Data Privacy Impact Assessment (DPIA) Template
An actionable, fillable DPIA template to assess projects for privacy risk, capture mitigation plans, and record approvals. Includes a worked example for a user analytics pipeline and fields to score likelihood, impact, and residual risk.
Data Privacy Impact Assessment (DPIA) Template
This interactive DPIA helps teams quickly evaluate privacy risks, document mitigation decisions, and capture required approvals. Use the fields below to describe the project, identify personal data involved, record the lawful basis, score likelihood and impact, list mitigations, and record approvals. An example filled DPIA for a user analytics pipeline is included to show a practical, minimal response.
Example (filled) — User analytics pipeline
Project summary: Collect event data from web and mobile apps to understand feature usage and improve onboarding. No health or financial data; identifiers are limited to a hashed user id and email for account linking.
Lawful basis: Legitimate interests (product improvement). Balance test performed; sensitive data avoided; opt-out respected for marketing cookies.
Data types: Identifiers (hashed user id), contact (email), behavioral (event data), device (user agent), location (coarse city level).
Mitigations: Data minimization, pseudonymization (hashing), encryption in transit and at rest, RBAC for analytics team, 90-day event retention then aggregation to 12-month monthly summaries, DPAs with vendor analytics provider.
Risk scoring: Likelihood 2, Impact 3 → Estimated risk: Medium. Residual risk accepted by DPO pending anonymization of any records used for support.
Save a personal copy, bring it to your team, or tailor the questions and workflow to fit what you are hungry to improve.
Discussion
Comments and conversation will live here.