DPDP NavigatorAct 2023 · Rules 2025
All templates
Internal Registers & TrackersSection 10

DPIA (Data Protection Impact Assessment) Template

A structured assessment template for evaluating privacy risk before launching a new or higher-risk processing activity.

Template
DATA PROTECTION IMPACT ASSESSMENT (DPIA)

Organization: [Organization Name]
Assessment ID: [DPIA-YYYY-NN]
Processing Activity Assessed: [Name of project / feature / system]
Prepared By: [Name, Role]
Reviewed By: [DPO Name]
Date: [DD-MM-YYYY]

1. PURPOSE AND TRIGGER

A DPIA is a documented assessment of the necessity, proportionality, and risk of a processing activity before it goes live. Section 10 requires a Significant Data Fiduciary to conduct a DPIA; as good practice, [Organization Name] applies this template to any activity involving large-scale processing, sensitive data categories, children's data, or new automated decision-making, regardless of SDF status.

2. DESCRIPTION OF PROCESSING

Purpose of Processing: [Describe the business purpose in plain language]
Categories of Personal Data: [List, e.g. name, location, biometric data, financial data]
Categories of Data Principals: [e.g. customers, employees, minors]
Volume / Scale: [Approx. number of Data Principals affected]
Data Flow Summary: [How data is collected, where it is stored, who accesses it, whether it is shared with processors or transferred cross-border]

3. LAWFUL BASIS

Basis Relied Upon: [Consent under Section 6 / Legitimate use under Section 7 - specify sub-clause]
Notice Given: [Reference to the notice under Section 5 provided to Data Principals]
Children's Data Involved: [Y/N - if Y, describe verifiable parental consent mechanism under Section 9]

4. NECESSITY AND PROPORTIONALITY

Is the data collected the minimum required for the stated purpose? [Yes/No - explain]
Could the purpose be achieved with less data or a less intrusive method? [Explain]
Is the retention period justified and documented in the Retention Schedule? [Reference]

5. RISK ASSESSMENT

Column headers: Risk Description | Likelihood (Low/Med/High) | Impact on Data Principal (Low/Med/High) | Existing Safeguard | Residual Risk | Mitigation / Action Owner

Example Row 1:
Risk Description: Re-identification of users from anonymized location data
Likelihood: Medium
Impact: High
Existing Safeguard: Geohash truncation, no raw coordinates stored
Residual Risk: Low
Mitigation / Action Owner: Quarterly re-identification risk review, [Data Science Lead]

Example Row 2:
Risk Description: Excessive access to sensitive health data by internal staff
Likelihood: Medium
Impact: High
Existing Safeguard: Role-based access, need-to-know restriction
Residual Risk: Medium
Mitigation / Action Owner: Implement access request approval workflow, [Security Lead], due [DD-MM-YYYY]

6. AUTOMATED DECISION-MAKING (IF APPLICABLE)

Does the activity involve algorithmic scoring, ranking, or automated eligibility decisions affecting Data Principals? [Yes/No]
If yes, describe the algorithmic due-diligence performed, human review checkpoints, and how a Data Principal can seek grievance redressal under Section 13.

7. CROSS-BORDER TRANSFER (IF APPLICABLE)

Countries Involved: [List]
Confirm no government restriction under Section 16 applies to the listed destination(s): [Confirmed / Under review]

8. OVERALL DETERMINATION

Overall Risk Rating: [Low / Medium / High]
Conditions for Go-Live: [List any mitigations that must be completed before launch]
Sign-off: [DPO Name and signature] Date: [DD-MM-YYYY]
Next Review Date: [DD-MM-YYYY, or annually per SDF obligations]

This template is a starting point, not legal advice. Have it reviewed by qualified counsel before use, and adapt bracketed placeholders to your organization's facts.