Get started

Compliance Tools

A Data Protection Impact Assessment is required by GDPR Article 35 whenever your data processing is "likely to result in a high risk to the rights and freedoms of natural persons." If you're using AI to process personal data, you almost certainly need one. A completed DPIA becomes part of the evidence your auditors will actually see, not a document that sits in a drawer.

The 6 sections

#SectionWhat you fill in
1Processing DescriptionWhat data you process, why, the legal basis, who receives it, how long you keep it
2Necessity & ProportionalityWhy this processing is necessary and proportionate to its purpose
3Risk AssessmentWhat could go wrong for the people whose data you process
4Mitigation MeasuresWhat you're doing to reduce those risks
5ConsultationWhether you've consulted your DPO and/or the affected individuals
6OutcomeThe overall risk level and your decision (proceed, proceed with conditions, or stop)

How to use

Navigate to Compliance Command Center → Privacy Impact tab.

Auto-population

If you have the asset registry configured (REG stream), several fields are auto-populated:

  • Controller name from your organisation settings
  • Data categories from your registered AI systems
  • International transfers detected from your AI model providers (Anthropic = US, Google = global, OpenAI = US)

Risk matrix

In the Risk Assessment section, add risks and score each on:

  • Likelihood (1-5) — how likely is this to happen?
  • Severity (1-5) — how bad is it if it does?

The interactive 5×5 matrix visualises your risks as dots. Scores are colour-coded on a gradient:

ScoreColour
below 4Green
4-8Amber
9-15Orange
16 or higherRed

Lifecycle

  1. Draft — you're writing it
  2. DPO Review — your Data Protection Officer reviews and adds their opinion
  3. Approved — the DPO signs off, processing can proceed
  4. Prior Consultation Required — residual risk is too high; you must consult your supervisory authority before proceeding

Frequently asked questions

When do we actually need to complete a DPIA?

A DPIA is required by GDPR Article 35 whenever data processing is likely to result in a high risk to the rights and freedoms of natural persons. If you are using AI to process personal data, one is almost certainly needed.

What does the tool auto-populate for us?

If your asset registry is configured (REG stream), several fields auto-populate: controller name from your organisation settings, data categories from your registered AI systems, and international transfers detected from your AI model providers.

How is risk scored inside the DPIA?

In the Risk Assessment section you add risks and score each on Likelihood (1 to 5) and Severity (1 to 5). The scores plot on a 5x5 risk matrix, colour-coded from green at the low end through amber and orange to red once a score reaches 16 or higher.

What happens if residual risk is still too high after mitigation?

The DPIA moves to a "Prior Consultation Required" state. This means the residual risk remains too high and, under Article 36, you must consult the supervisory authority.

Glossary

TermDefinition
DPIAData Protection Impact Assessment — a structured risk assessment required by GDPR
DPOData Protection Officer — the person responsible for GDPR compliance
Legal BasisThe lawful reason for processing personal data (consent, contract, legitimate interest, etc.)
Prior ConsultationWhen residual risk remains high after mitigations, Art.36 requires you to consult the supervisory authority
Data SubjectThe person whose data is being processed
ControllerThe organisation that determines why and how personal data is processed