# Data Protection Impact Assessment (DPIA)

> ISO/IEC 27701 + GDPR Art.35 required for high-risk processing.
> Required when: systematic profiling, large-scale sensitive data,
> public-area monitoring, new tech, or processing could restrict
> data subject rights.

| Field | Value |
|-------|-------|
| Assessment ID | DPIA-YYYY-NNN |
| Processing activity | name |
| Assessor | @name |
| DPO consulted | @name – required for high-risk |
| Date | YYYY-MM-DD |
| Status | Assessment / mitigation / approved |

## 1. Processing description

- **What**: personal data types, subjects (customers/employees/users)
- **Purpose**: why processing happens
- **Scale**: volume, duration, geographic scope
- **Tech**: systems, storage, transfers
- **Data flow**: collection → use → storage → sharing → deletion

## 2. Necessity & proportionality

- Is the processing necessary for the purpose?
- Is there a less invasive alternative?
- Lawful basis: consent / contract / legal obligation / legitimate interest

## 3. Risk assessment to data subjects

| Risk to individuals | Likelihood | Severity | Existing controls | Residual |
|---------------------|------------|----------|-------------------|----------|
| Unauthorized disclosure | H/M/L | H/M/L | encryption, access | |
| Re-identification of anonymized | | | | |
| Discrimination/profiling harm | | | | |
| Loss of availability | | | | |

## 4. Consultation

- DPO opinion: summary of advice given
- Data subject input: how views were considered (if required)

## 5. Mitigation plan

| Risk | Measure | Owner | Residual target | Due |
|------|---------|-------|-----------------|-----|
| High residual risk | additional control | @name | acceptable | |

## 6. Outcome

- [ ] Processing may proceed (residual acceptable)
- [ ] Proceed with mitigations above
- [ ] Requires prior consultation with supervisory authority
- [ ] Must not proceed

## 7. Approvals

| Role | Name | Decision | Date |
|------|------|----------|------|
| DPO | | approved/conditions | |
| Data controller | | | |
