Knowella

Data Protection Impact Assessment

A DPIA weighs the privacy impact of a new system or monitoring activity before it is introduced - cameras, telematics, biometric access. Its recurring failure is timing: the assessment gets written after the system is already installed, when 'proceed' is no longer a real decision and the document becomes a justification exercise rather than a control. The second is treating consultation as informing people rather than asking them.

KnowComplyAssessmentCMP-03245 fields across 5 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
ISO 27701 cl.7.2
Workspace
KnowComply
Form type
Assessment
Completed by
The privacy lead
Timing
Before implementation - singleton per system, not per event

The short version

  • This is a singleton per system or activity, completed once before implementation and updated as the project moves through its stages - not a periodic record raised on a schedule like most templates in the library.
  • Stage Of The Project is itself scored, and scores lowest for Already live. A DPIA is a pre-implementation control; one written after go-live has already lost its ability to change the system.
  • Necessity, proportionality and the less intrusive alternative are assessed as three separate questions, not one. An activity can be necessary for its purpose and still fail on proportionality or on there being a less intrusive way to achieve it.
  • The template holds 45 fields across 5 sections: header, necessity, risks, safeguards and outcome, and Proceed Recommended can be Yes, With conditions or No - conditions attached to a qualified Yes need to be tracked to closure, not just written down.

What this is

What is a data protection impact assessment?

What is a data protection impact assessment?

A structured assessment, carried out before a new system or monitoring activity is introduced, that tests whether the processing is necessary and proportionate, identifies the risk to the people affected, records the safeguards in place, and reaches a proceed decision. It exists specifically for processing likely to result in high risk to individuals - systematic monitoring, biometric identification, large-scale special category data.

Why is timing central to a DPIA?

Because the assessment is meant to inform whether and how a system is built or bought, not to record that it already has been. A DPIA completed after go-live can still surface risk, but it can no longer change the system's design, and 'proceed' stops being a genuine option - which is why Stage Of The Project is scored, with Already live scoring lowest.

What makes an activity need a DPIA rather than the general processing register?

Novelty and intrusiveness. A processing activity that is already running and understood belongs on the processing register; one that is new, changed materially, or falls into a recognised high-risk category - cameras, telematics, biometrics, automated decisions - needs the impact weighed before it starts, which is what this assessment is for.

Scope

When is a data protection impact assessment required?

This assessment is the pre-implementation step in a larger programme. Using it to log an activity that is already running, or to record what happened after something went wrong, produces a document with the wrong content for either purpose.

Use this template when

  • A new system, camera, monitoring activity or biometric access control is being planned, before purchase or installation
  • An existing system is changing materially - new cameras added to a network, new data fields captured, a new use of existing footage
  • Periodic reassessment of a high-risk activity that is already live, where the trigger is the interval rather than a change
  • You are running the Data Protection and Information Security programme and this is its pre-implementation gate
  • A linked record needs this one to exist: CCTV review, telematics, management of change

Do not use it for

  • Personal Data Processing Record, which logs an activity once it is running, rather than assessing one before it starts.
  • Data Breach Record, which records loss, exposure or unauthorised access after the fact, not the risk of a system before it is introduced.
  • Subject Access Request Record, which records answering an individual's request for data already held.
  • Information Security Risk Assessment, which assesses security risk to the organisation's systems generally, not privacy risk to the individuals a specific activity affects.
  • Anything outside KnowComply, which belongs in the workspace that owns that process

Compliance mapping

Which ISO 27701 cl.7.2 requirements does this satisfy?

ISO/IEC 27701 names the privacy impact assessment directly within its PIMS-specific controls, alongside the equivalent statutory duty most comprehensive privacy regimes impose for high-risk processing specifically, not for processing in general.

ClauseRequirementWhere it lands
ISO 27701 cl.7.2.5Privacy impact assessment carried out for processing likely to result in high risk to individualsHeader
ISO 27701 cl.7.2.2Necessity and lawful basis established before processing beginsNecessity
ISO 27701 cl.7.2.5Risk to the rights and interests of individuals assessed, including function creep and profilingRisks
ISO 27701 cl.7.4.9Safeguards applied to limit access, retention and use to what the assessment justifiesSafeguards
ISO 27701 cl.6.1.2Risk treatment decision recorded, including conditions attached to proceedingOutcome
ISO 27701 cl.5.4Consultation and participation of affected workers in the assessmentHeader

What it does not cover

  • Personal Data Processing Record, which the assessed activity must be added to once it goes live, since the DPIA alone does not create the ongoing inventory entry.
  • Data Breach Record, which applies once the assessed system is running and something goes wrong with it.
  • CCTV and Monitoring Review, which periodically re-examines a live monitoring system's justification, distinct from the one-off pre-implementation assessment.
  • The consultation itself, which is evidenced here but conducted elsewhere - the assessment records that workers were consulted, not the process.
  • Information Security Risk Assessment, which covers security risk to the organisation's systems, separate from the privacy risk this assessment weighs for individuals.

Global

Data Protection Impact Assessment requirements by country

The duty to assess before implementing is narrower than the general processing duty - it applies to processing likely to be high-risk, and the definition of high-risk differs by regime.

United States

State privacy laws requiring data protection assessments (Colorado, Connecticut, CPRA)

No federal DPIA duty; several states require a documented assessment for profiling, targeted advertising, sale of data, or sensitive data including biometrics.

Biometric access control and workplace monitoring fall inside the state assessment triggers even without one nationwide requirement forcing the point.

United Kingdom

UK GDPR Art.35; ICO guidance

DPIA mandatory for processing likely to result in high risk, with the ICO publishing an explicit list including systematic monitoring, biometric data and new technology.

Cameras, telematics and biometric access sit on the ICO's own list - not a matter of interpretation, it is named.

International

EU GDPR Art.35; ISO/IEC 27701 cl.7.2.5

The equivalent duty under EU GDPR, with ISO 27701 providing the certifiable process an auditor checks against for PIMS certification.

A regulator can require the assessment be produced before processing starts - completing one retrospectively does not satisfy the duty even if sound.

How to complete it

How to complete a data protection impact assessment, step by step

The template prompts the right questions in the right order. Whether the answers are honest is a separate matter, and it is where most of the judgement in a DPIA actually sits.

Treat Stage Of The Project as the honesty check

An assessment answered Already live has already conceded that the decision it exists to inform has been made elsewhere. Record that honestly - the finding that matters is not the score, it is why the assessment came after the fact and what will stop that recurring.

Distinguish informed from consulted

Workers Consulted offers Yes, Informed only and No as genuinely different states. Telling people a camera system is being installed is not the same as asking whether it should be, or what would achieve the same purpose with less intrusion - only the latter changes what gets built.

Make Necessary and Proportionate two separate tests, not one

A monitoring activity can be necessary for its purpose - reducing theft - and still be disproportionate in scope, such as recording continuously where spot checks would serve the same purpose. Answering both Yes without engaging Less Intrusive Alternative Considered collapses three questions into a rubber stamp.

Track conditions attached to Proceed Recommended to closure

With conditions is not a softer Yes; it is a Yes contingent on something specific happening - a retention limit shortened, access restricted, a review point brought forward. The Conditions field records what was promised, but nothing checks it was delivered unless it is followed up as an action.

What auditors find

Most common data protection impact assessment findings

DPIA findings concentrate on timing and depth: whether the assessment happened when it could still change something, and whether the risk questions were actually engaged with or answered by pattern.

FindingClauseWhat fixes it
Stage Of The Project recorded as Already live, with the assessment written to justify a decision already taken.ISO 27701 cl.7.2.5Record the timing honestly, and put a trigger in place - purchase approval, installation permit - that forces the assessment before the next system goes live.
Necessary and Proportionate both answered Yes with no record of the less intrusive alternative considered.ISO 27701 cl.7.4.2Require a stated alternative and the reason it was rejected before Proportionate can be marked Yes.
Workers Consulted marked Informed only for a system with direct impact on how they are monitored or accessed.ISO 27701 cl.5.4Distinguish informing from consulting; escalate to genuine consultation where the activity affects individuals directly.
Register Updated left at No after the assessment concluded Proceed, so the processing register never reflects the activity.ISO 27701 cl.7.2.8Make updating the processing register a condition of closing the DPIA, not a task someone remembers later.
Proceed Recommended answered With conditions, but the conditions were never tracked to a CAPA or an owner.ISO 27701 cl.6.1.2Raise an action with an owner and date for every condition attached to a qualified Proceed, and verify before closing.
Automated Decision Making marked N/A for a system that scores access or risk using collected data.ISO 27701 cl.7.2.5Test any scoring, ranking or access-control logic against the definition before marking N/A.

Case in point

Case in point: the DPIA that arrived after the cameras

A logistics site fitted in-cab telematics to cut fuel use and support insurance renewal. The DPIA was raised three weeks after the units were installed and drivers had started seeing behaviour scores in the app, at the point compliance noticed no assessment existed. Necessity and proportionality were both marked Yes; Stage Of The Project was recorded, honestly, as Already live.

Drivers raised a formal grievance over the scoring feature two months later, arguing it had been introduced without consultation and used for more than fuel efficiency - feeding into performance conversations nobody had disclosed. The DPIA, written after the fact, had nothing to say about that use, because the system was already built around it by the time anyone assessed it. Fleet and vehicle changes now route through a DPIA gate before procurement is approved, not after the units arrive.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

45fields
5 sections
Reference
CMP-032
Archetype
Assessment
Record ID
DPIA-2026-000
Scoring
Assessments complete
Direction
High is good
Singleton
Yes
Basis
ISO 27701 cl.7.2
Links
Links CCTV review, Telematics, MOC
Tags
Privacy, Assessment
Sections
5
Fields
45
Follow up fields
3
Repeating sections
0
Links out
2
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

13 fields
Text

Assessment ID*

Generated on save

Auto sequence. Format DPIA-2026-000.

The record's own ID. Other templates point at this value.

Single Choice

Status*

Scored

Drives who this goes to next.

  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts
Date & Time

Date and Time*

Users

Completed By*

Pick List

Site*

From FDN-001 Site NameFilter: Status is Active
Text

Site ID*

Linked

Format SITE-000.

Links to FDN-001 Site ID

Text

System Or Activity*

Single Choice

Assessment Trigger*

ComplaintPermit requirementPlant changePeriodicNew installationAfter an incident
Users

Assessed By*

Single Choice

Stage Of The Project*

Scored
  • Before purchase4 pts
  • Before installation3 pts
  • Before go live2 pts
  • Already live0 pts
Single Choice

Workers Consulted*

Scored
  • Yes3 pts
  • Informed only1 pt
  • No0 pts
Single Choice

Privacy Lead Involved*

Scored
  • Yes3 pts
  • No0 pts
Info

Cameras, Telematics And Biometrics All Need One

The systems that most improve safety are also the ones that most intrude. Assessing that before installation is both a legal requirement and the way to keep trust.

Necessity

6 fields
Single Choice

Purpose Clearly Defined*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Necessary For The Purpose*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Proportionate To The Purpose*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Less Intrusive Alternative Considered*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Lawful Basis Identified*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Scope Limited To What Is Needed*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts

Risks

6 fields
Single Choice

Intrusion On Workers Assessed*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Function Creep Risk Assessed*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Data Security Risk Assessed*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Accuracy Risk Assessed*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Automated Decision Making Involved*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Effect On Trust Considered*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts

Safeguards

6 fields
Single Choice

Access Restricted And Logged*

Scored
  • Yes3 pts
  • Restricted only1 pt
  • No0 pts
Single Choice

Retention Period Limited*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Anonymisation Or Aggregation Used*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Transparency To Workers Provided*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Not Used For Unrelated Purposes*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Review Point Set*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts

Outcome

14 fields
Single Choice

Residual Privacy Risk*

Scored
  • Low3 pts
  • Medium1 pt
  • High0 pts
Single Choice

Proceed Recommended*

Scored
  • Yes3 pts
  • With conditions2 pts
  • No0 pts
Text

Conditions

Optional
Single Choice

Register Updated*

Scored
  • Yes3 pts
  • No0 pts
Single Choice

Consultation Feedback Addressed*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Date & Time

Review Date*

Single Choice

Action Required*

Scored

Raise the action record, then enter its reference here.

  • No2 pts
  • Yes0 pts
Single Choice

Priority

OptionalScoredShows if Action Required equals Yes
  • High0 pts
  • Medium1 pt
  • Low3 pts
Text

CAPA ID

OptionalLinkedShows if Action Required equals Yes

Format CAPA-2026-00000.

Links to FDN-014 CAPA ID

Users

Action Owner

OptionalShows if Action Required equals Yes
Users

Privacy Lead*

Signature

Signature*

Users

Site Manager*

Signature

Second Signature*

CMP-032 · record IDs look like DPIA-2026-000 · Links CCTV review, Telematics, MOC

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

The assessment itself is a one-time document. What fails is the gate around it - the purchase that proceeds before the DPIA is written, and conditions attached to a qualified Yes that nobody tracks.

KnowComply

Holds the DPIA against the processing register and retention schedule, and flags when Proceed Recommended closes without the corresponding register entry being added.

KnowFleet

Surfaces telematics and vehicle monitoring proposals early enough to route them through the DPIA gate before procurement.

KnowSafe

Flags new camera and access-control installations at planning stage, so Stage Of The Project can genuinely be Before purchase.

Ella
Ella

Tracks conditions attached to a qualified Proceed through to closure, and prompts the review date rather than leaving it to expire unnoticed.

This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.

Meet KnowComply→

Glossary

Data Protection Impact Assessment definitions and key terms

Data protection impact assessment
A pre-implementation assessment of the privacy risk a new system or activity poses to individuals, required specifically for processing likely to result in high risk.
Necessity and proportionality
Two distinct tests: whether the processing is required to achieve the purpose, and whether its scope and intrusiveness are no more than the purpose justifies.
Residual privacy risk
The risk remaining once identified safeguards are applied - the figure the proceed decision is actually made against, not the raw risk before safeguards.
Function creep
A system used beyond the purpose it was assessed and introduced for, such as fuel-efficiency telematics later feeding into disciplinary decisions.
Data minimisation
Collecting and retaining no more data than the stated purpose requires - the principle behind Scope Limited To What Is Needed and Retention Period Limited.

FAQ

Frequently asked questions about data protection impact assessment

When does a DPIA need to be done rather than just logging on the processing register?+

When the activity is new, has changed materially, or falls into a recognised high-risk category - systematic monitoring, biometric identification, automated decisions, large-scale special category data. An established, low-risk activity belongs on the processing register; a new camera network or biometric access system needs the impact weighed first.

What if the system is already live when someone realises a DPIA was never done?+

Complete it, and record Stage Of The Project as Already live honestly rather than backdating it. Treat the gap itself as a finding, and fix the trigger so the next system reaches go-live assessed, not this one retrospectively cleared.

Is informing workers the same as consulting them?+

No. Workers Consulted distinguishes Yes from Informed only precisely because they produce different assessments - consultation can surface a less intrusive alternative or a use nobody had considered, while informing only confirms the decision has already been made.

What does Proceed With conditions actually commit the organisation to?+

Whatever is written in the Conditions field - a retention limit, restricted access, a review point - and those conditions need an owner and a date to be delivered, not just a note. Without that, With conditions functions as an unconditional Yes.

Does completing the DPIA update the processing register automatically?+

No. Register Updated is a separate field - the assessment and the register are different records, and an activity can pass its DPIA and still never reach the register if closing the assessment isn't treated as the trigger.

How is residual risk different from the risk assessed under Risks?+

The Risks section evaluates intrusion, function creep, security, accuracy and trust before safeguards are applied. Residual Privacy Risk in the Outcome section is what remains once the Safeguards section's controls are counted - the figure the proceed decision is actually made against.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

  • ISO 27701:2019 cl.7.2.5
  • UK GDPR Article 35; ICO guidance on when a DPIA applies
  • EU GDPR Article 35
  • Article 29 Working Party guidelines on DPIA (WP248)

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.