dashboard with elevated permissions, including the ability to approve DPIAs and documents, update breach notification status, and manage DSR assignments.

A single DPO can be assigned to multiple client organisations. When a DPO signs in, they can switch between their assigned tenants using the Tenant Switcher in the sidebar, giving them a seamless workflow across all their responsibilities.

External DPO Designation

When assigning a DPO, you can mark the assignment as "external". This flag is recorded for audit purposes and reflects the fact that the DPO is not an employee of the client organisation — an important distinction under GDPR Article 37.

Supporting Your Clients

Ongoing support is what differentiates a great reseller partner from a simple software subscription. GDPR4All gives you the tools to provide proactive, informed support.

Accessing Client Compliance Data

From your reseller dashboard, you can view any client's compliance records in read-only mode. This means you can review their ROPA register, check the status of breach incidents, audit their consent records, and verify that DPIAs are progressing through the approval workflow — all without needing to ask the client to share screenshots or export data.

Audit Logs

Every significant action within a client workspace is recorded in the audit log, including record creation, status changes, approvals, and deletions. As a reseller, you can review these logs to understand what has changed and when, which is invaluable during compliance reviews or when investigating issues raised by a client.

Document Generation Support

You can guide clients through the document generation process, helping them produce privacy policies, breach notifications, DPIA reports, and vendor DPAs. The platform's template engine pre-populates documents with data from the client's compliance records, reducing manual effort and ensuring consistency.

Tips for Effective Client Management

Drawing on the experience of our most successful reseller partners, here are practical recommendations for managing your client portfolio effectively.

  • Schedule regular check-ins. Monthly or quarterly compliance review meetings keep clients engaged and demonstrate the ongoing value of your services. Use the dashboard's compliance scores and trend data to structure these conversations.

  • Use compliance scores to identify at-risk clients. A declining compliance score is an early warning sign. Reach out proactively to clients whose scores drop, and offer targeted support to address specific gaps — whether that is completing overdue ROPA entries or responding to pending DSRs.

  • Standardise your onboarding process. Create a repeatable onboarding checklist that covers workspace setup, initial data entry, role assignment, and training course allocation. A consistent onboarding experience reduces support requests and accelerates time to value.

  • Leverage the Training Academy. Assign GDPR awareness courses to client teams during onboarding. Well-trained staff generate fewer compliance incidents and require less day-to-day support, freeing your time to focus on higher-value advisory work.

  • Document everything. Encourage clients to use the Document Generator for all formal compliance documentation. Having documents generated from live compliance data — rather than created ad hoc in word processors — ensures accuracy and creates a clear audit trail.

By combining the platform's tools with a proactive support approach, you can build lasting relationships with your clients and grow your reseller business sustainably.

Related Articles

Was this article helpful?