Free PDF template
Free DPIA Template for Software & AI Products
A practical starting point for documenting high-risk personal-data processing, the necessity of the work, risks to people and the controls your team will implement.
Request the free templateEmail delivery · No marketing unless you explicitly opt in
What the template covers
- +Data flows, actors & processors
- +Necessity and proportionality assessment
- +Risk identification and scoring
- +Mitigating controls and residual risk
- +Owner and action plan
Use it when
- +A new product or feature may create high risk for individuals
- +You process health, biometric, location or other sensitive data
- +You use systematic monitoring, profiling or consequential AI
- +Legal, product and engineering need one shared assessment
What it does not replace
- –A substitute for advice from your DPO or qualified counsel
- –A guarantee that a processing activity is lawful
- –A checkbox exercise completed without the people who understand the system
How to use it
- 01Define the processing purpose, actors and intended outcome
- 02Map personal data from collection through deletion
- 03Assess necessity, proportionality and risks to people
- 04Assign controls, owners, deadlines and residual risk
- 05Obtain the appropriate internal review and sign-off
Frequently asked questions
Who should complete a DPIA?
The product owner, engineers, security or privacy stakeholders and the DPO where applicable should contribute. No single person normally holds the whole data-flow picture.
When is a DPIA required?
GDPR requires one where processing is likely to result in high risk to people. Your DPO or qualified adviser should confirm the legal determination for your specific activity.