Privacy & Data Protection

Data Protection Impact Assessment Procedure

A DPIA procedure template providing a step-by-step methodology for assessing privacy risks in new projects and processing activities.

14-18 pages|Updated 2026-02-15|2 frameworks
Aligned to:
GDPR
ISO 27701

What's Included

1. Purpose & Scope

Defines when a DPIA is required and who is responsible.

2. Screening Criteria

Establishes criteria for determining whether a DPIA is needed.

3. Assessment Methodology

Outlines the step-by-step DPIA process.

4. Risk Identification

Defines how to identify privacy risks in processing activities.

5. Risk Mitigation

Specifies how identified risks should be mitigated.

6. Consultation

Outlines requirements for consulting the DPO and supervisory authority.

7. Documentation & Review

Sets documentation standards and review frequency.

Frequently Asked Questions

What should a data protection impact assessment procedure include?

A comprehensive data protection impact assessment procedure should include purpose & scope, screening criteria, assessment methodology, risk identification, and more. This template covers 7 key sections aligned to GDPR, ISO 27701 requirements.

Which frameworks require a privacy & data protection policy?

Major frameworks requiring privacy & data protection policies include GDPR, ISO 27701. This template maps directly to their control requirements, making it easier to demonstrate compliance across multiple standards.

How often should a data protection impact assessment procedure be reviewed?

Best practice is to review your data protection impact assessment procedure at least annually, or whenever significant changes occur in your organisation, technology environment, or regulatory landscape. Most frameworks including ISO 27001 and NIST CSF require documented policy review cycles.

Build Your Compliance Programme

Pair this policy template with our compliance platform to map controls across 693+ frameworks, run self-assessments, and get AI-powered compliance advisory.

Get Started Free →

Free forever — no credit card required