The Business Case for DPDP Act Compliance

Read Now

Get privacy insights in your inbox.

Best Practices

The DPO's Operating System: How the IQWorks Suite Fits Together

Maulik BengaliOctober 6, 20265 min read
Share
The DPO's Operating System: How the IQWorks Suite Fits Together

The IQWorks suite runs on one organization, one login, and one data spine rather than six disconnected tools. A single Auth0 tenant issues one JWT across every product, and Row Level Security enforces org isolation on every query. The apps share a common data and component layer, so a notice published in ComplyIQ underpins the consent page ConsentIQ serves, a data subject request in ComplyIQ can deep-link a targeted DiscoverIQ scan, and ConsultIQ's AI advisor reads the same live compliance data ComplyIQ manages.

Source: IQWorks Research | Last updated: July 2026

A DPO running a privacy program typically ends up running a small IT estate of their own: a notice builder, a consent banner vendor, a discovery scanner, a spreadsheet for data subject requests, and now an AI assistant that knows nothing about any of it. Each tool has its own login, its own copy of the data principal's record, and its own idea of what "the org" contains. Keeping them in sync becomes a second job.

IQWorks was built to avoid that outcome by design, not by integration project. ComplyIQ, ConsentIQ, DiscoverIQ, ClassifyIQ, ConsultIQ, and ChatIQ are separate products with separate jobs, but they sit on one identity layer and one data layer underneath. The rest of this piece is about what that actually means in the product, not as an architecture diagram.

One org, one login

Every product in the suite authenticates against the same Auth0 tenant. A user signs in once, and the JWT that comes back carries the organization ID and role claims that every app reads. There is no separate account to provision in ConsentIQ after a user already exists in ComplyIQ, and no second password to rotate.

The same JWT also carries the role — Super Admin, Admin, Team Member, or Viewer — and that role means the same thing everywhere. An Admin who can approve a DPIA in ComplyIQ has the equivalent write access in ConsentIQ; a Viewer who can read incidents in ComplyIQ is read-only in DiscoverIQ too. A product switcher lets a user move between the products their org has licensed without a fresh login, because the session already establishes who they are and which org they belong to.

One data spine underneath

Underneath the login sits Row Level Security: every query is scoped to the organization ID in the JWT, enforced at the database, not just checked in application code. That is what keeps one customer's data activities, consent records, and incidents invisible to another customer, regardless of which product is asking.

The products also share a common code layer rather than each reimplementing the same concepts. Data subject request handling, consent records, the data inventory model, and the read tools that power AI features all live in one shared package that every app imports. A "data activity" is the same entity whether it was created in ComplyIQ's inventory or read by ConsultIQ's advisor — not a lookalike record that has to be reconciled later.

Where the products actually meet

The shared spine shows up as concrete wiring between products, not just a shared login screen.

A privacy notice built and published in ComplyIQ's Notices module is the basis for the live consent page ConsentIQ serves to the data principal — the purposes and data items in the notice reach the person as a consent capture point, rather than as a second document someone has to keep in sync by hand.

When a data subject request comes into ComplyIQ, the DSR workflow can deep-link a DiscoverIQ scan pre-filled with the requester's identifiers — email, name — so whoever is fulfilling the request starts a targeted scan instead of retyping the same search terms into a separate discovery tool. DiscoverIQ's scan results, in turn, are what ClassifyIQ applies its labeling rules against, turning detected attributes into policy-driven classification levels.

ConsultIQ, the AI compliance advisor, reads that same live data. Its org-scoped read tools query the data activities, assessments, and incidents ComplyIQ manages, so its chat answers and its drafts inside Word, Excel, and PowerPoint are grounded in the organization's actual compliance record rather than a generic knowledge base. ConsultIQ also has knowledgebase search built in; ChatIQ, the suite's embeddable chat widget, does not — the two serve different jobs, and neither is described as doing the other's.

ProductWhat it does
ComplyIQCompliance operations: the data inventory (RoPA), privacy notices, the full DSR lifecycle, incidents, assessments, DPIA, and vendors.
ConsentIQConsent capture and proof: hosted consent pages, cryptographically signed consent records, and DPO console search.
DiscoverIQData discovery: scans an org's data sources and catalogs where personal data lives.
ClassifyIQClassification: applies rule-driven labels to the attributes DiscoverIQ detects.
ConsultIQAI compliance advisor: reads the org's live compliance data, drafts inside Office, and includes knowledgebase search.
ChatIQEmbeddable AI chat widget for an org's own applications.

Why the operating system matters more than any one feature

None of these products needs the others to function. ComplyIQ runs a compliance program on its own; ConsentIQ runs a consent program on its own. The difference the shared spine makes shows up in what a DPO does not have to do: re-enter the same principal, re-explain the same notice, or re-export a scan result to hand to another tool. The record created in one product is the record the next product reads.

That is also what keeps the suite auditable as a whole. Because access is enforced by the same JWT and Row Level Security everywhere, an auditor reviewing who could see what does not need a separate answer per product — the answer is the same organization boundary, checked the same way, on every query.

Key Takeaways

  • A single Auth0 tenant issues one JWT across ComplyIQ, ConsentIQ, DiscoverIQ, ClassifyIQ, ConsultIQ, and ChatIQ; roles carry the same meaning in every product.
  • Row Level Security enforces organization isolation at the database on every query, not just in application code.
  • The products share a common data and component layer for DSR handling, consent records, and the data inventory, rather than each maintaining its own copy.
  • A notice published in ComplyIQ underpins the live consent page ConsentIQ serves to the data principal.
  • A DSR opened in ComplyIQ can deep-link a DiscoverIQ scan pre-filled with the requester's identifiers.
  • ConsultIQ's AI advisor reads the same org-scoped compliance data ComplyIQ manages and includes knowledgebase search; ChatIQ, the embedded chat widget, does not.

The suite runs on one Auth0 tenant, one JWT, and Row Level Security enforcing organization isolation on every product, every query. See the suite fit together in your own environment: book a demo.

Our verdict

ComplyIQ4.8out of 5

29 ratings, from Customer Success Research.

Maulik Bengali

Written by

Maulik Bengali

Founder and Chief Executive Officer

Sixteen years building software for Fortune 500 clients and unicorn startups across Europe and the United States, where GDPR, HIPAA and sector rules repeatedly decided whether a product could ship at all. Founder and CEO of IQWorks, hands-on in the platform every day across data discovery, classification and the AIQ detection engine.

Ready to automate your compliance?

See how IQWorks helps enterprises manage data protection at scale.

Request Demo

Related Articles