{"catalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","download":{"releaseId":"sha256:48c093b98ae22ce49aadb9a2924bac8b409091ae91462aa9299443994adac0cf","slug":"reg-dpia-privacy-impact-assessment","url":"/controls/assets/agent_workflow-reg-dpia-privacy-impact-assessment-e931fa07.bc1bcb9a1a0dd627.json"},"kind":"record","record":{"attributes":{"department":"privacy","domain":"reg","lineOfDefense":"operate"},"canonicalUrl":"https://assureswarm.com/workflows/all/?w=reg-dpia-privacy-impact-assessment","description":"GDPR Article 35 data protection impact assessment as a decision-aware workflow, run on the existing Process item (process_type=business_process) that represents the processing activity under assessment — the Process item doubles as the AssureSwarm proxy for the activity's records-of-processing (RoPA) entry, and the instance enriches it rather than creating a duplicate. It draws on upstream evidence — the RoPA extract, the data inventory and data-flow map, the Article 28 processor arrangements and transfer impact assessment from vendor due diligence, and the security risk assessment for the hosting systems — and moves the activity from screening, through necessity and proportionality and privacy-risk treatment, to a residual-risk decision with Article 36 prior consultation where needed and DPO sign-off. The named deliverable is the signed, versioned DPIA package (or, on the screened-out path, a defensible screening memo), registered against the Process item with tracked mitigation actions; close-and-archive hands that package off to records-of-processing maintenance. In scope: one processing activity (or a set of similar operations with comparable risks per Article 35(1)) from screening through sign-off; out of scope: the related workflows it draws on or feeds — vendor due diligence for new processors, transfer impact assessment for third-country transfers, security risk assessment for the hosting systems, and the records-of-processing maintenance that absorbs the outcome.","details":{"canonicalUrl":"https://assureswarm.com/workflows/all/?w=reg-dpia-privacy-impact-assessment","capabilities":[],"controls":["UC-RISK-16"],"domains":["reg"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:48c093b98ae22ce49aadb9a2924bac8b409091ae91462aa9299443994adac0cf","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:reg-dpia-privacy-impact-assessment","standards":["gdpr"],"teams":["privacy"]},"id":"wf:R8","mapUrl":"https://assureswarm.com/controls/?v=1&node=wf%3AR8","slug":"reg-dpia-privacy-impact-assessment","sourceIds":["gdpr","nist-800-53"],"sourceUrl":null,"title":"DPIA / Privacy Impact Assessment","type":"workflow"},"relationships":[{"expectedCatalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","id":"rel:fda4770d953c7433b9fa2b7a8c84ed8282cfb8848fc14d1dcb93668a0a3f99a5","properties":{},"sourceDetailPath":"/controls/data/v1/records/wf-r8-7a63c8f3.json","sourceId":"wf:R8","targetDetailPath":"/controls/data/v1/records/uc-uc-risk-16-81243062.json","targetId":"uc:UC-RISK-16","type":"operates"}],"schemaVersion":1}
