A DPIA is not finished when the last section is written — it is finished when the DPO has reviewed it, the decision is recorded, and the assessment stays alive as the processing evolves.
DPIA approval workflow with DPO review and sign-off status

DPO review

GDPR Article 35(2) requires controllers to seek the advice of the DPO when carrying out a DPIA. TruePrivacy builds this in as a mandatory workflow step:
  • The completed assessment routes to the DPO with the full risk matrix, mitigations, and residual scores.
  • The DPO records a structured opinion — concur, concur with conditions, or object.
  • If the DPO’s opinion differs from the project team’s assessment, the divergence is documented in the DPIA record, as GDPR expects.
The DPO advises; the controller decides. TruePrivacy records both the DPO’s opinion and the controller’s final decision separately, so the accountability chain is explicit.

The approval workflow

1

Submit for review

The assessment owner submits the completed DPIA. Incomplete sections and unscored risks block submission.
2

Stakeholder sign-offs

Configurable reviewers — IT security, legal, the business owner — sign off on their sections. Each sign-off is timestamped and attributed.
3

DPO consultation

The DPO reviews and records their opinion. Change requests send the assessment back to the owner with comments attached to specific sections.
4

Final approval

The accountable approver records the decision: approved, approved with conditions (conditions become tracked tasks), or rejected. Approved DPIAs are locked as a versioned record.
If the assessment concludes that residual risk remains high despite mitigations, approval is blocked and the DPA prior consultation path opens instead. TruePrivacy generates a consultation submission package pre-formatted to your national authority’s requirements.

Revisiting assessments when processing changes

A DPIA reflects the processing as assessed — when the processing changes, the assessment must too.
TriggerWhat happens
Data map changeNew data categories, systems, or recipients on the linked processing activity flag the DPIA for review
AI system changeA linked AI system starts receiving new data categories or changes purpose
New risk findingsDSPM findings on stores holding the assessed data raise the activity’s risk profile
Scheduled reviewPeriodic re-review on a cadence you set (annually is a common baseline)
Regulatory changeUpdated EDPB or DPA guidance prompts re-screening of affected assessments
A flagged DPIA reopens as a new version: the previous approved version remains intact, and reviewers see exactly what changed since it was signed off.

Audit trail and export

Every event in the DPIA lifecycle is recorded — screening determination, section edits, sign-offs, DPO opinion, final decision, reopenings, and mitigation completions — each with actor and timestamp.
  • PDF export — the full assessment: processing description, risk matrix, mitigations, DPO opinion, and approvals, formatted for auditors and regulators.
  • Version history — export any prior approved version to show what applied at a given point in time.
  • Risk register view — open risks across all DPIAs, exportable for board and audit reporting.
Regulators asking “show me your DPIA” almost always follow with “show me it was reviewed and kept current.” The version history and approval trail answer the second question before it is asked.