Data Protection Impact Assessment

DPIA Questionnaire

A working questionnaire built from the EDPB's official DPIA template (v1.0, adopted 10 March 2026). Work through it section by section: start with the overview of the processing, then move into the detailed analysis, risk assessment, and final decision.

01
Overview
Who the controller and processors are, what the processing is called, and why a DPIA is being carried out.
02
Detailed analysis
The processing itself, its lawfulness, necessity and proportionality, and the compliance measures in place.
03
Risk & decision
Inherent and residual risk, the mitigation plan, and the final decision on whether the processing can proceed.
Start with the overview ↓
0

Overview of the processing

0.1 Controller(s)

If there are joint controllers, add one entry per controller and describe their respective obligations and tasks.

Controller nameManagement units responsible for the processing inside the organisationMain establishment / point of contact or representativeDPO or similar function, if applicable

0.2 Processor(s) and sub-processor(s)

#ProcessorDefinition of their obligations and tasks

0.3 Name of the processing

0.4 Planning of the processing

0.5 DPIA technical sheet

1

Systematic description of the processing

1.1.a Processed personal data

#Processed personal data (item or element)Explanation (data type, data subject category, details)Special category

1.1.b Purposes of the processing

#Purpose: specific and explicit reason for processingPersonal data involved (from 1.1.a) and justification

1.1.c Secondary or compatible uses

#Secondary or compatible use of the dataPersonal data involved, conditions, and compatibility assessment

1.1.d Nature, scope and context of the processing

1.2 Functional description

Ideally supplement this table with one or more data-flow diagrams.

#Processing phase or stageType of operation(s)Explanation

1.3 Means of processing, supporting assets and underlying architecture

#Processing phase or stage (from 1.2)Means of processing and supporting assetsExplanation

1.4 Compliance with approved codes of conduct

#Code of conductStatusWhy?
2

Analysis of the processing

2.1.a Legal basis

One row per purpose/use from 1.1.b and 1.1.c.

#Purpose / useLegal basis (Art. 6(1) GDPR)Justification (analyse legitimate interests / balancing test where relevant)

2.1.b Reasons to lift the processing prohibition

Only needed for special categories of data (Art. 9) identified in 1.1.a.

#Special category of data (from 1.1.a)Reason to lift prohibition (Art. 9(2))Justification

2.2.a Data minimisation and retention periods

#Processed personal dataJustification of need/relevanceRecipientsJustificationRetention periodJustification

2.2.b Data quality

#Processed personal dataQuality metrics, requirements or thresholdsJustification

2.3.a Measures supporting compliance with Article 5(1)(a-f) GDPR principles

2.3.b Measures supporting the exercise of data subjects' rights

2.3.c Measures supporting compliance with other GDPR requirements

2.3.d Measures supporting data protection by design and by default (Art. 25)

#List of supporting measuresDiscussion of appropriateness and effectivenessStatus

2.3.e Measures supporting security of processing (Art. 32)

#List of supporting measuresDiscussion of appropriateness and effectivenessStatus
3

Considerations on necessity and proportionality

3.1 Impacts of the processing on the rights and freedoms of data subjects

#Threats posed by the processing as designed (incl. mitigating measures)How can it be materialised?Risk sources (purpose, wrong design, weaknesses, exposures)Impact on rights and freedoms

3.2 Assess the necessity of the processing

3.3 Assess the proportionality of the processing

4

Risk assessment and management

4.1.a Impacts caused by non-default, accidental, unlawful or abnormal events

Identify, at minimum, threats that could lead to illegitimate access, undesired modification, or disappearance of data.

#Threats (malfunctions, deviations, CIA/cybersecurity threats)How can it be materialised?Risk sources (exposures, errors, vulnerabilities)Impacts on rights and freedoms

4.1.b Method

4.1.c Inherent risk assessment

#Risk to rights and freedoms (from 3.1 / 4.1.a)LikelihoodSeverityModulating factorsRisk levelAcceptable?

4.2.a Additional mitigating measures

#Type of measureMeasure(s)Mitigated risks (from 4.1.c)Discussion of appropriateness and effectivenessStatus

4.2.b Residual risk assessment

#Reassessed riskAdditional mitigating measures appliedResidual likelihoodResidual severityResidual risk levelAcceptable?

4.2.c Plan

5

Involvement of interested parties

5.1 DPO advice

5.2 Views of data subjects or their representatives

6

Conclusion and decision

Based on the assessment of risks and rights, select the decision taken.

#Condition

Justification of the decision (optional)