
DPO review
GDPR Article 35(2) requires controllers to seek the advice of the DPO when carrying out a DPIA. TruePrivacy builds this in as a mandatory workflow step:- The completed assessment routes to the DPO with the full risk matrix, mitigations, and residual scores.
- The DPO records a structured opinion — concur, concur with conditions, or object.
- If the DPO’s opinion differs from the project team’s assessment, the divergence is documented in the DPIA record, as GDPR expects.
The DPO advises; the controller decides. TruePrivacy records both the DPO’s opinion and the controller’s final decision separately, so the accountability chain is explicit.
The approval workflow
Submit for review
The assessment owner submits the completed DPIA. Incomplete sections and unscored risks block submission.
Stakeholder sign-offs
Configurable reviewers — IT security, legal, the business owner — sign off on their sections. Each sign-off is timestamped and attributed.
DPO consultation
The DPO reviews and records their opinion. Change requests send the assessment back to the owner with comments attached to specific sections.
Revisiting assessments when processing changes
A DPIA reflects the processing as assessed — when the processing changes, the assessment must too.| Trigger | What happens |
|---|---|
| Data map change | New data categories, systems, or recipients on the linked processing activity flag the DPIA for review |
| AI system change | A linked AI system starts receiving new data categories or changes purpose |
| New risk findings | DSPM findings on stores holding the assessed data raise the activity’s risk profile |
| Scheduled review | Periodic re-review on a cadence you set (annually is a common baseline) |
| Regulatory change | Updated EDPB or DPA guidance prompts re-screening of affected assessments |
Audit trail and export
Every event in the DPIA lifecycle is recorded — screening determination, section edits, sign-offs, DPO opinion, final decision, reopenings, and mitigation completions — each with actor and timestamp.- PDF export — the full assessment: processing description, risk matrix, mitigations, DPO opinion, and approvals, formatted for auditors and regulators.
- Version history — export any prior approved version to show what applied at a given point in time.
- Risk register view — open risks across all DPIAs, exportable for board and audit reporting.