Summary
In short
- A data protection impact assessment is an assessment used in KnowComply that assesses the privacy impact of a new system or monitoring activity before it is introduced. It is built against ISO 27701 cl.7.2 and forms part of the Data Protection and Information Security programme.
- Carried out before implementation. Completed by the privacy lead.
- The template holds 45 fields across 5 sections.
- Scoring is assessments complete, where high is good.
- ISO is international Organization for Standardization. A voluntary international standard. Widely adopted, often required by customers, and certifiable where a management system standard.
- It connects to the rest of the library: links CCTV review, Telematics, MOC.
What it is
What it is
What is a data protection impact assessment?
A data protection impact assessment is an assessment used in KnowComply that assesses the privacy impact of a new system or monitoring activity before it is introduced. It is built against ISO 27701 cl.7.2 and forms part of the Data Protection and Information Security programme.
When is a data protection impact assessment completed?
A data protection impact assessment is completed when the task, area or population being assessed is new or has materially changed. Carried out before implementation.
When to use it
When to use it, and when not to
This assessment is one step in a larger programme. Using it for work that belongs to a neighbouring template produces records that are hard to report on later.
Use it for
- The event or activity this assessment covers has occurred, or is about to
- The workspace is being set up, or the register needs an entry added or retired
- You are running the Data Protection and Information Security programme and this is one of its steps
- A linked record needs this one to exist: links cctv review, telematics, moc
Not for
- Personal Data Processing Record, which records what personal data the organisation holds, why, on what basis and for how long.
- Data Breach Record, which records loss, exposure or unauthorised access to personal data, with the assessment of harm and notification decision.
- Subject Access Request Record, which records a request from an individual for the data held about them, and how it was answered within the deadline.
- Anything outside KnowComply, which belongs in the workspace that owns that process
Standards
What it is built against
ISOInternational Organization for Standardization
A voluntary international standard. Widely adopted, often required by customers, and certifiable where a management system standard.
FAQ
Frequently asked questions
What is the data protection impact assessment template based on?+
It is built against ISO 27701 cl.7.2. ISO is international Organization for Standardization. A voluntary international standard. Widely adopted, often required by customers, and certifiable where a management system standard.
What sections does the data protection impact assessment contain?+
There are 5 sections: header, necessity, risks, safeguards, outcome. Together they hold 45 fields, 40 of which are required.
How many data protection impact assessment records should we have?+
This is a singleton. One record per workspace, set up once and maintained, rather than one per event. Other templates refer back to it.
Which programme does the data protection impact assessment belong to?+
It is part of Data Protection and Information Security. Monitoring introduced with consultation, and backups proven by restoring them.
How is a data protection impact assessment scored?+
Scoring is assessments complete. High is good. Scores exist to make the form tell you something, not to produce a percentage for its own sake.
Can the data protection impact assessment template be changed?+
Yes. Every field, option, score and conditional rule is editable, and the links to other templates come with it. Most teams install it as it is, run it for a cycle, then adjust.
The agents
What the agents do with it
The form is the easy part. Keeping it current, routing it to the right owner and holding the evidence together is the work that actually slips.
Holds the data protection impact assessment library against your registers, routes each record to its owner, and keeps the evidence trail together.
Coordinates the crew, rolls completion and exceptions into one view, and holds every write for your approval before it touches a record.
This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.
Sources
Sources
- ISO — International Organization for Standardization