What this is
What is a data protection impact assessment?
What is a data protection impact assessment?
A structured assessment, carried out before a new system or monitoring activity is introduced, that tests whether the processing is necessary and proportionate, identifies the risk to the people affected, records the safeguards in place, and reaches a proceed decision. It exists specifically for processing likely to result in high risk to individuals - systematic monitoring, biometric identification, large-scale special category data.
Why is timing central to a DPIA?
Because the assessment is meant to inform whether and how a system is built or bought, not to record that it already has been. A DPIA completed after go-live can still surface risk, but it can no longer change the system's design, and 'proceed' stops being a genuine option - which is why Stage Of The Project is scored, with Already live scoring lowest.
What makes an activity need a DPIA rather than the general processing register?
Novelty and intrusiveness. A processing activity that is already running and understood belongs on the processing register; one that is new, changed materially, or falls into a recognised high-risk category - cameras, telematics, biometrics, automated decisions - needs the impact weighed before it starts, which is what this assessment is for.
Scope
When is a data protection impact assessment required?
This assessment is the pre-implementation step in a larger programme. Using it to log an activity that is already running, or to record what happened after something went wrong, produces a document with the wrong content for either purpose.
Use this template when
- A new system, camera, monitoring activity or biometric access control is being planned, before purchase or installation
- An existing system is changing materially - new cameras added to a network, new data fields captured, a new use of existing footage
- Periodic reassessment of a high-risk activity that is already live, where the trigger is the interval rather than a change
- You are running the Data Protection and Information Security programme and this is its pre-implementation gate
- A linked record needs this one to exist: CCTV review, telematics, management of change
Do not use it for
- Personal Data Processing Record, which logs an activity once it is running, rather than assessing one before it starts.
- Data Breach Record, which records loss, exposure or unauthorised access after the fact, not the risk of a system before it is introduced.
- Subject Access Request Record, which records answering an individual's request for data already held.
- Information Security Risk Assessment, which assesses security risk to the organisation's systems generally, not privacy risk to the individuals a specific activity affects.
- Anything outside KnowComply, which belongs in the workspace that owns that process
Compliance mapping
Which ISO 27701 cl.7.2 requirements does this satisfy?
ISO/IEC 27701 names the privacy impact assessment directly within its PIMS-specific controls, alongside the equivalent statutory duty most comprehensive privacy regimes impose for high-risk processing specifically, not for processing in general.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 27701 cl.7.2.5 | Privacy impact assessment carried out for processing likely to result in high risk to individuals | Header |
| ISO 27701 cl.7.2.2 | Necessity and lawful basis established before processing begins | Necessity |
| ISO 27701 cl.7.2.5 | Risk to the rights and interests of individuals assessed, including function creep and profiling | Risks |
| ISO 27701 cl.7.4.9 | Safeguards applied to limit access, retention and use to what the assessment justifies | Safeguards |
| ISO 27701 cl.6.1.2 | Risk treatment decision recorded, including conditions attached to proceeding | Outcome |
| ISO 27701 cl.5.4 | Consultation and participation of affected workers in the assessment | Header |
What it does not cover
- Personal Data Processing Record, which the assessed activity must be added to once it goes live, since the DPIA alone does not create the ongoing inventory entry.
- Data Breach Record, which applies once the assessed system is running and something goes wrong with it.
- CCTV and Monitoring Review, which periodically re-examines a live monitoring system's justification, distinct from the one-off pre-implementation assessment.
- The consultation itself, which is evidenced here but conducted elsewhere - the assessment records that workers were consulted, not the process.
- Information Security Risk Assessment, which covers security risk to the organisation's systems, separate from the privacy risk this assessment weighs for individuals.
Global
Data Protection Impact Assessment requirements by country
The duty to assess before implementing is narrower than the general processing duty - it applies to processing likely to be high-risk, and the definition of high-risk differs by regime.
State privacy laws requiring data protection assessments (Colorado, Connecticut, CPRA)
No federal DPIA duty; several states require a documented assessment for profiling, targeted advertising, sale of data, or sensitive data including biometrics.
Biometric access control and workplace monitoring fall inside the state assessment triggers even without one nationwide requirement forcing the point.
UK GDPR Art.35; ICO guidance
DPIA mandatory for processing likely to result in high risk, with the ICO publishing an explicit list including systematic monitoring, biometric data and new technology.
Cameras, telematics and biometric access sit on the ICO's own list - not a matter of interpretation, it is named.
EU GDPR Art.35; ISO/IEC 27701 cl.7.2.5
The equivalent duty under EU GDPR, with ISO 27701 providing the certifiable process an auditor checks against for PIMS certification.
A regulator can require the assessment be produced before processing starts - completing one retrospectively does not satisfy the duty even if sound.
How to complete it
How to complete a data protection impact assessment, step by step
The template prompts the right questions in the right order. Whether the answers are honest is a separate matter, and it is where most of the judgement in a DPIA actually sits.
An assessment answered Already live has already conceded that the decision it exists to inform has been made elsewhere. Record that honestly - the finding that matters is not the score, it is why the assessment came after the fact and what will stop that recurring.
Workers Consulted offers Yes, Informed only and No as genuinely different states. Telling people a camera system is being installed is not the same as asking whether it should be, or what would achieve the same purpose with less intrusion - only the latter changes what gets built.
A monitoring activity can be necessary for its purpose - reducing theft - and still be disproportionate in scope, such as recording continuously where spot checks would serve the same purpose. Answering both Yes without engaging Less Intrusive Alternative Considered collapses three questions into a rubber stamp.
With conditions is not a softer Yes; it is a Yes contingent on something specific happening - a retention limit shortened, access restricted, a review point brought forward. The Conditions field records what was promised, but nothing checks it was delivered unless it is followed up as an action.
What auditors find
Most common data protection impact assessment findings
DPIA findings concentrate on timing and depth: whether the assessment happened when it could still change something, and whether the risk questions were actually engaged with or answered by pattern.
| Finding | Clause | What fixes it |
|---|---|---|
| Stage Of The Project recorded as Already live, with the assessment written to justify a decision already taken. | ISO 27701 cl.7.2.5 | Record the timing honestly, and put a trigger in place - purchase approval, installation permit - that forces the assessment before the next system goes live. |
| Necessary and Proportionate both answered Yes with no record of the less intrusive alternative considered. | ISO 27701 cl.7.4.2 | Require a stated alternative and the reason it was rejected before Proportionate can be marked Yes. |
| Workers Consulted marked Informed only for a system with direct impact on how they are monitored or accessed. | ISO 27701 cl.5.4 | Distinguish informing from consulting; escalate to genuine consultation where the activity affects individuals directly. |
| Register Updated left at No after the assessment concluded Proceed, so the processing register never reflects the activity. | ISO 27701 cl.7.2.8 | Make updating the processing register a condition of closing the DPIA, not a task someone remembers later. |
| Proceed Recommended answered With conditions, but the conditions were never tracked to a CAPA or an owner. | ISO 27701 cl.6.1.2 | Raise an action with an owner and date for every condition attached to a qualified Proceed, and verify before closing. |
| Automated Decision Making marked N/A for a system that scores access or risk using collected data. | ISO 27701 cl.7.2.5 | Test any scoring, ranking or access-control logic against the definition before marking N/A. |
Case in point
Case in point: the DPIA that arrived after the cameras
A logistics site fitted in-cab telematics to cut fuel use and support insurance renewal. The DPIA was raised three weeks after the units were installed and drivers had started seeing behaviour scores in the app, at the point compliance noticed no assessment existed. Necessity and proportionality were both marked Yes; Stage Of The Project was recorded, honestly, as Already live.
Drivers raised a formal grievance over the scoring feature two months later, arguing it had been introduced without consultation and used for more than fuel efficiency - feeding into performance conversations nobody had disclosed. The DPIA, written after the fact, had nothing to say about that use, because the system was already built around it by the time anyone assessed it. Fleet and vehicle changes now route through a DPIA gate before procurement is approved, not after the units arrive.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
5 sections
- Reference
- CMP-032
- Archetype
- Assessment
- Record ID
- DPIA-2026-000
- Scoring
- Assessments complete
- Direction
- High is good
- Singleton
- Yes
- Basis
- ISO 27701 cl.7.2
- Links
- Links CCTV review, Telematics, MOC
- Tags
- Privacy, Assessment
- Sections
- 5
- Fields
- 45
- Follow up fields
- 3
- Repeating sections
- 0
- Links out
- 2
Header
13 fieldsAssessment ID*
Auto sequence. Format DPIA-2026-000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Date and Time*
Completed By*
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
System Or Activity*
Assessment Trigger*
Assessed By*
Stage Of The Project*
- Before purchase4 pts
- Before installation3 pts
- Before go live2 pts
- Already live0 pts
Workers Consulted*
- Yes3 pts
- Informed only1 pt
- No0 pts
Privacy Lead Involved*
- Yes3 pts
- No0 pts
Cameras, Telematics And Biometrics All Need One
The systems that most improve safety are also the ones that most intrude. Assessing that before installation is both a legal requirement and the way to keep trust.
Necessity
6 fieldsPurpose Clearly Defined*
- Yes3 pts
- Partly1 pt
- No0 pts
Necessary For The Purpose*
- Yes3 pts
- Partly1 pt
- No0 pts
Proportionate To The Purpose*
- Yes3 pts
- Partly1 pt
- No0 pts
Less Intrusive Alternative Considered*
- Yes3 pts
- Partly1 pt
- No0 pts
Lawful Basis Identified*
- Yes3 pts
- Partly1 pt
- No0 pts
Scope Limited To What Is Needed*
- Yes3 pts
- Partly1 pt
- No0 pts
Risks
6 fieldsIntrusion On Workers Assessed*
- Yes3 pts
- Partly1 pt
- No0 pts
Function Creep Risk Assessed*
- Yes3 pts
- Partly1 pt
- No0 pts
Data Security Risk Assessed*
- Yes3 pts
- Partly1 pt
- No0 pts
Accuracy Risk Assessed*
- Yes3 pts
- Partly1 pt
- No0 pts
Automated Decision Making Involved*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Effect On Trust Considered*
- Yes3 pts
- Partly1 pt
- No0 pts
Safeguards
6 fieldsAccess Restricted And Logged*
- Yes3 pts
- Restricted only1 pt
- No0 pts
Retention Period Limited*
- Yes3 pts
- Partly1 pt
- No0 pts
Anonymisation Or Aggregation Used*
- Yes3 pts
- Partly1 pt
- No0 pts
Transparency To Workers Provided*
- Yes3 pts
- Partly1 pt
- No0 pts
Not Used For Unrelated Purposes*
- Yes3 pts
- Partly1 pt
- No0 pts
Review Point Set*
- Yes3 pts
- Partly1 pt
- No0 pts
Outcome
14 fieldsResidual Privacy Risk*
- Low3 pts
- Medium1 pt
- High0 pts
Proceed Recommended*
- Yes3 pts
- With conditions2 pts
- No0 pts
Conditions
Register Updated*
- Yes3 pts
- No0 pts
Consultation Feedback Addressed*
- Yes3 pts
- Partly1 pt
- No0 pts
Review Date*
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Privacy Lead*
Signature*
Site Manager*
Second Signature*
CMP-032 · record IDs look like DPIA-2026-000 · Links CCTV review, Telematics, MOC
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The assessment itself is a one-time document. What fails is the gate around it - the purchase that proceeds before the DPIA is written, and conditions attached to a qualified Yes that nobody tracks.
Holds the DPIA against the processing register and retention schedule, and flags when Proceed Recommended closes without the corresponding register entry being added.
Surfaces telematics and vehicle monitoring proposals early enough to route them through the DPIA gate before procurement.
Flags new camera and access-control installations at planning stage, so Stage Of The Project can genuinely be Before purchase.

Tracks conditions attached to a qualified Proceed through to closure, and prompts the review date rather than leaving it to expire unnoticed.
This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.
Meet KnowComply→Glossary
Data Protection Impact Assessment definitions and key terms
- Data protection impact assessment
- A pre-implementation assessment of the privacy risk a new system or activity poses to individuals, required specifically for processing likely to result in high risk.
- Necessity and proportionality
- Two distinct tests: whether the processing is required to achieve the purpose, and whether its scope and intrusiveness are no more than the purpose justifies.
- Residual privacy risk
- The risk remaining once identified safeguards are applied - the figure the proceed decision is actually made against, not the raw risk before safeguards.
- Function creep
- A system used beyond the purpose it was assessed and introduced for, such as fuel-efficiency telematics later feeding into disciplinary decisions.
- Data minimisation
- Collecting and retaining no more data than the stated purpose requires - the principle behind Scope Limited To What Is Needed and Retention Period Limited.
FAQ
Frequently asked questions about data protection impact assessment
When does a DPIA need to be done rather than just logging on the processing register?+
When the activity is new, has changed materially, or falls into a recognised high-risk category - systematic monitoring, biometric identification, automated decisions, large-scale special category data. An established, low-risk activity belongs on the processing register; a new camera network or biometric access system needs the impact weighed first.
What if the system is already live when someone realises a DPIA was never done?+
Complete it, and record Stage Of The Project as Already live honestly rather than backdating it. Treat the gap itself as a finding, and fix the trigger so the next system reaches go-live assessed, not this one retrospectively cleared.
Is informing workers the same as consulting them?+
No. Workers Consulted distinguishes Yes from Informed only precisely because they produce different assessments - consultation can surface a less intrusive alternative or a use nobody had considered, while informing only confirms the decision has already been made.
What does Proceed With conditions actually commit the organisation to?+
Whatever is written in the Conditions field - a retention limit, restricted access, a review point - and those conditions need an owner and a date to be delivered, not just a note. Without that, With conditions functions as an unconditional Yes.
Does completing the DPIA update the processing register automatically?+
No. Register Updated is a separate field - the assessment and the register are different records, and an activity can pass its DPIA and still never reach the register if closing the assessment isn't treated as the trigger.
How is residual risk different from the risk assessed under Risks?+
The Risks section evaluates intrusion, function creep, security, accuracy and trust before safeguards are applied. Residual Privacy Risk in the Outcome section is what remains once the Safeguards section's controls are counted - the figure the proceed decision is actually made against.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Data Protection and Information Security
Personal Data Processing Record
Records what personal data the organisation holds, why, on what basis and for how long
Data Breach Record
Records loss, exposure or unauthorised access to personal data, with the assessment of harm and notification decision
Subject Access Request Record
Records a request from an individual for the data held about them, and how it was answered within the deadline
Information Security Risk Assessment
Assesses threats to systems, data and operational technology, including plant control systems
System Access Review
Reviews who has access to which systems and at what privilege level
Cyber Incident Record
Records a cyber event affecting systems, data or plant operation, with containment, recovery and notification
More in Data and Privacy
Personal Data Processing Record
Records what personal data the organisation holds, why, on what basis and for how long
Data Breach Record
Records loss, exposure or unauthorised access to personal data, with the assessment of harm and notification decision
Subject Access Request Record
Records a request from an individual for the data held about them, and how it was answered within the deadline

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 27701:2019 cl.7.2.5
- UK GDPR Article 35; ICO guidance on when a DPIA applies
- EU GDPR Article 35
- Article 29 Working Party guidelines on DPIA (WP248)
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.