DPDP NavigatorAct 2023 · Rules 2025
All templates
Board & GovernanceSection 10

Annual DPIA Summary Report Template

A consolidated annual report summarizing all DPIAs conducted during the year, prepared for Board and audit review.

Template
ANNUAL DPIA SUMMARY REPORT

Organization: [Organization Name]
Reporting Year: [FYXX / Calendar Year]
Prepared By: [DPO Name]
Reviewed By: [Data Protection Committee / Board]
Date: [DD-MM-YYYY]

1. PURPOSE OF THIS REPORT

This report consolidates all Data Protection Impact Assessments ("DPIAs") conducted by [Organization Name] during the reporting year, in support of the obligation under Section 10 of the Digital Personal Data Protection Act, 2023 for a Significant Data Fiduciary to undertake a periodic DPIA, and to provide the Board with a consolidated view of privacy risk across the organization's processing activities.

2. SCOPE OF ASSESSMENTS UNDERTAKEN

Total DPIAs Conducted This Year: [_]
Trigger for Each Assessment: [New product launch / Material change to existing processing / Introduction of automated decision-making / Routine annual review]

3. SUMMARY TABLE

Column headers: DPIA ID | Activity Assessed | Date Completed | Overall Risk Rating (Pre-Mitigation) | Overall Risk Rating (Post-Mitigation) | Key Mitigations Applied | Status

Example Row 1:
DPIA ID: DPIA-2026-01
Activity Assessed: Launch of personalized recommendation engine
Date Completed: [DD-MM-YYYY]
Overall Risk Rating (Pre-Mitigation): High
Overall Risk Rating (Post-Mitigation): Medium
Key Mitigations Applied: Data minimization on behavioral inputs, opt-out mechanism, human review of edge-case recommendations
Status: Live with monitoring

Example Row 2:
DPIA ID: DPIA-2026-02
Activity Assessed: Employee productivity monitoring tool
Date Completed: [DD-MM-YYYY]
Overall Risk Rating (Pre-Mitigation): Medium
Overall Risk Rating (Post-Mitigation): Low
Key Mitigations Applied: Restricted metrics to aggregate, defined access controls, employee notice issued
Status: Live with monitoring

4. CHILDREN'S DATA PROCESSING (IF APPLICABLE)

Activities Involving Children's Data This Year: [_]
Verifiable Parental Consent Mechanism Used: [Describe, per Section 9]
Confirmation of No Behavioural Monitoring or Targeted Advertising to Children: [Confirmed / Exception noted and remediated]

5. ALGORITHMIC AND AUTOMATED DECISION-MAKING DUE DILIGENCE

Systems Reviewed: [List]
Due-Diligence Performed: [Bias testing, explainability review, human-in-the-loop checkpoints]
Outstanding Concerns: [None / Describe, with remediation owner and date]

6. CROSS-BORDER TRANSFER REVIEW

Countries to Which Personal Data Was Transferred This Year: [List]
Confirmation Against Government Restrictions Under Section 16: [Confirmed as of DD-MM-YYYY]

7. OVERALL TREND AND OBSERVATIONS

[Narrative summary - e.g. "Residual risk across assessed activities trended downward this year following the introduction of a mandatory pre-launch DPIA gate. Two activities remain under enhanced monitoring."]

8. RECOMMENDATIONS FOR NEXT YEAR

- [Recommendation 1]
- [Recommendation 2]
- [Recommendation 3]

9. INDEPENDENT AUDIT CROSS-REFERENCE

This report is intended to be read alongside the independent auditor's report for the year, where applicable to [Organization Name] as a Significant Data Fiduciary, available at [reference / location].

Prepared and submitted by:
[DPO Name]
[Designation]
Date: [DD-MM-YYYY]

This template is a starting point, not legal advice. Have it reviewed by qualified counsel before use, and adapt bracketed placeholders to your organization's facts.