GDPR DPIA Generator
Build a GDPR Article 35 Data Protection Impact Assessment: necessity, proportionality, risk scoring and mitigations. Structured DPIA template, free.
Last reviewed by the Radiatus Cloud team
GDPR Data Protection Impact Assessment (DPIA)
Required when processing is likely to result in high risk to individuals' rights and freedoms (GDPR Article 35).
Processing Details
DPIA Required?
Required Actions
Mitigation Measures
Going for ISO 27001, SOC 2, HIPAA or GDPR?
Radiatus runs end-to-end compliance & GRC programs.
When a DPIA is mandatory
Article 35 of the GDPR requires a Data Protection Impact Assessment when processing is likely to result in a high risk to individuals' rights and freedoms. Three cases are named explicitly: systematic and extensive automated evaluation including profiling that produces legal or similarly significant effects; large-scale processing of special category data or criminal conviction data; and systematic monitoring of a publicly accessible area on a large scale.
Beyond those, supervisory authorities publish their own lists. The EDPB's nine criteria are the working standard: evaluation or scoring, automated decision-making with legal effect, systematic monitoring, sensitive data, large scale processing, matching or combining datasets, data on vulnerable subjects, innovative technological use, and processing that prevents subjects from exercising a right. Meeting two or more usually means a DPIA is expected.
What the assessment has to cover
A systematic description of the processing and its purposes. An assessment of necessity and proportionality relative to those purposes. An assessment of the risks to individuals. And the measures you intend to apply to address those risks, including safeguards and security measures. This generator walks each section and produces a document with all four.
Necessity and proportionality is where DPIAs fail
Most weak DPIAs describe the processing well and then assert it is necessary without argument. The question a regulator asks is whether the same purpose could be achieved with less data, shorter retention, aggregation instead of identification, or an opt-in instead of a default. Recording that you considered the less intrusive option and why you rejected it is what makes the assessment defensible.
Risk scoring
Risks are scored on likelihood and severity from the perspective of the data subject, not the organisation. Reputational damage to your company is not the risk being measured; harm to the individual is. The generator scores each identified risk before and after mitigation so residual risk is visible.
The consultation trigger
If residual risk remains high after mitigation, Article 36 requires prior consultation with your supervisory authority before you begin processing. The generated document flags this when any residual score stays in the high band, because proceeding without consulting is itself an infringement.
A DPIA is a process
The document is the artefact, not the point. A DPIA should start before processing begins, involve the data protection officer where one exists, and be revisited when the processing changes materially. Keep it as a living record.
Related tools
- SOC 2 Evidence Readiness — Interactive checklist to gauge your SOC 2 evidence readiness.
- Privacy Policy Checker — Check if your policy covers standard requirements (GDPR/CCPA basics).
- Compliance Req Finder — Find which standards (ISO, SOC2, HIPAA) apply to your industry/region.
- Audit Readiness Planner — Plan your compliance audit timeline (SOC2, ISO) backwards from deadline.
Frequently Asked Questions
When is a DPIA legally required?
When processing is likely to result in high risk to individuals, which Article 35 illustrates with systematic automated evaluation with significant effects, large-scale special category data, and large-scale systematic monitoring of public areas. Supervisory authorities publish additional mandatory lists, and the EDPB's nine criteria are the practical test: meeting two or more generally means you need one.
Who should carry out the DPIA?
The controller is responsible. Where a data protection officer is appointed, you must seek their advice and record it. In practice the assessment is usually drafted by whoever owns the processing activity with input from security, legal and engineering.
What happens if residual risk stays high?
Article 36 requires prior consultation with your supervisory authority before starting the processing. They have up to eight weeks, extendable by six, to respond. Beginning without consulting when required is itself an infringement, so the flag matters.
Does a DPIA need to be published?
No. There is no obligation to publish, though the ICO and others encourage publishing a summary for transparency where the processing affects the public. You must be able to produce it for your supervisory authority on request.
How is a DPIA different from a record of processing activities?
A ROPA under Article 30 is an inventory of all processing you carry out. A DPIA is a deep risk assessment of one specific high-risk activity. The ROPA tells you what you do; the DPIA examines whether one particular thing is safe to do.
When should a DPIA be updated?
Whenever the nature, scope, context or purposes of the processing change materially, and as a periodic review even when they do not. Adding a new data source, a new vendor, or an automated decision step all warrant revisiting the assessment.
Privacy & Security
Generated locally.
About This Tool
This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
SOC 2 Evidence Readiness
ComplianceInteractive checklist to gauge your SOC 2 evidence readiness.
Privacy Policy Checker
ComplianceCheck if your policy covers standard requirements (GDPR/CCPA basics).
Compliance Req Finder
ComplianceFind which standards (ISO, SOC2, HIPAA) apply to your industry/region.