Skip to content

DPIA

GDPR Data Protection Impact Assessment (DPIA) Checklist

A step-by-step DPIA checklist: screening, necessity, risks to rights, mitigations, and DPO/consultations.

Estimated time
2–8 Weeks per DPIA
Audience
Privacy, Security, and Product Teams Launching High-Risk Processing
Last updated

Operational reference for DPIA practice under GDPR Articles 35–36. High-risk processing may require supervisory prior consultation.

Progress0% Completed

Progress is saved in this browser only. Nothing is sent to a server.

Phase 1: Screening

Phase 2: Description & Necessity

Phase 3: Risks & Mitigations

Phase 4: Consultation & Review

FAQ

Is a DPIA always required?+

Only when processing is likely to result in a high risk to rights. Screening records still matter.

Who signs it off?+

The controller. The DPO advises. Processors may assist with facts.

Does ISO 27701 replace DPIAs?+

No. DPIA is a GDPR process. A PIMS can host the records.

What if residual risk stays high?+

Consider not proceeding, further mitigation, or Article 36 prior consultation.

Related field notes

The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer