Some processing is risky enough that the UK GDPR expects you to assess it before you start - large-scale profiling, special-category data, new technology. This assessment works through the need for a DPIA, describes the processing, records consultation and necessity, and rates the residual risk, so high-risk processing is thought through and documented.
This form template is supplied in fully editable MS Word format and can be easily customised and edited. The document uses pre-defined style formatting throughout, with all text in Calibri font for improved readability.
The following document labelling is included in the footer:
- Form number and title
- Information-classification
- Version
- Page number / total pages
alphaZ documents - beautifully designed, tried and tested form templates. No junk, jargon or unnecessary fields. Simple and usable form templates
developed over 25 years through practical use in the real world. No AI generated nonsense here!
Further guidance on data protection and processing risk:
Download this form template with your company name and logo already added!
Document Preparation available with all document toolkits.
To get access to this file please click on Add to Cart to purchase for immediate download. If you have an alphaZ Subscription just click on Download Files to view all the files available to download. This form is also included in the GDPR & Data Protection Toolkit and every alphaZ ISO toolkit that covers information security and data protection, so the toolkit route gives you this file plus everything else you need in one download.
If you'd like hands-on help working through a data protection impact assessment, or your wider information security management system, our remote support services provide direct expert input from our team, by the day, by project, or on an ongoing basis.
Data Protection Impact Assessment Template
A data protection impact assessment (DPIA) template for assessing the risks of a processing activity or project before it goes ahead. It works through five stages - the need for a DPIA, a description of the processing, consultation, an assessment of necessity and proportionality, and a risk assessment with controls - and includes a risk rating matrix.
Article 35 of the UK GDPR requires a DPIA where processing is likely to result in a high risk to individuals. This template gives you a structured way to carry one out, to demonstrate that the risks were assessed and mitigated, and to evidence accountability under the Data Protection Act 2018.
Built for the UK GDPR DPIA Requirement
The template follows the stages a DPIA is expected to cover:
- An assessment of whether a DPIA is needed, with the scope of the initiative
- A description of the nature, scope, context and purposes of the processing
- A record of the consultation process and of necessity and proportionality
- A risk assessment of the processing, with inherent and residual risk ratings and control measures
What's Included in this Data Protection Impact Assessment
The template is set out in stages so an assessment can be completed and evidenced in one document:
- Stage 1 - Need for a DPIA - the scope of the initiative and a summary of why a DPIA is required
- Stage 2 - Describe the Processing - the nature, scope, context and purposes of the processing
- Stage 3 - Consultation - who was consulted internally and externally, and why
- Stage 4 - Necessity and Proportionality - the lawful basis, transparency, data minimisation and data subject rights
- Stage 5 - Risk Assessment - a matrix rating the source and impact of each risk, inherent and residual, with control measures
Who Needs a Data Protection Impact Assessment?
Any organisation planning processing that could be high risk to individuals - new systems, profiling, monitoring, or handling special-category data - needs to assess it first. It suits smaller businesses that need a clear, defensible method without a dedicated privacy team, and anyone maintaining data protection compliance or an information security management system aligned with ISO 27001.
Included in the GDPR & Data Protection Toolkit
This form is part of the GDPR & Data Protection Toolkit - the registers, forms, policies and guidance for documenting how you collect and process personal data in one download - and is included in the alphaZ ISO 27001 Toolkit for information security.
Pairs with the Record of Processing Form
A DPIA builds on knowing what you process, so it pairs with the F-Q99 Record of Processing Form, which documents your processing activities, their lawful basis and how the data is shared, stored and protected.