Privacy, Compliance & Data Ethics — Impact Assessment Template

Structured, savable privacy & ethics impact assessment for projects that use personal data or produce automated decisions. Collects inventory, lawful basis, risk scoring, mitigations, acceptance criteria, and approvals so teams can document decisions, track reviews, and preserve audit trails.

Interactive Tool

Privacy & Ethics Impact Assessment

Use this assessment to identify, evaluate, and document privacy, compliance, and ethical risks for any project, model, or dataset that uses personal data or produces automated decisions. Complete fields honestly, attach evidence where appropriate, and record approvals. Saving the form stores a submission you can review later.

Short, descriptive name for the project or model.
Name and role of the person accountable for privacy decisions.
Describe what the project does, what decisions will be made, who benefits, and who may be affected.
List data types used (PII, PHI, device IDs, location, behavioral, inferred attributes). Note sensitivity (low/medium/high) and any third-party sources.
How long will data be stored, and why? Include criteria for deletion or anonymization.
Check any that apply.
Choose the lawful basis for processing personal data (adjust options to local law).
Describe each intended use of the data and map it to the legal basis, teams, and downstream consumers.
Examples: automated approvals/denials, scoring, recommendations that materially affect people.
If automated decisions occur, how will humans review or override outputs?
Estimate how likely it is that individuals could be re-identified from the data (0=none, 5=very high). Consider direct identifiers, quasi-identifiers, and linkage risk.
1.0 10.0
Estimate the likelihood that model or process will produce biased or discriminatory outcomes (0=none, 5=very high). Consider training data, representation, and outcome disparities.
1.0 10.0
Could legitimate outputs be misused later (profiling, surveillance, discriminatory operations)? (0=none, 5=very high)
1.0 10.0
Automators may calculate this client-side as a sum or weighted average. If left blank, approvers may compute during review.
List technical, organizational, and procedural mitigations (anonymization, minimization, encryption, access controls, bias mitigation, monitoring). Be specific and assign owners and deadlines.
Choose the approach and reference any verified methods or tests.
Define measurable criteria that must be met before deployment (e.g., re-id risk <=2, fairness metric parity within X%). Include monitoring triggers and rollback conditions.
How will you monitor performance, privacy, and fairness in production? Include metrics, frequency, and responsible owners.
Check items you will attach to the assessment.
Indicate whether the formal privacy/legal review occurred.
Select required approvers before deployment.
Record the names, roles, and dates of approvers who accepted the risk and mitigations.
How often will this assessment be reviewed?
Capture open items, owners, and deadlines for follow-up.
You can explore this tool now. Sign in or create an account to save your responses and return to them later.
Make this tool part of your work

Save a personal copy, bring it to your team, or tailor the questions and workflow to fit what you are hungry to improve.

Member customization and team collaboration are coming soon.

Discussion

Comments and conversation will live here.