All templates
Internal Registers & TrackersSection 10
DPIA (Data Protection Impact Assessment) Template
A structured assessment template for evaluating privacy risk before launching a new or higher-risk processing activity.
Template
DATA PROTECTION IMPACT ASSESSMENT (DPIA) Organization: [Organization Name] Assessment ID: [DPIA-YYYY-NN] Processing Activity Assessed: [Name of project / feature / system] Prepared By: [Name, Role] Reviewed By: [DPO Name] Date: [DD-MM-YYYY] 1. PURPOSE AND TRIGGER A DPIA is a documented assessment of the necessity, proportionality, and risk of a processing activity before it goes live. Section 10 requires a Significant Data Fiduciary to conduct a DPIA; as good practice, [Organization Name] applies this template to any activity involving large-scale processing, sensitive data categories, children's data, or new automated decision-making, regardless of SDF status. 2. DESCRIPTION OF PROCESSING Purpose of Processing: [Describe the business purpose in plain language] Categories of Personal Data: [List, e.g. name, location, biometric data, financial data] Categories of Data Principals: [e.g. customers, employees, minors] Volume / Scale: [Approx. number of Data Principals affected] Data Flow Summary: [How data is collected, where it is stored, who accesses it, whether it is shared with processors or transferred cross-border] 3. LAWFUL BASIS Basis Relied Upon: [Consent under Section 6 / Legitimate use under Section 7 - specify sub-clause] Notice Given: [Reference to the notice under Section 5 provided to Data Principals] Children's Data Involved: [Y/N - if Y, describe verifiable parental consent mechanism under Section 9] 4. NECESSITY AND PROPORTIONALITY Is the data collected the minimum required for the stated purpose? [Yes/No - explain] Could the purpose be achieved with less data or a less intrusive method? [Explain] Is the retention period justified and documented in the Retention Schedule? [Reference] 5. RISK ASSESSMENT Column headers: Risk Description | Likelihood (Low/Med/High) | Impact on Data Principal (Low/Med/High) | Existing Safeguard | Residual Risk | Mitigation / Action Owner Example Row 1: Risk Description: Re-identification of users from anonymized location data Likelihood: Medium Impact: High Existing Safeguard: Geohash truncation, no raw coordinates stored Residual Risk: Low Mitigation / Action Owner: Quarterly re-identification risk review, [Data Science Lead] Example Row 2: Risk Description: Excessive access to sensitive health data by internal staff Likelihood: Medium Impact: High Existing Safeguard: Role-based access, need-to-know restriction Residual Risk: Medium Mitigation / Action Owner: Implement access request approval workflow, [Security Lead], due [DD-MM-YYYY] 6. AUTOMATED DECISION-MAKING (IF APPLICABLE) Does the activity involve algorithmic scoring, ranking, or automated eligibility decisions affecting Data Principals? [Yes/No] If yes, describe the algorithmic due-diligence performed, human review checkpoints, and how a Data Principal can seek grievance redressal under Section 13. 7. CROSS-BORDER TRANSFER (IF APPLICABLE) Countries Involved: [List] Confirm no government restriction under Section 16 applies to the listed destination(s): [Confirmed / Under review] 8. OVERALL DETERMINATION Overall Risk Rating: [Low / Medium / High] Conditions for Go-Live: [List any mitigations that must be completed before launch] Sign-off: [DPO Name and signature] Date: [DD-MM-YYYY] Next Review Date: [DD-MM-YYYY, or annually per SDF obligations]
This template is a starting point, not legal advice. Have it reviewed by qualified counsel before use, and adapt bracketed placeholders to your organization's facts.