Seed-stage B2B SaaS startup
Sample for a fictional organisation · 3,245 words[Company] DPIA Procedure
- Version: 1.0
- Owner: The CTO
- Approved by: The CEO
- Effective date: [Effective date]
- Next review date: [Review date]
1. Purpose and Scope
A data protection impact assessment (a DPIA) is an assessment, made before a new or changed use of personal data starts, of the risks that use creates for the people the data is about and of the measures that reduce them. This procedure applies to every new or changed way [Company] collects, uses, shares or stores personal data (information that relates to an identifiable person), whether in its own operations or in the products and services it provides. It sits beneath [Company]'s information security policy.
[Company] decides how personal data is used for some purposes, such as data about its own staff and the people it deals with directly, and for personal data it processes on behalf of a customer it acts on the customer's instructions. This procedure keeps the two cases apart. A controller is the organization that decides why and how personal data is used. A processor is an organization that uses personal data on behalf of a controller and on its instructions. US state privacy laws call a similar record a data protection assessment or a risk assessment, and [Company] uses the record in Appendix B for all of them.
This procedure does not replace:
- [Company]'s assessment of information security risk, which looks at threats to its systems and information as a whole rather than at the risk to individuals from one use of data.
- [Company]'s checks on a supplier before engaging it, which look at whether the supplier is suitable and secure.
10. Appendix A: Screening Checklist
The project lead answers each question yes or no for the new or changed use of personal data and records the answers.
- Does it evaluate, score or profile people, including predicting their behavior, interests, health, performance or location?
- Does it lead to decisions with legal or similarly significant effects on people, including any made without a person's involvement?
- Does it monitor people systematically, including tracking location or online behavior, or monitoring staff?
- Does it process sensitive data, including criminal offense data, financial details, precise location or identity documents?
- Does it process data on a large scale, by number of people, volume, variety, duration or geographical reach?
- Does it combine, compare or match data from different sources?
- Does it involve children or people who may be vulnerable, or people in a position of dependence such as employees?
- Does it use new or innovative technology, including AI, machine learning or biometrics, whether or not new to [Company]?
- Could it prevent people from exercising a right or from using a service or entering a contract?
- Does it collect data from people without their knowledge, or use data in a way they would not expect?
- Could a breach of the data cause physical harm or put people's safety at risk?
- Will a new processor or supplier handle the data?
- Will personal data be used for targeted advertising, or sold or shared with another business?
- Will the data be used to train automated decision-making, facial recognition or similar technology?
This is [Company]'s own rule. A yes to two or more questions means a DPIA is required, and a yes to one means the CTO decides whether a DPIA is required and records the reasons. Where every answer is no, the screening record says that no DPIA is needed. A yes to question 13 or 14, to question 2, to question 4, or to question 1 where the profiling could cause unfair treatment or financial, physical or reputational harm, also means a DPIA is required wherever a US state privacy law that requires an assessment of that activity applies to [Company].
Screening record:
- Project name: [Project name]
- Project lead: [Project lead]
- Date completed: [Date]
- Answer to each question: [Yes or no for each question]
- Questions answered yes: [Questions answered yes]
- Outcome under the rule above: [DPIA required, not required, or for decision]
- Decision and reasons: [Decision and reasons]
- Decided by: [Name and role of the person deciding]
- Date of decision: [Date]
11. Appendix B: DPIA Record Template
Reference and project:
- DPIA reference: [DPIA reference]
- Project name: [Project name]
- Project lead: [Project lead]
- Date started: [Date started]
- Version: [Version]
1. Need for the DPIA:
- Screening outcome: [Screening outcome]
- Why a DPIA is needed: [Why a DPIA is needed]
2. Description of the processing:
- How data is collected, used, stored, shared and deleted: [How data is collected, used, stored, shared and deleted]
- How long each category of data is kept: [How long each category of data is kept]
- Categories of data: [Categories of data]
- Categories of people: [Categories of people]
- Volume of data: [Volume of data]
- Geographical reach: [Geographical reach]
- Relationship with the people and their expectations: [Relationship with the people and their expectations]
- New technology involved: [New technology involved]
- Purposes: [Purposes of the processing]
- Locations where data is held: [Locations where data is held]
- Processor or supplier involved: [Processor or supplier involved]
2a. AI processing:
- Complete this part only where the use involves AI.
- Data sent to any AI model: [Data sent to any AI model]
- Provider of the model: [Provider of the model]
- Where the model runs: [Where the model runs]
- Whether the provider keeps or learns from the data: [Whether the provider keeps or learns from the data]
- How people review outputs: [How people review outputs]
- Whether any output leads to a decision about a person without a person's involvement: [Whether any output leads to a decision without a person's involvement]
3. Consultation:
- Who was consulted: [Who was consulted]
- What they said: [What they said]
- Reason the people affected were not consulted: [Reason the people affected were not consulted]
4. Necessity and proportionality:
- Whether the purpose could be achieved with less data or less intrusion: [Whether less data or less intrusion would achieve the purpose]
- How people are told about the processing: [How people are told about the processing]
- How people exercise their rights: [How people exercise their rights]
5. Risks:
| Severity | Remote | Possible | Probable |
|---|---|---|---|
| Severe | Medium | High | High |
| Significant | Low | Medium | High |
| Minimal | Low | Low | Medium |
| Ref | Risk to individuals | Likelihood | Severity | Overall |
|---|---|---|---|---|
| [Risk reference] | [Risk to individuals] | [Likelihood] | [Severity] | [Overall rating] |
| [Risk reference] | [Risk to individuals] | [Likelihood] | [Severity] | [Overall rating] |
Other risks noted: [Risks to the company or its customers rather than to individuals]
These risks are not rated in this record and are passed to the assessment of information security risk.
6. Measures:
The effect on risk is one of Eliminated, Reduced or Accepted.
| Ref | Measure | Effect on risk | Residual risk | Owner |
|---|---|---|---|---|
| [Risk reference] | [Measure] | [Effect on risk] | [Residual risk] | [Measure owner] |
| [Risk reference] | [Measure] | [Effect on risk] | [Residual risk] | [Measure owner] |
7. Decision and sign-off:
- Whether [Company] will go ahead with the processing: [Decision to proceed]
- Advice of the CTO: [Advice of the CTO]
- Whether the advice was followed, and the reasons if it was not: [Whether the advice was followed and the reasons]
- Confirmation by the CTO that the DPIA was carried out as this procedure requires: [CTO confirmation]
- Residual risk accepted: [Residual risk accepted]
- Accepted by: [Name and role of the person accepting the residual risk]
- Date: [Date]
- Review date: [Review date]
8. Customer acknowledgement (optional):
This part is completed only where this record is the DPIA of [Company]'s service shared with a customer, and the customer signs to confirm that it has received the record for use in its own assessment.
- Customer name: [Customer name]
- Name and role of the person signing for the customer: [Name and role of the person signing]
- Date: [Date]
Read the full example
[Company] DPIA Procedure
- Version: 1.0
- Owner: The CTO
- Approved by: The CEO
- Effective date: [Effective date]
- Next review date: [Review date]
1. Purpose and Scope
A data protection impact assessment (a DPIA) is an assessment, made before a new or changed use of personal data starts, of the risks that use creates for the people the data is about and of the measures that reduce them. This procedure applies to every new or changed way [Company] collects, uses, shares or stores personal data (information that relates to an identifiable person), whether in its own operations or in the products and services it provides. It sits beneath [Company]'s information security policy.
[Company] decides how personal data is used for some purposes, such as data about its own staff and the people it deals with directly, and for personal data it processes on behalf of a customer it acts on the customer's instructions. This procedure keeps the two cases apart. A controller is the organization that decides why and how personal data is used. A processor is an organization that uses personal data on behalf of a controller and on its instructions. US state privacy laws call a similar record a data protection assessment or a risk assessment, and [Company] uses the record in Appendix B for all of them.
This procedure does not replace:
- [Company]'s assessment of information security risk, which looks at threats to its systems and information as a whole rather than at the risk to individuals from one use of data.
- [Company]'s checks on a supplier before engaging it, which look at whether the supplier is suitable and secure.
2. Roles
- The project lead is whoever leads the project, product change, new supplier or new use of data, and may be any member of staff. The project lead screens, drafts the DPIA, consults, carries out the measures, keeps the record current and accepts a Low residual risk.
- The CTO keeps this procedure and the DPIA log, reviews screening records, advises on and reviews every DPIA, and confirms in the sign-off that it was carried out as this procedure requires. The CTO advises on security measures, accepts a Medium residual risk except where the CTO is also the project lead, and reports to the CEO under section 7.
- The CEO approves this procedure, accepts a High residual risk in writing, accepts a Medium residual risk where the CTO is also the project lead, and decides under section 7.
3. When a DPIA Is Required
[Company] carries out a DPIA, before the processing starts, wherever a new or changed use of personal data is likely to result in a high risk to the people the data is about, and always where the screening outcome rule in Appendix A requires one. One DPIA may cover a set of similar uses that present similar risks. An existing use of personal data is screened again when it changes in purpose, data, scale, technology, recipients or location. Some US state privacy laws require a data protection assessment, or in California a risk assessment, before processing that presents a heightened risk to consumers. Where such a law applies to [Company], it treats each of the following as requiring a DPIA, and the assessment weighs the benefits of the processing against the risks to the people affected, as reduced by the safeguards [Company] will apply:
- Targeted advertising.
- Selling or sharing personal data.
- Profiling that could cause unfair treatment or financial, physical or reputational harm.
- Processing sensitive data.
- Using automated decision-making for decisions with significant effects on a person.
- Training automated decision-making technology.
4. Screening
Every new or changed use of personal data goes through screening before its design is fixed, using the checklist in Appendix A. The project lead completes the screening record and sends it to the CTO, who decides within 10 working days ([Company]'s own target) whether a DPIA is needed. A decision not to carry out a DPIA is recorded with its reasons and kept in the DPIA log. Screening is repeated when the use changes. The following start screening:
- A new system or service that holds personal data.
- A new supplier that will process personal data.
- A new feature that uses personal data.
- A new use of data [Company] already holds.
- Sharing data with a new recipient.
- Any new or changed use of AI on personal data.
5. Carrying Out a DPIA
A DPIA begins as early in the project as possible and runs alongside its design, so that its outcomes can change the design.
- Identify the need. Record the screening outcome and why a DPIA is needed.
- Describe the processing. Set out its nature (how data is collected, used, stored, shared and deleted, and for how long it is kept), its scope (the categories of data and of people, the volume and the geographical reach), its context (the relationship with the people, their expectations, and any new technology involved) and its purposes, including the locations where data is held and any processor or supplier involved. Where the use involves AI, the description also covers, in part 2a of the record in Appendix B, what data is sent to any AI model, who provides the model and where it runs, whether the provider keeps or learns from the data, and how people review its outputs, including whether any output leads to a decision about a person without a person's involvement.
- Consult. Seek the views of the people affected or their representatives where appropriate, and record the reason where they are not consulted. Ask the CTO for advice, including on security measures, and record it, and ask any processor or supplier involved for the information the record needs.
- Assess necessity and proportionality. Record whether the purpose could be achieved with less data or less intrusion, how [Company] tells people about the processing, and how they exercise their rights.
- Identify and assess the risks. For each risk to the people affected, give a likelihood of remote, possible or probable and a severity of minimal, significant or severe, then give an overall rating of Low, Medium or High from the scales table in Appendix B and record the reason for each rating. Consider harms such as loss of control over their data, discrimination, identity theft or fraud, financial loss, damage to reputation, physical harm, loss of confidentiality, and being unable to exercise a right or use a service. A risk that falls on [Company] or its customers rather than on individuals, such as exposure of confidential security information, is recorded under "Other risks noted" in Appendix B and passed to [Company]'s assessment of information security risk, and it is left out of the overall and residual ratings, which measure risk to individuals only.
- Identify measures. For each risk, identify the measures that remove or reduce it, record whether the risk is eliminated, reduced or accepted, and rate the residual risk on the same scale.
- Sign off and record the outcome. Follow section 6, and put the measures into the project plan with an owner and a date for each.
6. Sign-off and the Decision to Proceed
No processing covered by a DPIA starts until the DPIA is signed off. The CTO signs to confirm that the DPIA was carried out as this procedure requires and records its advice, and where [Company] decides not to follow that advice the reasons are recorded in the DPIA. The DPIA states whether [Company] will go ahead with the processing, and the person who accepts the residual risk has the authority to decide that. The outcomes of the DPIA go into the project plan, and a DPIA is a living record that the project lead updates as the design changes. The residual risk is accepted by one role according to its level:
- Low: the project lead accepts it, and the CTO reviews the record.
- Medium: the CTO accepts it, except that the CEO accepts it where the CTO is also the project lead.
- High: it is accepted only as section 7 allows, and then by the CEO in writing with the reasons.
7. Where a High Risk Remains
Where the DPIA shows that a high risk to people would remain after every measure [Company] could take, the processing must not start. The CTO reports the DPIA to the CEO, who decides whether to change the design, add safeguards or drop the processing.
The processing may go ahead only where, after those changes, the risks to the people affected no longer outweigh the benefits of the processing and the CEO accepts the residual risk in writing.
8. Records and Review
- The CTO keeps a DPIA log listing every screening record and DPIA with its reference, the project, the outcome, the date signed off, the review date and its status.
- A DPIA is kept for as long as the processing continues and for 5 years after it was last updated.
- Each DPIA is reviewed when the risk it assessed changes, such as a change in purpose, data, scale, technology, recipients or location. It is also reviewed after a security incident affecting the processing or after a complaint about it, and in any case at least every 3 years.
- The review is recorded in the DPIA.
- Where California's regulations apply to [Company], a risk assessment they require is updated within 45 calendar days of a material change to the processing.
- Where California's regulations apply to [Company], it submits to the California Privacy Protection Agency each year the summary information those regulations require about the assessments it carried out, without submitting the assessments themselves.
- [Company] may share a summary of a DPIA with a customer or the people affected on request, leaving out anything that would harm security or confidentiality.
- The CTO reviews this procedure at least once a year and after any change in the law that affects it.
9. Suppliers and Customers
[Company]'s DPIAs depend on the suppliers that process personal data for it, and its customers' assessments depend on [Company].
9.1 Suppliers That Process Personal Data for the Company
Every supplier that processes personal data for [Company] must assist with [Company]'s DPIAs by giving the information the record needs about how it processes the data, where, with what sub-processors and with what security measures. [Company]'s contracts with such suppliers require this. A supplier's information is recorded in the DPIA, and the supplier is not responsible for [Company]'s decision.
9.2 Helping Customers with Their Assessments
Where [Company] processes personal data on behalf of a customer, [Company] is the processor and the customer, as controller, decides whether a DPIA is needed for its use of [Company]'s service and carries it out. [Company] assists, taking into account the nature of the processing and the information available to it.
- [Company] keeps a DPIA of its own service, recorded on the template in Appendix B, so that each customer can use it in its own assessment.
- [Company] shares it with each customer during onboarding, leaving out anything that would harm the security of the service.
- The CTO reviews it when the service, the way data flows through it or the suppliers it uses change, and when a customer asks.
- Requests for help are sent to [Privacy contact email] and answered within 10 working days.
- [Company] supplies a description of the processing it performs for the customer, the categories of data and people, the locations where data is held, the sub-processors involved, the security measures, and how long data is kept and how it is deleted.
- [Company] does not assess the customer's own purposes, its reasons for using the data, or the risks of its wider use of the data.
- Where a customer asks [Company] to carry out the DPIA for it, the customer remains responsible for the DPIA.
- A change [Company] makes to how the service processes personal data is screened under section 4, and customers are told of it as [Company]'s contract with the customer requires.
10. Appendix A: Screening Checklist
The project lead answers each question yes or no for the new or changed use of personal data and records the answers.
- Does it evaluate, score or profile people, including predicting their behavior, interests, health, performance or location?
- Does it lead to decisions with legal or similarly significant effects on people, including any made without a person's involvement?
- Does it monitor people systematically, including tracking location or online behavior, or monitoring staff?
- Does it process sensitive data, including criminal offense data, financial details, precise location or identity documents?
- Does it process data on a large scale, by number of people, volume, variety, duration or geographical reach?
- Does it combine, compare or match data from different sources?
- Does it involve children or people who may be vulnerable, or people in a position of dependence such as employees?
- Does it use new or innovative technology, including AI, machine learning or biometrics, whether or not new to [Company]?
- Could it prevent people from exercising a right or from using a service or entering a contract?
- Does it collect data from people without their knowledge, or use data in a way they would not expect?
- Could a breach of the data cause physical harm or put people's safety at risk?
- Will a new processor or supplier handle the data?
- Will personal data be used for targeted advertising, or sold or shared with another business?
- Will the data be used to train automated decision-making, facial recognition or similar technology?
This is [Company]'s own rule. A yes to two or more questions means a DPIA is required, and a yes to one means the CTO decides whether a DPIA is required and records the reasons. Where every answer is no, the screening record says that no DPIA is needed. A yes to question 13 or 14, to question 2, to question 4, or to question 1 where the profiling could cause unfair treatment or financial, physical or reputational harm, also means a DPIA is required wherever a US state privacy law that requires an assessment of that activity applies to [Company].
Screening record:
- Project name: [Project name]
- Project lead: [Project lead]
- Date completed: [Date]
- Answer to each question: [Yes or no for each question]
- Questions answered yes: [Questions answered yes]
- Outcome under the rule above: [DPIA required, not required, or for decision]
- Decision and reasons: [Decision and reasons]
- Decided by: [Name and role of the person deciding]
- Date of decision: [Date]
11. Appendix B: DPIA Record Template
Reference and project:
- DPIA reference: [DPIA reference]
- Project name: [Project name]
- Project lead: [Project lead]
- Date started: [Date started]
- Version: [Version]
1. Need for the DPIA:
- Screening outcome: [Screening outcome]
- Why a DPIA is needed: [Why a DPIA is needed]
2. Description of the processing:
- How data is collected, used, stored, shared and deleted: [How data is collected, used, stored, shared and deleted]
- How long each category of data is kept: [How long each category of data is kept]
- Categories of data: [Categories of data]
- Categories of people: [Categories of people]
- Volume of data: [Volume of data]
- Geographical reach: [Geographical reach]
- Relationship with the people and their expectations: [Relationship with the people and their expectations]
- New technology involved: [New technology involved]
- Purposes: [Purposes of the processing]
- Locations where data is held: [Locations where data is held]
- Processor or supplier involved: [Processor or supplier involved]
2a. AI processing:
- Complete this part only where the use involves AI.
- Data sent to any AI model: [Data sent to any AI model]
- Provider of the model: [Provider of the model]
- Where the model runs: [Where the model runs]
- Whether the provider keeps or learns from the data: [Whether the provider keeps or learns from the data]
- How people review outputs: [How people review outputs]
- Whether any output leads to a decision about a person without a person's involvement: [Whether any output leads to a decision without a person's involvement]
3. Consultation:
- Who was consulted: [Who was consulted]
- What they said: [What they said]
- Reason the people affected were not consulted: [Reason the people affected were not consulted]
4. Necessity and proportionality:
- Whether the purpose could be achieved with less data or less intrusion: [Whether less data or less intrusion would achieve the purpose]
- How people are told about the processing: [How people are told about the processing]
- How people exercise their rights: [How people exercise their rights]
5. Risks:
| Severity | Remote | Possible | Probable |
|---|---|---|---|
| Severe | Medium | High | High |
| Significant | Low | Medium | High |
| Minimal | Low | Low | Medium |
| Ref | Risk to individuals | Likelihood | Severity | Overall |
|---|---|---|---|---|
| [Risk reference] | [Risk to individuals] | [Likelihood] | [Severity] | [Overall rating] |
| [Risk reference] | [Risk to individuals] | [Likelihood] | [Severity] | [Overall rating] |
Other risks noted: [Risks to the company or its customers rather than to individuals]
These risks are not rated in this record and are passed to the assessment of information security risk.
6. Measures:
The effect on risk is one of Eliminated, Reduced or Accepted.
| Ref | Measure | Effect on risk | Residual risk | Owner |
|---|---|---|---|---|
| [Risk reference] | [Measure] | [Effect on risk] | [Residual risk] | [Measure owner] |
| [Risk reference] | [Measure] | [Effect on risk] | [Residual risk] | [Measure owner] |
7. Decision and sign-off:
- Whether [Company] will go ahead with the processing: [Decision to proceed]
- Advice of the CTO: [Advice of the CTO]
- Whether the advice was followed, and the reasons if it was not: [Whether the advice was followed and the reasons]
- Confirmation by the CTO that the DPIA was carried out as this procedure requires: [CTO confirmation]
- Residual risk accepted: [Residual risk accepted]
- Accepted by: [Name and role of the person accepting the residual risk]
- Date: [Date]
- Review date: [Review date]
8. Customer acknowledgement (optional):
This part is completed only where this record is the DPIA of [Company]'s service shared with a customer, and the customer signs to confirm that it has received the record for use in its own assessment.
- Customer name: [Customer name]
- Name and role of the person signing for the customer: [Name and role of the person signing]
- Date: [Date]
Disclaimer
This document is provided for informational purposes only and does not constitute legal advice. It is provided "as is", without warranty of any kind, express or implied, and no liability is accepted for any loss or damage arising from its use. It is used at your own discretion. Review it with a qualified adviser before adopting it.