
Dynamic PRA™ · known as a DPA under some states' statutes
The assessment your state statute happens to call something else.
Virginia-model statutes call this document a "data protection assessment." California's statute calls the same kind of document a "risk assessment." Different statutes, different word — one document class, produced state by state on the Dynamic PRA™ factory.
The naming, not the duty, is what varies
One assessment, named per statute.
Nothing in the corpus gives a state two separate assessment duties under two separate names. What changes state to state is the statute's own word for the document, not the document itself — so we build it once, per state, and title it the way that state's law does.
Same factory, every state
Whether your state's statute says "data protection assessment" or "risk assessment," the document comes off the same per-state assessment pipeline as the Dynamic PRA™ — built from that state's own provisions, not a template with the state name swapped in.
The title follows the statute
The document is titled with the term your state's law actually uses, sourced to that statute — never a generic label standing in for it.
One purchase per state
You are not buying a PRA and a DPA for the same state. One state, one document, one price — see the Dynamic PRA™ page for the full per-state duty map.
We bring the regulatory intelligence and the intake. You bring the privacy and legal judgment for your use case and organization. The document is built to hold both.
The division of labour, stated onceWhat arrives
Built from the statute you are actually subject to.
The same discipline as everything else here: the scaffold is assembled from provisions that were opened, pinned and verified, and nothing is filled in that the corpus cannot support.
The processing, described against that statute's vocabulary
Statutes differ on what they call the actors and the activity. A document using the wrong vocabulary reads as though it was written for somewhere else, because it was.
The safeguards the provision expects
Each tied to the section that expects it, so a reviewer can go from the control to the requirement in one step.
The heightened-risk analysis
Structured, with the categories that statute recognises — not a generic risk register relabelled.
Retention, as a number
How long to keep it, from the provision that says so. Not a reasonable period.
What this is not. LegisGate produces regulatory intelligence and assessment-preparation materials. Nothing we produce is legal advice, a legal opinion, a certification, or a determination of compliance, and no document we deliver satisfies a legal obligation on its own. Sufficiency is determined by your counsel.

One determination, one document per state
Find the states, then buy the document once for each.
Run the determination to establish which states your deployment actually reaches, then buy the per-state assessment for each one — whatever your state's statute calls it.