Compliance

GDPR DPIA Generator

Build a GDPR Article 35 Data Protection Impact Assessment: necessity, proportionality, risk scoring and mitigations. Structured DPIA template, free.

Last reviewed by the Radiatus Cloud team

GDPR Data Protection Impact Assessment (DPIA)

Required when processing is likely to result in high risk to individuals' rights and freedoms (GDPR Article 35).

Processing Details

Going for ISO 27001, SOC 2, HIPAA or GDPR?

Radiatus runs end-to-end compliance & GRC programs.

Get a free readiness review

When a DPIA is mandatory

Article 35 of the GDPR requires a Data Protection Impact Assessment when processing is likely to result in a high risk to individuals' rights and freedoms. Three cases are named explicitly: systematic and extensive automated evaluation including profiling that produces legal or similarly significant effects; large-scale processing of special category data or criminal conviction data; and systematic monitoring of a publicly accessible area on a large scale.

Beyond those, supervisory authorities publish their own lists. The EDPB's nine criteria are the working standard: evaluation or scoring, automated decision-making with legal effect, systematic monitoring, sensitive data, large scale processing, matching or combining datasets, data on vulnerable subjects, innovative technological use, and processing that prevents subjects from exercising a right. Meeting two or more usually means a DPIA is expected.

What the assessment has to cover

A systematic description of the processing and its purposes. An assessment of necessity and proportionality relative to those purposes. An assessment of the risks to individuals. And the measures you intend to apply to address those risks, including safeguards and security measures. This generator walks each section and produces a document with all four.

Necessity and proportionality is where DPIAs fail

Most weak DPIAs describe the processing well and then assert it is necessary without argument. The question a regulator asks is whether the same purpose could be achieved with less data, shorter retention, aggregation instead of identification, or an opt-in instead of a default. Recording that you considered the less intrusive option and why you rejected it is what makes the assessment defensible.

Risk scoring

Risks are scored on likelihood and severity from the perspective of the data subject, not the organisation. Reputational damage to your company is not the risk being measured; harm to the individual is. The generator scores each identified risk before and after mitigation so residual risk is visible.

The consultation trigger

If residual risk remains high after mitigation, Article 36 requires prior consultation with your supervisory authority before you begin processing. The generated document flags this when any residual score stays in the high band, because proceeding without consulting is itself an infringement.

A DPIA is a process

The document is the artefact, not the point. A DPIA should start before processing begins, involve the data protection officer where one exists, and be revisited when the processing changes materially. Keep it as a living record.

Related tools

Frequently Asked Questions

When is a DPIA legally required?

When processing is likely to result in high risk to individuals, which Article 35 illustrates with systematic automated evaluation with significant effects, large-scale special category data, and large-scale systematic monitoring of public areas. Supervisory authorities publish additional mandatory lists, and the EDPB's nine criteria are the practical test: meeting two or more generally means you need one.

Who should carry out the DPIA?

The controller is responsible. Where a data protection officer is appointed, you must seek their advice and record it. In practice the assessment is usually drafted by whoever owns the processing activity with input from security, legal and engineering.

What happens if residual risk stays high?

Article 36 requires prior consultation with your supervisory authority before starting the processing. They have up to eight weeks, extendable by six, to respond. Beginning without consulting when required is itself an infringement, so the flag matters.

Does a DPIA need to be published?

No. There is no obligation to publish, though the ICO and others encourage publishing a summary for transparency where the processing affects the public. You must be able to produce it for your supervisory authority on request.

How is a DPIA different from a record of processing activities?

A ROPA under Article 30 is an inventory of all processing you carry out. A DPIA is a deep risk assessment of one specific high-risk activity. The ROPA tells you what you do; the DPIA examines whether one particular thing is safe to do.

When should a DPIA be updated?

Whenever the nature, scope, context or purposes of the processing change materially, and as a periodic review even when they do not. Adding a new data source, a new vendor, or an automated decision step all warrant revisiting the assessment.

Privacy & Security

Generated locally.

Data: None
Client-side-Side
Active
v1.0

About This Tool

This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.