DPIA
GDPR Data Protection Impact Assessment (DPIA) Checklist
A step-by-step DPIA checklist: screening, necessity, risks to rights, mitigations, and DPO/consultations.
- Estimated time
- 2–8 Weeks per DPIA
- Audience
- Privacy, Security, and Product Teams Launching High-Risk Processing
- Last updated
Operational reference for DPIA practice under GDPR Articles 35–36. High-risk processing may require supervisory prior consultation.
Progress is saved in this browser only. Nothing is sent to a server.
Phase 1: Screening
Phase 2: Description & Necessity
Phase 3: Risks & Mitigations
Phase 4: Consultation & Review
FAQ
Is a DPIA always required?+–
Only when processing is likely to result in a high risk to rights. Screening records still matter.
Who signs it off?+–
The controller. The DPO advises. Processors may assist with facts.
Does ISO 27701 replace DPIAs?+–
No. DPIA is a GDPR process. A PIMS can host the records.
What if residual risk stays high?+–
Consider not proceeding, further mitigation, or Article 36 prior consultation.
Related field notes
The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer