Data Privacy Impact Assessment (DPIA) Template

An actionable, fillable DPIA template to assess projects for privacy risk, capture mitigation plans, and record approvals. Includes a worked example for a user analytics pipeline and fields to score likelihood, impact, and residual risk.

Interactive Tool

Data Privacy Impact Assessment (DPIA) Template

This interactive DPIA helps teams quickly evaluate privacy risks, document mitigation decisions, and capture required approvals. Use the fields below to describe the project, identify personal data involved, record the lawful basis, score likelihood and impact, list mitigations, and record approvals. An example filled DPIA for a user analytics pipeline is included to show a practical, minimal response.

Example (filled) — User analytics pipeline

Project summary: Collect event data from web and mobile apps to understand feature usage and improve onboarding. No health or financial data; identifiers are limited to a hashed user id and email for account linking.

Lawful basis: Legitimate interests (product improvement). Balance test performed; sensitive data avoided; opt-out respected for marketing cookies.

Data types: Identifiers (hashed user id), contact (email), behavioral (event data), device (user agent), location (coarse city level).

Mitigations: Data minimization, pseudonymization (hashing), encryption in transit and at rest, RBAC for analytics team, 90-day event retention then aggregation to 12-month monthly summaries, DPAs with vendor analytics provider.

Risk scoring: Likelihood 2, Impact 3 → Estimated risk: Medium. Residual risk accepted by DPO pending anonymization of any records used for support.

Briefly describe the project, purpose, scope, and intended outcomes (2–5 sentences).
Name and role of the person responsible for this DPIA.
Contact address for questions.
Why are you collecting or using personal data? Be specific about the intended outcomes.
Check all that apply. If you select 'Other', explain in the Other personal data types field.
Describe any other data types not listed above.
Select the primary lawful basis. If you select 'Legitimate interests', complete the legitimate interests assessment field.
If relying on legitimate interests, describe purpose, necessity, balancing of rights, and safeguards.
Describe where data originates, downstream systems, third-party processors, and any cross-border transfers.
Identify storage systems, cloud providers, databases, and geographic regions.
How long will personal data be kept? Include retention schedule and deletion/archival processes.
Describe authentication, RBAC, encryption at rest/in transit, and logging practices.
Rate the likelihood that a privacy event could occur without mitigations.
1.0 10.0
Rate the potential severity if a privacy incident occurs (reputational, financial, individual harm, regulatory).
1.0 10.0
Multiply likelihood × impact and select the corresponding level: 1–6 low, 7–12 medium, 13–25 high.
Select mitigation measures planned.
Describe any additional technical or organizational controls.
Describe remaining risk, acceptance rationale, or compensating controls.
Describe processes for access, rectification, erasure, portability, objection, and consent withdrawal.
List processors, evidence of certification (SOC2, ISO27001), and contract links.
Select all approvers required for this project.
Record approval names, dates, and comments. Use this field to capture evidence of review.
Links to architecture diagrams, contracts, privacy policy, or an example filled DPIA.
You can explore this tool now. Sign in or create an account to save your responses and return to them later.
Make this tool part of your work

Save a personal copy, bring it to your team, or tailor the questions and workflow to fit what you are hungry to improve.

Member customization and team collaboration are coming soon.

Discussion

Comments and conversation will live here.