Compliance

GDPR DPIA Generator

Build a GDPR Article 35 Data Protection Impact Assessment: necessity, proportionality, risk scoring and mitigations. Structured DPIA template, free.

GDPR Data Protection Impact Assessment (DPIA)

Required when processing is likely to result in high risk to individuals' rights and freedoms (GDPR Article 35).

Processing Details

Going for ISO 27001, SOC 2, HIPAA or GDPR?

Radiatus runs end-to-end compliance & GRC programs.

Get a free readiness review

When a DPIA is mandatory

Article 35 of the GDPR requires a Data Protection Impact Assessment when processing is likely to result in a high risk to individuals' rights and freedoms. Three cases are named explicitly: systematic and extensive automated evaluation including profiling that produces legal or similarly significant effects; large-scale processing of special category data or criminal conviction data; and systematic monitoring of a publicly accessible area on a large scale.

Beyond those, supervisory authorities publish their own lists. The EDPB's nine criteria are the working standard: evaluation or scoring, automated decision-making with legal effect, systematic monitoring, sensitive data, large scale processing, matching or combining datasets, data on vulnerable subjects, innovative technological use, and processing that prevents subjects from exercising a right. Meeting two or more usually means a DPIA is expected.

What the assessment has to cover

A systematic description of the processing and its purposes. An assessment of necessity and proportionality relative to those purposes. An assessment of the risks to individuals. And the measures you intend to apply to address those risks, including safeguards and security measures. This generator walks each section and produces a document with all four.

Necessity and proportionality is where DPIAs fail

Most weak DPIAs describe the processing well and then assert it is necessary without argument. The question a regulator asks is whether the same purpose could be achieved with less data, shorter retention, aggregation instead of identification, or an opt-in instead of a default. Recording that you considered the less intrusive option and why you rejected it is what makes the assessment defensible.

Risk scoring

Risks are scored on likelihood and severity from the perspective of the data subject, not the organisation. Reputational damage to your company is not the risk being measured; harm to the individual is. The generator scores each identified risk before and after mitigation so residual risk is visible.

The consultation trigger

If residual risk remains high after mitigation, Article 36 requires prior consultation with your supervisory authority before you begin processing. The generated document flags this when any residual score stays in the high band, because proceeding without consulting is itself an infringement.

A DPIA is a process

The document is the artefact, not the point. A DPIA should start before processing begins, involve the data protection officer where one exists, and be revisited when the processing changes materially. Keep it as a living record.

Frequently Asked Questions

Privacy & Security

Generated locally.

Data: None
Client-side-Side
Active
v1.0

About This Tool

This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.