A Data Protection Impact Assessment is how you demonstrate — before processing begins — that you understood the risks to individuals and dealt with them. TruePrivacy turns the assessment from a blank document into a guided, pre-filled workflow.
DPIA assessment workspace with screening, risk matrix, and mitigations

When is a DPIA required?

Under GDPR Article 35, a DPIA is mandatory whenever processing is likely to result in a high risk to individuals — in particular:
  • Systematic and extensive automated decision-making with legal or similarly significant effects (credit decisions, hiring, insurance pricing)
  • Large-scale processing of special category data (health, biometric, racial or ethnic origin, religious beliefs) or criminal-offense data
  • Systematic monitoring of publicly accessible areas on a large scale
The EDPB adds further indicators — evaluation or scoring, matching or combining datasets, data on vulnerable subjects, innovative technology, and processing that prevents individuals from exercising rights. National DPAs publish their own mandatory lists on top. India’s DPDP Act imposes comparable assessment duties on Significant Data Fiduciaries.
When two or more indicators apply, most DPAs expect a DPIA. When in doubt, screen — the screening record itself is evidence of a working accountability process.

Screening questions

Every new processing activity in your data map is evaluated automatically against EDPB criteria and your national DPA’s lists. You can also screen manually:
1

Answer the screening questionnaire

Short, plain-language questions about the processing — scale, data categories, subjects, technology, and effects. Most answers pre-fill from the data map.
2

Get a determination

TruePrivacy records one of three outcomes: DPIA required, DPIA recommended, or not required — with the rationale mapped to the criteria that fired.
3

A task is created

If required, a DPIA task is assigned to the responsible team. Activities already running without a completed DPIA are flagged as gaps with a remediation task.

The assessment flow

Assessments are template-driven: start from the standard EDPB-aligned template, a template from your DPA, or one created from a previous assessment for similar processing (shared sections pre-fill; reviewers confirm each is still accurate for the new context).
1

Describe the processing

Nature, scope, context, and purposes. Data categories, systems, retention, and third parties pre-fill from the data map — you focus on analysis, not data gathering.
2

Assess necessity and proportionality

Document the legal basis, why the processing is necessary for the purpose, and why less intrusive alternatives are insufficient.
3

Identify risks to individuals

Enumerate risks — unauthorized access, discrimination, loss of control, re-identification — from the perspective of the data subject, not the business.
4

Score each risk

Rate likelihood and severity on the risk matrix (below). The overall assessment score updates live as risks are added and scored.
5

Define mitigations

Attach mitigation measures to each risk, with owners and deadlines. Residual risk is re-scored assuming mitigations are in place.

The risk scoring matrix

Minimal severitySignificantSevereMaximum
Highly likelyMediumHighCriticalCritical
LikelyLowMediumHighCritical
PossibleLowMediumHighHigh
UnlikelyLowLowMediumHigh
The matrix dimensions and thresholds are configurable to match your organization’s risk methodology. Each risk stores both an inherent score (before mitigation) and a residual score (after), and the DPIA’s overall score recalculates automatically as mitigations complete.

Mitigations

  • Mitigations are tracked tasks — owner, deadline, status, evidence attachments — not bullet points in a document.
  • Completed mitigations lower the residual score; overdue ones escalate to the assessment owner.
  • Risks and mitigations feed the organizational privacy risk register, alongside vendor risk and AI governance findings.
If residual risk remains high after all reasonable mitigations, GDPR Article 36 requires prior consultation with your DPA before processing begins. TruePrivacy flags this outcome automatically and generates the submission package — see Review & Approvals.
Assign sections to different stakeholders — IT security for technical risk, legal for legal basis, the business owner for purpose and necessity. Each contributor works independently and progress is visible to all.