workflow

DPIA / Privacy Impact Assessment

GDPR Article 35 data protection impact assessment as a decision-aware workflow, run on the existing Process item (process_type=business_process) that represents the processing activity under assessment — the Process item doubles as the AssureSwarm proxy for the activity's records-of-processing (RoPA) entry, and the instance enriches it rather than creating a duplicate. It draws on upstream evidence — the RoPA extract, the data inventory and data-flow map, the Article 28 processor arrangements and transfer impact assessment from vendor due diligence, and the security risk assessment for the hosting systems — and moves the activity from screening, through necessity and proportionality and privacy-risk treatment, to a residual-risk decision with Article 36 prior consultation where needed and DPO sign-off. The named deliverable is the signed, versioned DPIA package (or, on the screened-out path, a defensible screening memo), registered against the Process item with tracked mitigation actions; close-and-archive hands that package off to records-of-processing maintenance. In scope: one processing activity (or a set of similar operations with comparable risks per Article 35(1)) from screening through sign-off; out of scope: the related workflows it draws on or feeds — vendor due diligence for new processors, transfer impact assessment for third-country transfers, security risk assessment for the hosting systems, and the records-of-processing maintenance that absorbs the outcome.

Record JSON · Open in map · Data retrieval guide

Catalog revision: f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e. A connection does not establish full coverage.

Attributes

domain
reg
department
privacy
lineOfDefense
operate

Details

teams
  • privacy
domains
  • reg
standards
  • gdpr
sourceTemplateId
workflow-library:reg-dpia-privacy-impact-assessment
releaseId
sha256:48c093b98ae22ce49aadb9a2924bac8b409091ae91462aa9299443994adac0cf
canonicalUrl
https://assureswarm.com/workflows/all/?w=reg-dpia-privacy-impact-assessment
capabilities
    mappingStatus
    mapped
    lineOfDefense
    operate
    controls
    • UC-RISK-16
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:48c093b98ae22ce49aadb9a2924bac8b409091ae91462aa9299443994adac0cf

            Connections