
In this section
Conducting Assessments
When a DPIA is required under GDPR Article 35, screening questions, the assessment flow, risk scoring, and mitigations.
Review & Approvals
DPO review, the approval workflow, revisiting assessments when processing changes, and the audit trail.
Automated triggering
Processing activities in your data map are automatically evaluated against EDPB high-risk criteria and your national DPA’s published lists of processing requiring DPIAs — systematic automated decision-making, large-scale special-category processing, systematic monitoring of public areas, and more. Required assessments are created as tasks before processing begins. Activities already running without a DPIA are flagged as gaps with a remediation task.The assessment framework
Each DPIA follows a structured framework:Necessity and proportionality
Document the purpose, legal basis, and why the processing is necessary and proportionate. TruePrivacy pre-fills data categories, systems, and third parties from your data map.
Risk identification and scoring
Identify risks to data subjects and score each by likelihood and severity on a configurable risk matrix. The overall risk score updates as the assessment evolves.
Mitigation measures
Record mitigations as tracked tasks with owners and deadlines. The DPIA risk score recalculates automatically as mitigations complete.
Templates and reuse
Create a DPIA template from a completed assessment and reuse it for similar processing activities. Shared sections are pre-filled, and reviewers are prompted to confirm each section is still accurate for the new context.Collaboration and the risk register
- Assign sections to different stakeholders — IT security for technical risk, legal for legal basis, DPO for overall review — with independent progress tracking.
- Identified risks and mitigations feed automatically into your organizational privacy risk register, alongside vendor risk and AI governance findings.