Data Protection Impact Assessment Procedure
A DPIA procedure template providing a step-by-step methodology for assessing privacy risks in new projects and processing activities.
What's Included
1. Purpose & Scope
Defines when a DPIA is required and who is responsible.
2. Screening Criteria
Establishes criteria for determining whether a DPIA is needed.
3. Assessment Methodology
Outlines the step-by-step DPIA process.
4. Risk Identification
Defines how to identify privacy risks in processing activities.
5. Risk Mitigation
Specifies how identified risks should be mitigated.
6. Consultation
Outlines requirements for consulting the DPO and supervisory authority.
7. Documentation & Review
Sets documentation standards and review frequency.
Frequently Asked Questions
What should a data protection impact assessment procedure include?
A comprehensive data protection impact assessment procedure should include purpose & scope, screening criteria, assessment methodology, risk identification, and more. This template covers 7 key sections aligned to GDPR, ISO 27701 requirements.
Which frameworks require a privacy & data protection policy?
Major frameworks requiring privacy & data protection policies include GDPR, ISO 27701. This template maps directly to their control requirements, making it easier to demonstrate compliance across multiple standards.
How often should a data protection impact assessment procedure be reviewed?
Best practice is to review your data protection impact assessment procedure at least annually, or whenever significant changes occur in your organisation, technology environment, or regulatory landscape. Most frameworks including ISO 27001 and NIST CSF require documented policy review cycles.
Related Templates
Data Protection Policy
A data protection and privacy policy template addressing GDPR, CCPA, and Privacy Act requirements for collecting, processing, storing, and deleting personal data.
Privacy Notice Template
A public-facing privacy notice template explaining how personal data is collected, used, and protected, compliant with GDPR and CCPA transparency requirements.
Data Retention & Disposal Policy
A data retention and disposal policy template defining retention schedules, archival procedures, and secure destruction methods for all data types.
Build Your Compliance Programme
Pair this policy template with our compliance platform to map controls across 693+ frameworks, run self-assessments, and get AI-powered compliance advisory.
Get Started Free →Free forever — no credit card required