Generate a GDPR-compliant Data Protection Impact Assessment with risk analysis, lawful basis mapping, and mitigation plans.
You are a data protection officer. Generate a complete DPIA for the following data processing activity. ## Processing Activity - **Activity Name**: [ACTIVITY e.g. customer analytics platform / employee monitoring / AI recommendation engine] - **Data Controller**: [CONTROLLER e.g. company name and jurisdiction] - **Data Subjects**: [SUBJECTS e.g. EU customers / employees / website visitors] - **Personal Data Categories**: [DATA e.g. name, email, IP, browsing behavior, biometrics, health data] - **Special Category Data**: [SPECIAL e.g. none / health / biometric / racial or ethnic origin] - **Processing Purpose**: [PURPOSE e.g. marketing personalization / fraud detection / performance evaluation] - **Lawful Basis**: [BASIS e.g. consent / legitimate interest / contract / legal obligation] ## DPIA Sections ### 1. Processing Description - Nature: What data is collected and how - Scope: Volume, frequency, geographical coverage - Context: Relationship with data subjects, expectations - Purpose: Specific objectives and outcomes - Data flow diagram: collection → processing → storage → sharing → deletion ### 2. Necessity and Proportionality - Lawful basis justification for [BASIS] - Data minimization assessment: is each data element necessary? - Purpose limitation: is processing strictly for stated purpose? - Storage limitation: defined retention periods with justification - Accuracy measures: how data quality is maintained - Legitimate interest assessment (if applicable) ### 3. Risk Identification For each risk, assess likelihood (1-4) and severity (1-4): - Unauthorized access to [DATA] - Data breach and notification requirements - Function creep (using data beyond stated purpose) - Automated decision-making impacts - Cross-border transfer risks - Third-party processor risks - Re-identification risks for pseudonymized data - Profiling and discrimination risks ### 4. Risk Mitigation Measures - Technical measures: encryption, pseudonymization, access controls - Organizational measures: policies, training, DPO appointment - Contractual measures: processor agreements, SCCs for transfers - Data subject rights implementation: access, rectification, erasure, portability - Privacy by design implementation - Regular review and audit schedule ### 5. Data Subject Rights - Right to access implementation - Right to rectification workflow - Right to erasure (right to be forgotten) process - Right to data portability format - Right to object mechanism - Automated decision-making opt-out ### 6. Consultation - DPO opinion and recommendation - Supervisory authority consultation threshold assessment - Stakeholder consultation summary - Approval and sign-off section Generate the complete DPIA document with risk matrices and action items.
Free to copy and use. Compatible with Claude 4 Opus, GPT-5, Gemini 2.5 Pro.
Describe the data processing activity in detail. Fill in all personal data categories being processed. The DPIA should be reviewed by your DPO and updated when processing changes.
Initial release
Sign in and download this prompt to leave a review.