Compliance Tools
A Data Protection Impact Assessment is required by GDPR Article 35 whenever your data processing is "likely to result in a high risk to the rights and freedoms of natural persons." If you're using AI to process personal data, you almost certainly need one. A completed DPIA becomes part of the evidence your auditors will actually see, not a document that sits in a drawer.
The 6 sections
| # | Section | What you fill in |
|---|---|---|
| 1 | Processing Description | What data you process, why, the legal basis, who receives it, how long you keep it |
| 2 | Necessity & Proportionality | Why this processing is necessary and proportionate to its purpose |
| 3 | Risk Assessment | What could go wrong for the people whose data you process |
| 4 | Mitigation Measures | What you're doing to reduce those risks |
| 5 | Consultation | Whether you've consulted your DPO and/or the affected individuals |
| 6 | Outcome | The overall risk level and your decision (proceed, proceed with conditions, or stop) |
How to use
Navigate to Compliance Command Center → Privacy Impact tab.
Auto-population
If you have the asset registry configured (REG stream), several fields are auto-populated:
- Controller name from your organisation settings
- Data categories from your registered AI systems
- International transfers detected from your AI model providers (Anthropic = US, Google = global, OpenAI = US)
Risk matrix
In the Risk Assessment section, add risks and score each on:
- Likelihood (1-5) — how likely is this to happen?
- Severity (1-5) — how bad is it if it does?
The interactive 5×5 matrix visualises your risks as dots. Scores are colour-coded on a gradient:
| Score | Colour |
|---|---|
| below 4 | Green |
| 4-8 | Amber |
| 9-15 | Orange |
| 16 or higher | Red |
Lifecycle
- Draft — you're writing it
- DPO Review — your Data Protection Officer reviews and adds their opinion
- Approved — the DPO signs off, processing can proceed
- Prior Consultation Required — residual risk is too high; you must consult your supervisory authority before proceeding
Frequently asked questions
When do we actually need to complete a DPIA?
A DPIA is required by GDPR Article 35 whenever data processing is likely to result in a high risk to the rights and freedoms of natural persons. If you are using AI to process personal data, one is almost certainly needed.
What does the tool auto-populate for us?
If your asset registry is configured (REG stream), several fields auto-populate: controller name from your organisation settings, data categories from your registered AI systems, and international transfers detected from your AI model providers.
How is risk scored inside the DPIA?
In the Risk Assessment section you add risks and score each on Likelihood (1 to 5) and Severity (1 to 5). The scores plot on a 5x5 risk matrix, colour-coded from green at the low end through amber and orange to red once a score reaches 16 or higher.
What happens if residual risk is still too high after mitigation?
The DPIA moves to a "Prior Consultation Required" state. This means the residual risk remains too high and, under Article 36, you must consult the supervisory authority.
Glossary
| Term | Definition |
|---|---|
| DPIA | Data Protection Impact Assessment — a structured risk assessment required by GDPR |
| DPO | Data Protection Officer — the person responsible for GDPR compliance |
| Legal Basis | The lawful reason for processing personal data (consent, contract, legitimate interest, etc.) |
| Prior Consultation | When residual risk remains high after mitigations, Art.36 requires you to consult the supervisory authority |
| Data Subject | The person whose data is being processed |
| Controller | The organisation that determines why and how personal data is processed |