PRIVASTU Command Center

Branded intelligence workspace for the full PRIVASTU operating model

Super Admin
โ— System healthy
โšก
๐Ÿ”ดAI Recruitment Screening DPIA is 4 days overdue. Art 35(3)(a) trigger confirmed - DPO consultation required immediately. View โ†’
1/6
โ–ฃ Healthy
Processing Activities
14
โ†‘ +2 this month
๐Ÿ‘ค On track
Active DSARs
3
โ†‘ 0 overdue
โ–ฅ Attention
Vendors tracked
24
โš  3 high risk
โ–ค Action
Open assessments
7
โš  1 overdue
โš  Attention
Open incidents
3
โš  1 critical
๐ŸŽ“ Healthy
Training completion
91%
โ†‘ +3% MoM
โ‰ฃ Attention
Policies due review
4
โš  2 overdue
โœ“ Healthy
Consent records
8420
โ†‘ Active

Privacy Risk Radar

Live cross-module risk distribution
Data Mapping 88
DSAR 94
Vendors 62
Assessments 58
Policies 71
Retention 74
AI Governance 66
Training 91
Incidents 70

Privacy Maturity Score

Composite across 9 governance modules
72
/100
Data Mapping 88%
DSAR 94%
Vendors 62%
Assessments 58%
Policies 71%

Activity Timeline

Recent actions and system events
๐Ÿ‘ค
New request received DSAR
Today 09:14
Mila Schneider - Rectification (Germany)
โ–ค
DPIA status updated Assessments
Today 08:55
Smart CCTV - moved to Mitigation Planning
โ–ฅ
Vendor review due Vendors
Yesterday 16:30
Cloud AI Labs DPA flagged for renewal
โš 
Incident escalated Incidents
Yesterday 14:12
INC-1444 - improper access escalated to Critical
๐ŸŽ“
Module completed Training
21 Mar 11:00
DSAR Handling for HR - 74/82 completions
โš 
Assessment overdue Assessments
21 Mar 09:30
AI Recruitment Screening DPIA - 4 days past due
โ–ฃ
Processing record updated Data Mapping
20 Mar 15:44
Behavioural Analytics - risk score revised to HIGH
โ‰ฃ
Policy review approaching Policies
20 Mar 10:22
DSAR Handling Standard - due 30 Mar

DSAR Pipeline

Active requests by status and urgency
2
Processing
1
Pending
0
Completed
Alex Morgan
PRIV-DSAR-001 ยท Access ยท UK
Processing
10 days remaining
Claire Dubois
PRIV-DSAR-002 ยท Erasure ยท France
Pending
21 days remaining
Mila Schneider
PRIV-DSAR-003 ยท Rectification ยท Germany
Processing
23 days remaining

Horizon Watchlist

Top signals from Scan my Horizon
Children-data transfer exposure
2 RoPA records + active cross-border transfers.
Threats ยท RoPA + Vendors
Critical
AI DPIA overdue
Recruitment AI - no completed DPIA. Art 35(3)(a).
Threats ยท Assessments
Critical
Vendor DPA hygiene gaps
2 high-risk processors with stale DPAs.
Weaknesses ยท Vendors
High
EU AI Act readiness gap
3 AI systems may need FRIA by Aug 2026.
PESTLE ยท AI + Assessments
High
Retention drift in 4 records
Deletion timelines missing - minimisation risk.
Weaknesses ยท RoPA
Medium

Module Health

Click any module to navigate
Data Mapping
88
2 issues
DSAR Manager
94
No issues
Vendors
62
3 issues
Assessments
58
4 issues
Policies
71
2 issues
Retention
74
2 issues
AI Governance
66
2 issues
Training
91
No issues
Incidents
70
1 issue
Global Data Sovereignty Map
Live 3D ยท Click nodes ยท Scroll to zoom ยท Drag to rotate
12visible points
6high risk
1critical
10mapped flows
Map intelligence
Low Moderate
High Critical
Solid route = controlled ยท dashed = review
๐Ÿ”€
Model my Data Map
Visual flow modeler ยท query your estate ยท compliance intelligence
10
Assets
11
Flows
8
High risk
Intelligent query shortcuts

Global Geographic Intelligence Console

Infrastructure, AI, physical routes, sovereignty, resilience, incidents and accountability in one governed layer

Visible points12
High / critical6
Countries12
Single points of failure4

Ask the globe

Select layers or ask a geographic governance question.
2026

Scenario simulation

No scenario active.

Priority geographic signals

Open AI Transfer Finding ยท 86Unresolved transfer evidence and provider-change exposure
LEO AI Telemetry Satellite ยท 74Onboard anomaly detection ยท signed telemetry ยท ground-controlled keys
Virginia Foundation Model Endpoint ยท 72External LLM API ยท transfer and subprocessor controls
Cape Town Warm Disaster Recovery ยท 67Encrypted recovery copies ยท tested restoration required
Singapore Edge Inference ยท 61Local intent classification and minimisation
Frankfurt High-Risk Cluster ยท 58Restricted Annex III workloads

Dashboard Map Intelligence Workspace

Operational map register, dependencies, transfer mechanisms, alerts and board-ready outputs

Global pointsGoverned estate

Cloud, AI, satellite, security, recovery and regulatory locations.

Highest exposureExternal model route

Provider, transfer and subprocessor evidence requires continuous validation.

Resilience focus4 dependencies

Model, HSM, cloud region and ground station require tested fallback.

Governance linkageLive routing

Use the map to navigate into AI Infrastructure and related governance workflows.

ActionPointTypeRiskYear
Open AI Transfer Finding
Unresolved transfer evidence and provider-change exposure
incident862026
LEO AI Telemetry Satellite
Onboard anomaly detection ยท signed telemetry ยท ground-controlled keys
satellite742026
Virginia Foundation Model Endpoint
External LLM API ยท transfer and subprocessor controls
model722025
Cape Town Warm Disaster Recovery
Encrypted recovery copies ยท tested restoration required
recovery672026
Singapore Edge Inference
Local intent classification and minimisation
edge612026
Frankfurt High-Risk Cluster
Restricted Annex III workloads
datacentre582025
GEO Communications Satellite
Network telemetry and service optimisation
satellite482025
Svalbard Ground Station
Downlink relay ยท EEA processing ยท secondary station required
ground462024
Dublin Vector and Data Zone
RAG corpus, embeddings and feature stores
datacentre392024
London Confidential Compute
Private inference ยท UK-only sensitive workloads
datacentre262024
Cardiff HSM and Key Trust Anchor
FIPS HSM ยท signing and approval tokens
hsm232024
London AI Security Operations Centre
Prompt attacks, agent actions and exfiltration monitoring
soc222025
FlowDataMechanismRiskStatus
External model inferencePrompts, retrieved context and outputsIDTA and transfer assessment78Review required
Human review escalationFlagged AI decisions and evidenceContractual safeguards62Assessment open
APAC minimised inferenceTokenised intent and metadataIDTA61Review required
AI security monitoringLogs, alerts and agent actionsUK-EU safeguards55Evidence due
Identity and access federationUser and role attributesProcessor contract49Monitored
Ground processing routeOperational telemetry and diagnosticsEEA processing46Monitored
Satellite telemetry downlinkSigned telemetry and anomaly eventsEEA route42Monitored
Disaster recovery replicationEncrypted backups and configurationsApproved recovery route38Tested
UK to EU RAG replicationKnowledge corpus and embeddingsUK-EU adequacy28Controlled
Key and signing trustEncryption keys and approval tokensDomestic18Controlled
Open AI Transfer Finding ยท 86
Unresolved transfer evidence and provider-change exposure
LEO AI Telemetry Satellite ยท 74
Onboard anomaly detection ยท signed telemetry ยท ground-controlled keys
Virginia Foundation Model Endpoint ยท 72
External LLM API ยท transfer and subprocessor controls
Cape Town Warm Disaster Recovery ยท 67
Encrypted recovery copies ยท tested restoration required
Singapore Edge Inference ยท 61
Local intent classification and minimisation
Frankfurt High-Risk Cluster ยท 58
Restricted Annex III workloads

Cross-Module Risk Heat Map

Where risk converges across the estate
TransferChildrenAI/AutoData Vol.RetentionVendorIncidentRights
RoPA
H
L
H
M
L
M
L
M
DSAR
L
M
L
L
L
L
H
H
Vendors
H
L
H
M
L
H
M
L
Assessments
M
M
M
H
M
L
L
M
Policies
L
L
L
L
H
L
L
L
Retention
M
L
L
L
M
L
L
L
AI
M
L
H
H
L
M
L
M
Incidents
M
H
M
L
L
L
H
M
High Medium Low

Programme Trends

6-month rolling view

Regulatory Calendar

Key dates and obligations
AI Recruitment DPIA overdue
25 Mar 2026 ยท EU / UK
DSAR Handling Standard review due
31 Mar 2026 ยท UK
Global Privacy Essentials training deadline
31 Mar 2026 ยท Global
Master Privacy Policy annual review
15 Apr 2026 ยท Global
EU AI Act - high-risk AI system requirements apply
01 Aug 2026 ยท EU
UK GDPR reform - potential divergence from EU
01 Jan 2027 ยท UK

Data Mapping

RoPA ยท Discovery ยท Information Assets ยท AI Copilot ยท Regulator Fit ยท 7 modules

PRIVASTU ยท Information Asset Register

Know every asset. Map every flow. Control every risk.

Automatically discover, classify and map all information assets across your organisation. Linked in real time to your RoPA records, vendor register, assessments and incidents - the single source of truth for what data you hold, where and why.

10
Total assets
In register
3
Critical risk
Immediate action
1
Shadow / unknown
Undocumented stores
4
No RoPA record
Not mapped to RoPA
2
Retention gap
No or overdue policy
4
Proposed new
From last scan
AssetTypeOwnerClassification Personal dataRiskSource system RoPAVendorLast scannedActions
Employee Lifecycle ManagementHRRecruitment, payroll, performanceContract / legal obligationEmployeesUK - US SCCsMediumActive
Marketing CRMMarketingLead generation and campaignsConsent / legitimate interestsProspectsEEA - USHighReview
Security MonitoringIT & SecurityThreat detection and incident responseLegitimate interestsEmployees / contractorsNoMediumActive
Customer Support Case HandlingOperationsService resolution and QAContractCustomersEEA - IndiaMediumDraft

Discovery Scan Engine

AppMap-style automated PII & asset discovery

Connect your systems and PRIVASTU automatically discovers personal data, classifies sensitivity, maps data flows and proposes RoPA records. Powered by pattern recognition, schema analysis and AI-assisted classification.

โ˜
Salesforce
Last scan: 21 Mar 2026 ยท 3 assets found
Connected
๐Ÿ‘ฅ
Workday
Last scan: 21 Mar 2026 ยท 4 assets found
Connected
โ„
Snowflake
Last scan: 21 Mar 2026 ยท 12 assets found
Connected
๐Ÿ”ท
Microsoft 365
Last scan: 21 Mar 2026 ยท 8 assets found
Connected
๐Ÿชฃ
AWS S3
Last scan: 20 Mar 2026 ยท 6 assets found
Partial
๐Ÿ“
Network file shares
Last scan: Never ยท 0 assets found
Pending

Scheduled Scans

Full estate scanWeekly ยท Sundays 02:00
New data type detectionDaily ยท 06:00
Transfer path monitoringContinuous
Shadow data detectionWeekly ยท Wednesdays 03:00

Discovery Findings

Last scan: 21 Mar 2026 ยท 06:14
๐Ÿ”ด
Legacy CRM discovered with ~200K unencrypted records - no owner, no RoPA, no retention policy
Critical
๐Ÿ”ด
PII (CV data, biometric) flowing to Cloud AI Labs without completed TRA or DPIA
Critical
๐ŸŸก
Production PII (customer emails) found in Snowflake development schema - 3 columns unmasked
High
๐ŸŸก
HR file share (\\server01\HR) contains salary spreadsheets and medical certificates - no RBAC
High
๐ŸŸก
Workday health data found in test environment - not masked or anonymised
High
๐Ÿ”ต
Slack workspace - 18-month message retention includes employee personal data - not in RoPA
Medium
๐Ÿ”ต
OneDrive personal folders - shadow PII in unmanaged documents - no policy applied
Medium

Proposed New Assets

Discovered but not yet in register
AWS S3 - analytics-raw-prod
File Store ยท S3 bucket scan found email addresses and device IDs
94% match
Slack workspace messages
Email System ยท Collaboration platform - message retention and employee data
87% match
Jira / Confluence
SaaS Application ยท Project management with employee personal data in issues
78% match
Network file share \\server01\HR
File Store ยท HR folder detected - contains payroll spreadsheets and medical certificates
96% match

Data Flow Map

How personal data moves across your asset estate
From To Type Data Freq. Risk Cross-border Documented
Salesforce CRM Snowflake DW Scheduled ETL Customer records, behavioural Daily Medium No โœ“
Workday HRIS Payroll Provider API push Salary, bank details, personal data Monthly High โš  Yes โœ“
Website Google Analytics 4 JavaScript tag Behavioural, location, device ID Real-time Medium โš  Yes โœ“
Salesforce CRM Mailchimp Integration Customer email, name, preferences Real-time sync Medium โš  Yes โœ“
Workday HRIS Cloud AI Labs Batch export CV data, contact details, assessments Per recruitment cycle Critical โš  Yes โœ— NOT DOCUMENTED
Unknown legacy CRM Unknown destination Unknown Unknown PII Unknown Critical No โœ— NOT DOCUMENTED
Snowflake DW BI tool (Tableau) Direct query Customer analytics with PII columns Ad hoc High No โœ— NOT DOCUMENTED
โš  3 undocumented flows ยท 4 cross-border transfers ยท 2 critical-risk flows

Transfer Risk Summary

๐Ÿ”ดCV/biometric data flowing to Cloud AI Labs (US) - no TRA, no DPIA
๐ŸŸกCustomer data to Mailchimp (US) via SCCs - verify Article 46 mechanism currency
๐ŸŸกEmployee data to Workday (US) via SCCs - DPA expiry: Dec 2026
๐ŸŸกAnalytics to Google Analytics 4 (US) via DPF - monitor DPF validity

Data Flow Anomalies

Unexpected or undocumented flows detected
๐Ÿ”ด
Legacy CRM โ†’ unknown destination: uncharted flow, unknown data types
First detected: 21 Mar
๐Ÿ”ด
Snowflake dev schema receiving production PII - unexpected flow
First detected: 19 Mar
๐ŸŸก
Workday โ†’ external payroll: batch export not on DPA schedule
First detected: 15 Mar

Classification Framework

Confidential
Personal data, financial data, health data, credentials, biometrics
8
Restricted
Payment data, authentication tokens, legal documents, sensitive contracts
2
Internal
Business-internal information, aggregated analytics, operational data
0
Public
Publicly available information, marketing content, published records
0

PII Detection Patterns

AI-powered field recognition (Concentric-style)
Email address
Validated email format
99%
8 assets
UK National Insurance No.
[A-Z]{2}[0-9]{6}[A-D]
98%
2 assets
Payment card number (PAN)
Luhn-validated 16-digit
97%
3 assets
Date of birth
DOB / birth_date field name + date pattern
95%
5 assets
IP address
IPv4/IPv6 pattern
99%
6 assets
UK phone number
+44 / 07xx pattern
94%
4 assets
Sort code + account number
NN-NN-NN + 8 digits
96%
2 assets
Location coordinates
lat/lon field names + numeric range
91%
3 assets

Unclassified Assets

Assets pending classification review
All assets have been classified. โœ“
3
Critical assets
6
High-risk assets
3
Undocumented flows
14
Anomalies detected

Asset Risk Matrix

Likelihood ร— Impact across asset estate
Assets plotted by risk rating
High impactMed impactLow impactMinimal
High likelihood
3
6
1
Medium likelihood
3
6
1
Low likelihood
6
1
Very low
6
1

High-Risk Assets

AI Recruitment Screening Model
AI / ML Model
91
Legacy CRM (pre-2020)
Database
88
Workday HRIS
SaaS Application
84
Snowflake Data Warehouse
Data Warehouse
78
PRIVASTU Document Archive
Backup / Archive
74
Salesforce Production CRM
SaaS Application
72

Shadow Data Exposure

Undocumented or overlooked data stores
Google Analytics 4Active
Behavioural / analytics ยท Location data
Legacy CRM (pre-2020)Shadow / Unknown
Name / contact details ยท Financial data ยท Behavioural / analytics

Retention Compliance

Assets with missing, exceeded, or undocumented retention periods
Asset Retention policy Status Action
AI Recruitment Screening Model Not defined - action needed โš  Missing
PRIVASTU Document Archive Varies by document type โš  Missing
Legacy CRM (pre-2020) No policy - OVERDUE โš  OVERDUE

Asset Type Library

Pre-built templates for common information asset types. Use as starting points for your asset register - each template includes recommended classification, typical PII types and standard risk indicators.

๐Ÿ—„
Production Database
Confidential High risk
Typical PII
Customer/employee PII ยท Financial data
Key controls
Encryption at restAccess controlsAudit loggingBackup & DR
High risk - likely requires RoPA record and possible DPIA. Ensure retention policy defined.
โ˜
SaaS CRM Platform
Confidential High risk
Typical PII
Customer data ยท Contact data ยท Commercial data
Key controls
DPA requiredSSO/MFAIP allowlistExport controls
Likely processor relationship. Verify SCCs/IDTA for non-EEA processing. Check sub-processors.
๐Ÿ‘ฅ
HR / People System
Confidential Critical risk
Typical PII
Employee data ยท Salary ยท Health data ยท Biometric data
Key controls
Strict RBACDedicated DPAHR-only accessRetention schedules
Special category data likely. Legal basis per Art. 9 required. DPA and transfer mechanism mandatory.
โ„
Data Warehouse / Analytics
Confidential High risk
Typical PII
Aggregated PII ยท Behavioural data ยท Financial analytics
Key controls
Column-level encryptionRow-level securityMasking for dev/testRetention enforcement
High risk of PII in test/dev environments. Minimisation critical. Profiling rules may apply.
๐Ÿค–
AI / ML Model
Confidential Critical risk
Typical PII
Training data (PII) ยท Inference inputs ยท Model outputs on individuals
Key controls
DPIA requiredHuman oversightExplainabilityBias testingFRIA (EU AI Act)
Art. 22 ADM obligations likely. DPIA mandatory. EU AI Act may require FRIA. No autonomous decisions without safeguards.
๐Ÿ“ง
Email / Collaboration System
Confidential Medium risk
Typical PII
Employee data ยท Customer correspondence ยท Attachments (unknown PII)
Key controls
Retention policyLegal hold capabilityDLPContent scanning
Often underestimated. Unstructured PII in emails. Retention and litigation hold must be balanced.
๐Ÿ’ณ
Payment / Financial System
Restricted High risk
Typical PII
Payment card data ยท Bank details ยท Transaction records
Key controls
PCI DSS complianceTokenisationNo raw card storageStrict access
Financial data is highly sensitive. PCI DSS alongside GDPR. Retention driven by tax/audit law.
๐Ÿ“
File Server / SharePoint
Internal Medium risk
Typical PII
Unstructured PII (unknown) ยท HR documents ยท Customer files
Key controls
Folder-level RBACDLP scanningPeriodic auditsAuto-classification
Highest source of shadow PII. Scan regularly. Apply auto-classification and retention tags.
๐Ÿ“ฆ
Backup / Archive System
Confidential Medium risk
Typical PII
Mirrors of all above ยท Historical PII
Key controls
Encrypted backupsGeo-restrictedDefined retentionTested restore
Erasure requests must include backups. Document backup retention separately from live system.
๐Ÿ“ท
CCTV / Physical Security
Restricted High risk
Typical PII
Biometric data ยท Location data ยท Visitor records
Key controls
Signage (transparency)30-day rolling retentionRestricted accessSecure export only
Special category biometric data in UK/EU. ICO CCTV Code of Practice. DPIA may be needed.
๐Ÿ”Œ
API / Integration Endpoint
Internal Medium risk
Typical PII
Transient PII in transit ยท API keys ยท Authentication tokens
Key controls
TLS 1.2+Token rotationRate limitingAudit logging
Data in transit. Ensure transfer logging. API access should appear in DPA schedules if third-party.
๐Ÿ“Š
Analytics / BI Tool
Internal Medium risk
Typical PII
Derived / aggregated PII ยท Reports with personal data
Key controls
Row-level securityExport controlsAnonymisation checksUser audit trail
Profiling risk. If individual-level data accessible, treat as live PII system. Minimise by default.

Signals ยท PRIVASTU - SWOT my Dataโ„ข

Role-based intelligence for your data landscape
Dashboard Intelligence - beyond static registers and generic privacy tooling. PRIVASTU turns your live data estate into a role-aware intelligence layer by combining DSAR, RoPA, consent, assessments, vendor, policy, retention, AI, incident, training and SWOT signals inside one analysis surface. Each query is engineered to return issues, affected populations, control owners, remediation pathways and defensible outputs.
โšฌ Cross-module reasoning
๐Ÿ‘ค Role-aware queries
โ—† SWOT
โ—† PESTLE
โ—† SOAR
โ—† Porter's 5 Forces
โ—† STEEPLE
โ—† TOWS Matrix
โ—† VRIO
โšก Actionable outputs

SIC Code Search

Type to search 1,270+ UK SIC codes
Start typing a code number or industry keyword to search
Selected:
Run Sector + Role Intelligence
Generates query packs using the selected analysis framework, sector, sub-sector and role context
Strengths8
Weaknesses5
Opportunities6
Threats4
Role packs15
Data signals12

Select Your Role

Each pack includes five intelligent queries built for how that function consumes privacy data

Chief Privacy Officer

Best for privacy leadership, investment decisions and enterprise-wide accountability.

CP
5 queries Role pack

Data Protection Officer

Best for legal oversight, statutory controls and evidence-ready compliance answers.

DP
5 queries Role pack

Chief Financial Officer

Best for funding decisions, exposure estimation and control-efficiency trade-offs.

CF
5 queries Role pack

Chief Executive Officer

Best for enterprise line of sight, sponsor actions and board-level judgement.

CE
5 queries Role pack

HR Director

Best for employee lifecycle controls, worker trust and HR process redesign.

HR
5 queries Role pack

Procurement Director

Best for vendor prioritisation, onboarding gates and contract discipline.

PD
5 queries Role pack

Risk Director

Best for risk committees, scenario analysis and exposure prioritisation.

RD
5 queries Role pack

Communications Director

Best for public-facing trust, internal messaging and response clarity.

CD
5 queries Role pack

AI Governance Officer

Best for use-case governance, model risk and AI-specific control assurance.

AI
5 queries Role pack

Chief Information Security Officer

Best for security/privacy overlap, operational control failures and escalation.

CS
5 queries Role pack

Privacy Manager

Best for day-to-day queue management, action orchestration and follow-through.

PM
5 queries Role pack

Sales & Growth Director

Best for customer-facing growth, marketing dependency and trust-led conversion.

SG
5 queries Role pack

Chief Compliance Officer

Best for enterprise compliance alignment and formal control assurance.

CC
5 queries Role pack

Chief Operating Officer

Best for process design, service delivery and operating-model improvements.

CO
5 queries Role pack

Regulatory Affairs Director

Best for external oversight, regulator packs and horizon-scanning discipline.

RA
5 queries Role pack

Analysis Framework

Change the lens without changing the underlying data graph

Chief Privacy Officer - Pre-built Queries

Enterprise privacy strategy, maturity, board narrative and control direction

PRIVASTU will use the selected VRIO lens to interpret the same underlying data for Chief Privacy Officer.

VRIO 5 queries
1. Privacy Program Maturity Index

Using RoPA coverage, DSAR SLA performance, policy review health, vendor assurance, assessment completion, incident severity and training completion, show the current enterprise privacy maturity baseline and the three areas moving in the wrong direction.

RoPADSARPoliciesVendorsAssessmentsIncidentsTraining
2. Cross-Border Risk Posture

Which business units depend on transfers involving high-risk jurisdictions, sensitive categories, children, workers, or profiling activity and where are safeguards, TIAs, or vendor terms still weak?

RoPAVendorsTransfersAssessments
3. Board-Ready Privacy Dashboard

Summarise the five items leadership should see now across incidents, DSAR deadlines, blocked contracts, AI use cases, overdue policies and material SWOT threats.

DashboardDSARIncidentsVendorsAISWOT
4. Privacy-vs-Competitive-Advantage Analysis

Identify where privacy strengths such as faster DSAR handling, better vendor assurance, stronger transparency, or lower incident rates can be converted into customer trust, sales enablement, or procurement advantage.

DSARVendorsPoliciesIncidentsSWOT
5. Regulatory Horizon Risk Forecast

Across AI, children data, worker monitoring, cross-border flows, retention and direct marketing, where are our next regulator-pressure points most likely to emerge based on open actions and current control debt?

AIRoPARetentionConsentSWOTPolicies

Privacy Program Maturity Index

Intelligent query: Using RoPA coverage, DSAR SLA performance, policy review health, vendor assurance, assessment completion, incident severity and training completion, show the current enterprise privacy maturity baseline and the three areas moving in the wrong direction.

Role framing

Chief Privacy Officer needs the answer expressed through enterprise privacy strategy, maturity, board narrative and control direction.

VRIO
Signals to traverse

RoPA, DSAR, Policies, Vendors, Assessments, Incidents, Training

Cross-module
Expected output

Maturity scorecard with trend movement, affected functions and next-step recommendations.

Actionable
Framework guidance

Anchor the analysis in internal strengths, weaknesses, opportunities and threats and translate them into control or growth actions.

Lens

Free-Form Intelligence Query

Ask a bespoke question in the context of the selected role
Role context: Chief Privacy Officer Framework: VRIO
PRIVASTU will expand your prompt into an intelligent cross-module query with role framing, suggested signals and expected output structure.

Prompt orchestration workspace

Your expanded intelligent query will appear here once generated.

PRIVASTU ยท Signals

Scan my Horizon

Separate dropdown packs for the data-protection landscape, plus document and link assimilation. Follows the scan โ†’ analyse โ†’ plan cadence. Upload supporting documents to contextualise relational database queries against your system data.

Role packs15
Horizon packs10
Queries per role5
Legally boundedYes

Select Your Role

All role packs - each contains five legally bounded queries.

Analysis Framework

Change the lens without changing the underlying data graph.

SWOT: assess internal strengths and weaknesses against external opportunities and threats.

Queries

Analysis Workspace

Governed signals based on your role, framework and selected query.

Select a role and query to generate analysis.

Intelligent Query Expansion

Enter a question in natural language - PRIVASTU will expand it into a governed, role-aware, cross-module query plan.

DPO Relational Query Studio

Governed cross-module joins. Select datasets, set parameters and generate a legally anchored query plan.

Run the DPO studio to generate a governed relational watchlist.

DSAR Manager

Public intake, tracking, jurisdiction logic and internal case operations inside PRIVASTU

This module turns PRIVASTU into a working data subject rights portal rather than a static register. It supports public submission, request tracking, jurisdiction-driven response clocks, identity verification checkpoints and an internal operations view for Privacy, Legal, HR and service owners.

Public request intake Jurisdiction-aware deadlines Identity verification control Admin case management
PRIVASTU
360ยฐ Enterprise Privacy Management

PRIVASTU - 360ยฐ Enterprise Privacy Management. The logo stays confined to the DSAR hero and selected brand panels so the product remains precise and uncluttered.

Total requests3All stored cases
Pending verification1Identity confirmation still needed
Active processing2Internal teams currently working
Overdue risk3Past statutory deadline

What is live in this build

Deployable static module

Public-facing submission flow

Requesters can submit access, rectification, erasure, restriction, portability and objection requests against a jurisdiction list with response logic attached.

Tracking experience

Every submission gets a PRIVASTU reference and a response deadline based on the selected jurisdiction.

Internal case operations

Privacy teams can verify identity, move cases through workflow stages, add or close actions, filter queues and inspect deadlines.

What makes it product-grade

Built into PRIVASTU, not bolted on
One shell, two audiences

Public subjects get a clean rights portal while internal teams stay in the operating console.

Unified
Jurisdiction-first logic

Deadlines are calculated from the applicable law table rather than hard-coded globally.

Smart
Ready for orchestration

The structure is already suited to connect later into mail, workflow engines, vaults, or case evidence repositories.

Scalable

Current case queue

Live register from PRIVASTU local storage
ReferenceTypeRequesterJurisdictionDue dateVerificationStatusAction
PRIV-DSAR-20260320-A1X9 Access Alex Morgan
Employee
United Kingdom Thursday, 9 April 2026 Verified Overdue
PRIV-DSAR-20260320-K7M2 Erasure Claire Dubois
Customer
France Saturday, 11 April 2026 Unverified Overdue
PRIV-DSAR-20260320-N4Q8 Rectification Mila Schneider
Candidate
Germany Monday, 13 April 2026 Verified Overdue

Data Subject Request Portal

PRIVASTU public rights interface
PRIVASTU respects privacy rights under applicable law. Requesters receive a unique reference and a deadline calculated from the selected jurisdiction.

Important legal information

  • Identity verification is required before any disclosure of personal data.
  • Response windows vary by jurisdiction and complexity.
  • Available rights depend on the law that applies in the requester's country or state.

Built for different requester groups

Employees, workers, candidates, customers, children and guardians, suppliers and other data subjects can use the same portal with consistent control points.

Submit Request

Working intake form
Select a jurisdiction to view the response rule.

Track a Request

Public status look-up

The public tracker shows high-level workflow only. Evidence, exemptions and internal handling notes remain in the operations console.

Enter a PRIVASTU request reference to see status, verification state and response deadline.

Operations Console

Internal case management for Privacy, Legal, HR and service owners
ReferenceRequesterJurisdictionSubmittedDue byDays leftVerificationStatusActions required
PRIV-DSAR-20260320-A1X9 Alex Morgan
alex.morgan@example.com
United Kingdom 10/03/2026 Thursday, 9 April 2026 106 overdue Verified Overdue Collect HRIS extracts, Review third-party references
PRIV-DSAR-20260320-K7M2 Claire Dubois
claire.dubois@example.com
France 12/03/2026 Saturday, 11 April 2026 104 overdue Unverified Overdue Verify identity, Check contractual retention
PRIV-DSAR-20260320-N4Q8 Mila Schneider
mila.schneider@example.com
Germany 14/03/2026 Monday, 13 April 2026 102 overdue Verified Overdue Update applicant system, Notify recruiter

DSAR Workflow Command Centre

Role queues, controlled hand-offs and intelligent suggested next steps
Open tasks22Across all roles
Approval queue0Awaiting sign-off
Overdue actions22Internal or statutory
Release-ready0Approved packages

Role queue

Every activity carries ownership, evidence and hand-off criteria
UrgencyReferenceStageRole / ownerStatusDueEvidence and hand-offSuggested next step
criticalPRIV-DSAR-20260320-A1X9
Alex Morgan
Intake and acknowledgementRequest Respondent
Unassigned
Completed11/03/2026
-136 day(s)
Original request and acknowledgement
Case logged and requester acknowledged.
Complete
criticalPRIV-DSAR-20260320-A1X9
Alex Morgan
Identity and authority verificationIdentity Verification Officer
Unassigned
Completed11/03/2026
-136 day(s)
Verification decision and evidence reference
Identity or authority verified, or further evidence request documented.
Complete
criticalPRIV-DSAR-20260320-A1X9
Alex Morgan
Scope, rights and jurisdictionCase Manager / DPO
Unassigned
In progress11/03/2026
-136 day(s)
Scope note and jurisdiction analysis
A clear search scope and legal route are recorded.
Immediate statutory escalation
criticalPRIV-DSAR-20260320-A1X9
Alex Morgan
Search and data collectionData Owner / Search Respondent
Unassigned
Not started11/03/2026
-136 day(s)
Search log, system returns and custodian attestations
All assigned searches are complete or exceptions escalated.
Continue or assign
criticalPRIV-DSAR-20260320-A1X9
Alex Morgan
Legal review and exemptionsLegal Reviewer
Unassigned
Not started11/03/2026
-136 day(s)
Exemption and legal review schedule
Every withholding or restriction has a documented basis.
Continue or assign
criticalPRIV-DSAR-20260320-A1X9
Alex Morgan
Redaction and response packageRedaction Reviewer
Unassigned
Not started11/03/2026
-136 day(s)
Redaction log, package index and QA record
A complete quality-assured response package is ready.
Continue or assign
criticalPRIV-DSAR-20260320-A1X9
Alex Morgan
Approval and sign-offApprover
Unassigned
Not started11/03/2026
-136 day(s)
Approval decision and conditions
Signed approval or documented rework instruction.
Continue or assign
criticalPRIV-DSAR-20260320-A1X9
Alex Morgan
Secure release and communicationRelease Officer
Unassigned
Not started11/03/2026
-136 day(s)
Delivery record and sent communication
Approved response securely delivered.
Continue or assign
criticalPRIV-DSAR-20260320-A1X9
Alex Morgan
Closure and lessons learnedCase Manager / DPO
Unassigned
Not started11/03/2026
-136 day(s)
Closure checklist and lessons log
Case closed with a complete audit trail.
Continue or assign
criticalPRIV-DSAR-20260320-K7M2
Claire Dubois
Intake and acknowledgementRequest Respondent
Unassigned
Completed13/03/2026
-133 day(s)
Original request and acknowledgement
Case logged and requester acknowledged.
Complete
criticalPRIV-DSAR-20260320-K7M2
Claire Dubois
Identity and authority verificationIdentity Verification Officer
Unassigned
In progress13/03/2026
-133 day(s)
Verification decision and evidence reference
Identity or authority verified, or further evidence request documented.
Immediate statutory escalation
criticalPRIV-DSAR-20260320-K7M2
Claire Dubois
Scope, rights and jurisdictionCase Manager / DPO
Unassigned
Not started13/03/2026
-133 day(s)
Scope note and jurisdiction analysis
A clear search scope and legal route are recorded.
Continue or assign
criticalPRIV-DSAR-20260320-K7M2
Claire Dubois
Search and data collectionData Owner / Search Respondent
Unassigned
Not started13/03/2026
-133 day(s)
Search log, system returns and custodian attestations
All assigned searches are complete or exceptions escalated.
Continue or assign
criticalPRIV-DSAR-20260320-K7M2
Claire Dubois
Legal review and exemptionsLegal Reviewer
Unassigned
Not started13/03/2026
-133 day(s)
Exemption and legal review schedule
Every withholding or restriction has a documented basis.
Continue or assign
criticalPRIV-DSAR-20260320-K7M2
Claire Dubois
Redaction and response packageRedaction Reviewer
Unassigned
Not started13/03/2026
-133 day(s)
Redaction log, package index and QA record
A complete quality-assured response package is ready.
Continue or assign
criticalPRIV-DSAR-20260320-K7M2
Claire Dubois
Approval and sign-offApprover
Unassigned
Not started13/03/2026
-133 day(s)
Approval decision and conditions
Signed approval or documented rework instruction.
Continue or assign
criticalPRIV-DSAR-20260320-K7M2
Claire Dubois
Secure release and communicationRelease Officer
Unassigned
Not started13/03/2026
-133 day(s)
Delivery record and sent communication
Approved response securely delivered.
Continue or assign
criticalPRIV-DSAR-20260320-K7M2
Claire Dubois
Closure and lessons learnedCase Manager / DPO
Unassigned
Not started13/03/2026
-133 day(s)
Closure checklist and lessons log
Case closed with a complete audit trail.
Continue or assign
criticalPRIV-DSAR-20260320-N4Q8
Mila Schneider
Intake and acknowledgementRequest Respondent
Unassigned
Completed15/03/2026
-132 day(s)
Original request and acknowledgement
Case logged and requester acknowledged.
Complete
criticalPRIV-DSAR-20260320-N4Q8
Mila Schneider
Identity and authority verificationIdentity Verification Officer
Unassigned
Completed15/03/2026
-132 day(s)
Verification decision and evidence reference
Identity or authority verified, or further evidence request documented.
Complete
criticalPRIV-DSAR-20260320-N4Q8
Mila Schneider
Scope, rights and jurisdictionCase Manager / DPO
Unassigned
In progress15/03/2026
-132 day(s)
Scope note and jurisdiction analysis
A clear search scope and legal route are recorded.
Immediate statutory escalation
criticalPRIV-DSAR-20260320-N4Q8
Mila Schneider
Search and data collectionData Owner / Search Respondent
Unassigned
Not started15/03/2026
-132 day(s)
Search log, system returns and custodian attestations
All assigned searches are complete or exceptions escalated.
Continue or assign
criticalPRIV-DSAR-20260320-N4Q8
Mila Schneider
Legal review and exemptionsLegal Reviewer
Unassigned
Not started15/03/2026
-132 day(s)
Exemption and legal review schedule
Every withholding or restriction has a documented basis.
Continue or assign
criticalPRIV-DSAR-20260320-N4Q8
Mila Schneider
Redaction and response packageRedaction Reviewer
Unassigned
Not started15/03/2026
-132 day(s)
Redaction log, package index and QA record
A complete quality-assured response package is ready.
Continue or assign
criticalPRIV-DSAR-20260320-N4Q8
Mila Schneider
Approval and sign-offApprover
Unassigned
Not started15/03/2026
-132 day(s)
Approval decision and conditions
Signed approval or documented rework instruction.
Continue or assign
criticalPRIV-DSAR-20260320-N4Q8
Mila Schneider
Secure release and communicationRelease Officer
Unassigned
Not started15/03/2026
-132 day(s)
Delivery record and sent communication
Approved response securely delivered.
Continue or assign
criticalPRIV-DSAR-20260320-N4Q8
Mila Schneider
Closure and lessons learnedCase Manager / DPO
Unassigned
Not started15/03/2026
-132 day(s)
Closure checklist and lessons log
Case closed with a complete audit trail.
Continue or assign

Case workflow

Nine governed stages from intake to closure
1

Intake and acknowledgement

Request Respondent ยท Unassigned ยท due 11/03/2026

Case logged and requester acknowledged.

Completed
2

Identity and authority verification

Identity Verification Officer ยท Unassigned ยท due 11/03/2026

Identity or authority verified, or further evidence request documented.

Completed
3

Scope, rights and jurisdiction

Case Manager / DPO ยท Unassigned ยท due 11/03/2026

A clear search scope and legal route are recorded.

In progress
4

Search and data collection

Data Owner / Search Respondent ยท Unassigned ยท due 11/03/2026

All assigned searches are complete or exceptions escalated.

Not started
5

Legal review and exemptions

Legal Reviewer ยท Unassigned ยท due 11/03/2026

Every withholding or restriction has a documented basis.

Not started
6

Redaction and response package

Redaction Reviewer ยท Unassigned ยท due 11/03/2026

A complete quality-assured response package is ready.

Not started
7

Approval and sign-off

Approver ยท Unassigned ยท due 11/03/2026

Signed approval or documented rework instruction.

Not started
8

Secure release and communication

Release Officer ยท Unassigned ยท due 11/03/2026

Approved response securely delivered.

Not started
9

Closure and lessons learned

Case Manager / DPO ยท Unassigned ยท due 11/03/2026

Case closed with a complete audit trail.

Not started

Suggested next steps

Deadline, right, evidence and stage-aware
critical

Immediate statutory escalation

This request is 106 day(s) overdue. Escalate to the DPO and Legal, record the breach risk and complete the oldest open stage immediately.

  • Notify accountable approver
  • Document cause and recovery plan
  • Prioritise secure completion
  • Consider regulatory or complainant communications

Case context

access ยท United Kingdom ยท deadline Thursday, 9 April 2026 ยท -106 day(s) remaining

Workflow audit trail

Updates, approvals, reports and email preparation
Date / timeReferenceActor / roleActionDetail
22/07/2026, 12:31:48PRIV-DSAR-20260320-N4Q8SystemWorkflow createdNine-stage DSAR workflow initialised
22/07/2026, 12:31:48PRIV-DSAR-20260320-K7M2SystemWorkflow createdNine-stage DSAR workflow initialised
22/07/2026, 12:31:48PRIV-DSAR-20260320-A1X9SystemWorkflow createdNine-stage DSAR workflow initialised

Step-by-step role guidance

Respondent through approver and release officer
Request Respondent
Recognise, log and acknowledge rights requests promptly and accurately.

1Treat any clear rights request as valid regardless of channel or wording.

2Preserve the original request and record the received date and time.

3Create the case, confirm contact details and issue the acknowledgement.

4Do not promise an outcome or seek unnecessary identity data.

5Hand off with the original request, acknowledgement and any obvious urgency indicators.

Minimum evidence

  • Original request
  • Intake timestamp
  • Acknowledgement
  • Initial triage note

Governed correspondence templates

Case-aware letters, notices and internal instructions
Review and tailor before issue.

DSAR handling DPIA suite

Full templates for process, technology and AI-assisted discovery or redaction
Scope: these templates assess risks created by the DSAR handling environment itself, including large data volumes, employee records, special-category data, third-party material, cross-border support, automated discovery and AI-assisted review.
Identify the DSAR process, technology or change being screened.
Accountable owner and delivery team.
Describe collection, review, redaction, transfer and delivery.
Requests, records, systems and jurisdictions.
Special-category, criminal, children, employee or confidential material.
Whether monitoring records or behavioural data are involved.
Discovery, classification, summarisation, redaction or decision support.
Remote support, vendors, cloud regions or cross-border review.
Children, workers, patients or people in dependent relationships.
Is a full DPIA required and why?
Immediate controls, owner and due date.

DSAR Report Studio

Structured working reports and polished PRIVASTU reports

Email-ready delivery

Generates a standards-based .eml file for review and sending
Workflow integration: report and email preparation writes to the audit trail, refreshes the role queues and updates suggested next steps. The standalone file does not send messages automatically.

Report preview

Rendered from current case, workflow, evidence, templates and DPIA data
Select a request and generate a report.

Request details

โฑ

Assessment Activity Queue

Role-specific queues, respondent deadlines, chasers, review gates and escalation actions
Total assessments5
Open5
Overdue responses1
High risk4
Comments1
Templates19

Chronological work queue

Earliest due first
AssessmentActivityRoleDueUrgencyAction
Employee Monitoring Platform
ASM-2026-MON02
Respondent completionWorkplace Technology Lead18 Jul 20266 days overdue
AI Recruitment Screening
ASM-2026-AI01
Respondent completionHR Systems Lead25 Jul 20261 days
Employee Monitoring Platform
ASM-2026-MON02
Final decision and closureCOO27 Jul 20263 days
Global Cloud Data Platform
ASM-2026-CLOUD03
Respondent completionCloud Architect01 Aug 20268 days
AI Recruitment Screening
ASM-2026-AI01
Final decision and closureChief People Officer05 Aug 202612 days
test
ASM-2026-OIFAN
Respondent completionnnn08 Aug 202615 days
test
ASM-2026-CM1Q5
Respondent completionnnn08 Aug 202615 days
test
ASM-2026-OIFAN
Final decision and closurennnmmm10 Aug 202617 days
test
ASM-2026-CM1Q5
Final decision and closurennnmmm10 Aug 202617 days
Global Cloud Data Platform
ASM-2026-CLOUD03
Final decision and closureCIO19 Aug 202626 days

Chase and escalation log

Automatic while PRIVASTU is open
Reminder logic: 7, 3 and 1 days before the respondent deadline, on the due date and daily when overdue. The standalone build prepares auditable email messages. Hosted deployment can connect the same queue to an email service.
2026-07-25T06:10:00.890Z ยท ASM-2026-MON02
Overdue response escalation: 6 day(s).
2026-07-25T06:10:00.890Z ยท ASM-2026-AI01
Scheduled response reminder: 1 day(s) remaining.
2026-07-24T09:41:46.370Z ยท ASM-2026-MON02
Overdue response escalation: 5 day(s).
2026-07-23T11:30:32.656Z ยท ASM-2026-MON02
Overdue response escalation: 4 day(s).
2026-07-23T11:30:32.655Z ยท ASM-2026-AI01
Scheduled response reminder: 3 day(s) remaining.
2026-07-22T17:40:55.722Z ยท ASM-2026-MON02
Overdue response escalation: 3 day(s).
๐Ÿ“‹

Assessment Registry

DPIA, PIA, US state assessments, AI FRIA, role workflows, respondent communications and audit evidence
Total assessments5
Open5
Overdue responses1
High risk4
Comments1
Templates19
ReferenceAssessmentTemplateRiskStatusRespondent / ownerResponse dueCompletionActions
ASM-2026-OIFANtest
USA
US-STATEHighDraftnnn
nnnnn
08 Aug 2026
15 days left
0%
ASM-2026-CM1Q5test
USA
US-STATEHighDraftnnn
nnnnn
08 Aug 2026
15 days left
0%
ASM-2026-AI01AI Recruitment Screening
EU/UK
AI-ADMHighIn progressHR Systems Lead
People Director
25 Jul 2026
1 days left
0%
ASM-2026-MON02Employee Monitoring Platform
UK/Germany
EMP-MONHighAwaiting reviewWorkplace Technology Lead
CISO
18 Jul 2026
6 days overdue
0%
ASM-2026-CLOUD03Global Cloud Data Platform
Global
CLOUDMediumDraftCloud Architect
CTO
01 Aug 2026
8 days left
0%
๐Ÿงญ

Assessment Workspace

ASM-2026-CM1Q5 ยท test
StatusDraft
RiskHigh
Question completion0%
Response deadline08 Aug 2026
Time remaining15 days
End date10 Aug 2026

Role and scenario guided questionnaire

Hover ? for deeper guidance
1. Describe the project, processing and decision this assessment must govern.?
ContextRespondent
2. Identify controllers, joint controllers, processors, subprocessors and accountable owners.?
RolesRespondent
3. Map collection, use, disclosure, storage, access, transfer, inference and deletion.?
Data flowsData owner
4. Identify data categories and affected groups, including sensitive, inferred and vulnerable-person data.?
People and dataRespondent
5. For each purpose identify the legal basis, compatibility analysis and sensitive-data condition.?
Purpose and basisLegal
6. Why is each operation necessary and what less intrusive alternatives were considered??
NecessityBusiness owner
7. Is scale, granularity, access, retention and effect on people proportionate to the benefit??
ProportionalityPrivacy analyst
8. How will people be informed and exercise access, correction, deletion, objection, consent withdrawal and contest rights??
Transparency and rightsRespondent
9. Who was consulted and how did their feedback change the design??
ConsultationAssessment owner
10. Which high-risk indicators and jurisdictional mandatory-list triggers apply??
High-risk screeningPrivacy analyst
11. Describe plausible events affecting confidentiality, integrity, availability, autonomy, fairness, dignity or rights.?
Risk eventsSecurity and privacy
12. List preventive, detective, corrective and recovery controls with owners and evidence.?
ControlsControl owner
13. Reassess likelihood and severity after verified controls for each affected group.?
Residual riskPrivacy analyst
14. Does residual high risk require consultation with a supervisory authority before processing??
Prior consultationDPO
15. Record DPO advice, owner acceptance, approver decision, conditions and dissent.?
ApprovalApprover
16. Define performance, fairness, privacy, security and complaint monitoring plus reassessment triggers.?
MonitoringSystem owner

Suggested next steps

Dynamic
1
Complete 16 unanswered assessment questions.Suggested from current answers, dates, risk evidence and workflow state.
2
Identify and score risk events for affected people.Suggested from current answers, dates, risk evidence and workflow state.

Respondent and decision roles

Respondent: nnn
Owner: nnnnn
DPO: Data Protection Officer
Approver: nnnmmm

Chronological chain of risk

IDRisk event and impact on peopleInherentControlsResidualOwnerEvidenceStatusAction
No risks recorded. Add risk events as the assessment develops.
Risk chain rule: every material risk must retain its original inherent rating, linked controls, evidence, residual rating, accountable owner, acceptance decision and later review history.

Conversation with DPO and respondents

Chronological and auditable
No comments yet.

Immutable chronological record

1 events
Created ยท Privacy Office22/07/2026, 20:00:37

Assessment created from US-STATE for USA.

Audit controls

All created, sent, opened, answered, commented, chased, reviewed, risk-rated, approved, rejected and exported events are timestamped against the assessment.

Global DPIA authority and jurisdiction library

143 DSAR-aligned jurisdictions
Current assessment: ASM-2026-CM1Q5 ยท test ยท USA. Select any country or US state to apply its DPIA terminology, trigger test, authority route, respondent prompts and approver decision rules.
143 visibleAll authority records replicatedDPIA-specific rules added

Albania

IDP ยท Information and Data Protection Commissioner
Europe ยท National Supervisory Authority
Global PIA Composite
Primary lawPersonal Data Protection Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Algeria

ANPDP ยท National Authority for the Protection of Personal Data
Africa ยท National supervisory authority
Global PIA Composite
Primary lawData Protection Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Andorra

APDA ยท Andorran Data Protection Agency
Europe ยท National Supervisory Authority
Global PIA Composite
Primary lawOrganic Law on Data Protection
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Angola

APD ยท Data Protection Agency
Africa ยท National supervisory authority
Global PIA Composite
Primary lawLDP
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Antigua and Barbuda

Information Commissioner ยท Information Commissioner
Americas ยท National supervisory authority
Global PIA Composite
Primary lawData Protection Act
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Argentina

AAIP ยท Agency of Access to Public Information
Americas ยท National supervisory authority
Global PIA Composite
Primary lawLGPDP
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Armenia

PDPA Armenia ยท Personal Data Protection Agency
Europe ยท National Supervisory Authority
Global PIA Composite
Primary lawLaw on Personal Data
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Australia

OAIC ยท Office of the Australian Information Commissioner
Asia-Pacific ยท National privacy authority
OAIC PIA
Primary lawPrivacy Act
DPIA terminologyPrivacy Impact Assessment (PIA)
Legal positionUse the OAIC risk-proportionate PIA process and verify any Australian Government, state, territory or sector-specific mandatory requirement.
Trigger testNew or changed projects involving personal information, intrusive technology, matching, biometrics, surveillance, AI, significant data sharing or sensitive information.
Required methodThreshold assessment; plan; describe project; identify stakeholders; map information flows; analyse impacts; manage risks; make recommendations; report; implement and review.
Authority escalationEngage privacy, security, legal and affected stakeholders. Check whether an agency, regulator or governance body requires submission or publication.
Review ruleTrack recommendation implementation and repeat when the project or information handling changes.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Austria

DSB ยท Austrian Data Protection Authority
European Union ยท National Supervisory Authority
EU / EEA DPIA
Primary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Azerbaijan

Authority ยท Ministry of Digital Development and Transport / competent authority
Europe ยท No dedicated authority confirmed in the source; verify before reliance
Global PIA Composite
Primary lawLaw on Personal Data
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Bahamas

DPC Bahamas ยท Data Protection Commissioner
Americas ยท National supervisory authority
Global PIA Composite
Primary lawData Protection Act
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Bahrain

PDPA Bahrain ยท Personal Data Protection Authority
Middle East ยท National supervisory authority
Global PIA Composite
Primary lawData Protection Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Bangladesh

Authority ยท Data Protection Board / competent authority
Asia-Pacific ยท Operational status should be verified
Global PIA Composite
Primary lawData Protection Act
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Barbados

DPC Barbados ยท Data Protection Commission
Americas ยท National supervisory authority
Global PIA Composite
Primary lawData Protection Act
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Belarus

NCPDP ยท National Center for Personal Data Protection
Europe ยท National Supervisory Authority
Global PIA Composite
Primary lawLaw on Personal Data
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Belgium

APD-GBA ยท Belgian Data Protection Authority
European Union ยท National Supervisory Authority
EU / EEA DPIA
Primary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Belize

Authority ยท Information Commissioner / competent data protection authority
Americas ยท Current authority details should be verified
Global PIA Composite
Primary lawData Protection Act
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Benin

APDP ยท Personal Data Protection Authority
Africa ยท National supervisory authority
Global PIA Composite
Primary lawData Protection Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Bhutan

Authority ยท GovTech Agency / competent privacy authority
Asia-Pacific ยท Current institutional position should be verified
Global PIA Composite
Primary lawPrivacy Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Bolivia

Authority ยท Personal Data Protection Agency / competent authority
Americas ยท Current institutional position should be verified
Global PIA Composite
Primary lawData Protection Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Bosnia and Herzegovina

AZLP ยท Personal Data Protection Agency in Bosnia and Herzegovina
Europe ยท National Supervisory Authority
Global PIA Composite
Primary lawLaw on Personal Data
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Botswana

Authority ยท Information and Data Protection Commission / competent authority
Africa ยท Current institutional position should be verified
Global PIA Composite
Primary lawPOPIA
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Brazil

ANPD ยท National Data Protection Authority
Americas ยท National supervisory authority
Brazil RIPD
Primary lawLGPD
DPIA terminologyRelatรณrio de Impacto ร  Proteรงรฃo de Dados Pessoais (RIPD)
Legal positionAssess whether the LGPD, ANPD request, sensitive data, legitimate-interests governance or high-impact processing requires or supports a RIPD.
Trigger testHigh-risk or sensitive processing, profiling, vulnerable people, large scale, legitimate interests, public-sector data sharing or processing identified by the ANPD.
Required methodDescribe data, methodology, safeguards, purposes, necessity, risks, mitigations, responsible persons and evidence.
Authority escalationThe ANPD may request the report. Verify current regulations, guidance and sector-specific requirements.
Review ruleUpdate for material changes and maintain evidence for ANPD scrutiny.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

British Virgin Islands

ICO BVI ยท Information Commissioner
Americas ยท National supervisory authority
Global PIA Composite
Primary lawData Protection Act
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Brunei Darussalam

AITI ยท Authority for Info-communications Technology Industry / competent privacy authority
Asia-Pacific ยท Current institutional position should be verified
Global PIA Composite
Primary lawData Protection Act
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Bulgaria

CPDP ยท Commission for Personal Data Protection
European Union ยท National Supervisory Authority
EU / EEA DPIA
Primary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Cambodia

MPTC ยท Ministry of Posts and Telecommunications / competent privacy authority
Asia-Pacific ยท Current institutional position should be verified
Global PIA Composite
Primary lawPersonal Data Protection Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Canada

OPC ยท Office of the Privacy Commissioner of Canada
Americas ยท Federal privacy authority; provincial authorities may also apply
Canada PIA
Primary lawPIPEDA
DPIA terminologyPrivacy Impact Assessment (PIA)
Legal positionDetermine the applicable federal, provincial and public-sector PIA requirement. Federal institutions should apply the current Treasury Board and OPC process.
Trigger testNew or substantially modified programme, activity, system or service involving personal information, particularly sensitive data, matching, AI, biometrics and cross-border services.
Required methodDescribe authority and programme; map flows; identify privacy risks and compliance gaps; document mitigations, residual risk, approval and submission requirements.
Authority escalationIdentify the correct federal or provincial commissioner and any mandatory review or submission route.
Review ruleUpdate for material programme or technology change and track mitigation implementation.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Chile

CPLT ยท Council for Transparency / competent data protection authority
Americas ยท Institutional allocation should be verified
Global PIA Composite
Primary lawLaw 19628
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Colombia

SIC ยท Superintendence of Industry and Commerce
Americas ยท National data protection authority
Global PIA Composite
Primary lawLaw 1581
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Congo, Democratic Republic of the

ARPTC ยท Post and Telecommunications Regulatory Authority / competent data authority
Africa ยท Current institutional position should be verified
Global PIA Composite
Primary lawData Protection Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Cรดte d'Ivoire

ARTCI ยท Telecommunications/ICT Regulatory Authority of Cรดte dโ€™Ivoire
Africa ยท Personal data supervisory authority
Global PIA Composite
Primary lawPersonal Data Protection Act
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Croatia

AZOP ยท Croatian Personal Data Protection Agency
European Union ยท National Supervisory Authority
EU / EEA DPIA
Primary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Cyprus

OCPDP ยท Office of the Commissioner for Personal Data Protection
European Union ยท National Supervisory Authority
EU / EEA DPIA
Primary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Czech Republic

UOOU ยท Office for Personal Data Protection
European Union ยท National Supervisory Authority
EU / EEA DPIA
Primary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Denmark

Datatilsynet ยท Danish Data Protection Agency
European Union ยท National Supervisory Authority
EU / EEA DPIA
Primary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Egypt

PDPC Egypt ยท Personal Data Protection Centre / competent authority
Africa ยท Operational authority details should be verified
Global PIA Composite
Primary lawLaw on Regulated Professions
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Estonia

AKI ยท Estonian Data Protection Inspectorate
European Union ยท National Supervisory Authority
EU / EEA DPIA
Primary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Eswatini

Authority ยท Eswatini Data Protection Authority / competent regulator
Africa ยท Current institutional position should be verified
Global PIA Composite
Primary lawPOPIA
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Ethiopia

ECA ยท Ethiopian Communications Authority / competent privacy authority
Africa ยท Current institutional position should be verified
Global PIA Composite
Primary lawPrivacy Directive
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Finland

ODPO ยท Office of the Data Protection Ombudsman
European Union ยท National Supervisory Authority
EU / EEA DPIA
Primary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

France

CNIL ยท Commission Nationale de l'Informatique et des Libertรฉs
European Union ยท National Supervisory Authority
CNIL AIPD
Primary lawGDPR
DPIA terminologyAnalyse dโ€™impact relative ร  la protection des donnรฉes (AIPD)
Legal positionApply the CNIL required and non-required lists, GDPR Article 35 and the high-risk criteria before processing.
Trigger testNational mandatory-list activity, GDPR Article 35(3), or processing meeting the CNIL / EDPB high-risk criteria.
Required methodUse the CNIL four-part method: context; fundamental principles including necessity and proportionality; privacy risks; formal validation, action plan and ongoing review.
Authority escalationRecord DPO advice. Consult the CNIL before processing where residual high risk remains after mitigation.
Review ruleMaintain the AIPD as a living record and reassess material changes, incidents and control failures.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Germany

BfDI ยท Federal Commissioner for Data Protection and Freedom of Information
European Union ยท Federal Supervisory Authority; state authorities also apply
Germany DSK / BfDI DSFA
Primary lawGDPR
DPIA terminologyDatenschutz-Folgenabschรคtzung (DSFA)
Legal positionApply GDPR Article 35 and the applicable BfDI, DSK or state authority mandatory list according to controller type and competence.
Trigger testMandatory-list processing, significant automated evaluation, extensive monitoring, sensitive data at scale and other likely high-risk processing.
Required methodDescribe processing and legal context; test necessity and proportionality; model threats and impacts on people; document safeguards, DPO advice, residual risk and review.
Authority escalationIdentify the competent federal or state authority. Prior consultation is required where high residual risk remains.
Review ruleReview after significant change and where monitoring shows risk assumptions or controls are no longer valid.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Ghana

DPC Ghana ยท Data Protection Commission
Africa ยท National supervisory authority
Global PIA Composite
Primary lawGDPA
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Greece

HDPA ยท Hellenic Data Protection Authority
European Union ยท National Supervisory Authority
EU / EEA DPIA
Primary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Hong Kong

PCPD ยท Office of the Privacy Commissioner for Personal Data
Asia-Pacific ยท Privacy regulator
Hong Kong PIA
Primary lawPDPO
DPIA terminologyPrivacy Impact Assessment (PIA)
Legal positionUse a PIA as accountability and privacy-by-design practice and verify sector or public-body requirements under the PDPO.
Trigger testNew systems, surveillance, biometrics, matching, AI, direct marketing, major sharing or processing that materially changes privacy risk.
Required methodMap data flows, assess Data Protection Principles, identify impacts, controls, owners and residual risks, then monitor implementation.
Authority escalationEngage the Data Protection Officer and consider PCPD guidance or consultation for novel or high-impact processing.
Review ruleReassess material changes and control effectiveness.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Hungary

NAIH ยท Hungarian National Authority for Data Protection and Freedom of Information
European Union ยท National Supervisory Authority
EU / EEA DPIA
Primary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

India

DPB ยท Data Protection Board of India
Asia-Pacific ยท Operational status and contact route should be verified
India DPIA
Primary lawDPDP Act
DPIA terminologyData protection impact / significant data fiduciary assessment
Legal positionVerify current DPDPA rules, significant data fiduciary designation and any sectoral or contractual impact-assessment requirement.
Trigger testHigh-volume or high-risk processing, sensitive sector data, children, profiling, AI, monitoring, cross-border processing and designation-based obligations.
Required methodDescribe purpose and data; test necessity and safeguards; assess harms to data principals; document rights, security, processors, residual risk and approval.
Authority escalationEngage the Data Protection Officer where appointed and verify Data Protection Board or sector regulator expectations.
Review ruleReassess material processing changes and prescribed periodic requirements.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Indonesia

PDP Authority ยท Personal Data Protection supervisory authority
Asia-Pacific ยท Institutional arrangements should be verified
Global PIA Composite
Primary lawPDP Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Ireland

DPC ยท Data Protection Commission
European Union ยท National Supervisory Authority
EU / EEA DPIA
Primary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Israel

PPA Israel ยท Privacy Protection Authority
Middle East ยท National supervisory authority
Global PIA Composite
Primary lawPrivacy Law 1981
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Italy

Garante ยท Garante per la protezione dei dati personali
European Union ยท National Supervisory Authority
Italy Garante DPIA
Primary lawGDPR
DPIA terminologyValutazione dโ€™impatto sulla protezione dei dati (DPIA)
Legal positionApply GDPR Article 35 and the Garante list of processing subject to DPIA.
Trigger testInnovative technology, systematic monitoring, profiling, vulnerable people, biometric or sensitive data, large scale and other Garante list triggers.
Required methodDocument processing, purposes, necessity, proportionality, rights risks, safeguards, DPO advice, approvals and implementation monitoring.
Authority escalationConsult the Garante before processing where residual high risk cannot be adequately mitigated.
Review ruleUpdate for material processing, technology, vendor, scale or risk changes.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Japan

PPC ยท Personal Information Protection Commission
Asia-Pacific ยท National supervisory authority
Japan PIA
Primary lawAPPI
DPIA terminologyPrivacy impact / personal information risk assessment
Legal positionDetermine whether a PIA is required by sector, public-body rules, procurement or organisational governance and apply APPI accountability.
Trigger testSensitive personal information, profiling, AI, large-scale data, cross-border provision, biometrics, location and novel surveillance.
Required methodMap data and third-party provision; identify purpose, notices, consent and security requirements; assess harms; assign safeguards and review.
Authority escalationEngage the privacy lead and relevant sector authority. Verify PPC guidance and notification or consultation requirements.
Review ruleUpdate for new purposes, vendors, transfers, security changes and material risk.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Jordan

PDPC Jordan ยท Personal Data Protection Council / Ministry of Digital Economy and Entrepreneurship
Middle East ยท National privacy authority
Global PIA Composite
Primary lawData Protection Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Kenya

ODPC ยท Office of the Data Protection Commissioner
Africa ยท National supervisory authority
Global PIA Composite
Primary lawDPA 2019
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Latvia

DVI ยท Data State Inspectorate
European Union ยท National Supervisory Authority
EU / EEA DPIA
Primary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Lesotho

DPC Lesotho ยท Data Protection Commission
Africa ยท National supervisory authority
Global PIA Composite
Primary lawPOPIA
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Lithuania

VDAI ยท State Data Protection Inspectorate
European Union ยท National Supervisory Authority
EU / EEA DPIA
Primary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Luxembourg

CNPD ยท National Commission for Data Protection
European Union ยท National Supervisory Authority
EU / EEA DPIA
Primary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Malawi

Authority ยท Data Protection Authority / Malawi Communications Regulatory Authority
Africa ยท Competence should be verified
Global PIA Composite
Primary lawPOPIA
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Malaysia

JPDP ยท Personal Data Protection Commissioner
Asia-Pacific ยท National supervisory authority
Global PIA Composite
Primary lawPDPA
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Malta

IDPC ยท Office of the Information and Data Protection Commissioner
European Union ยท National Supervisory Authority
EU / EEA DPIA
Primary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Mexico

Federal authority ยท Competent federal transparency and personal data authority
Americas ยท Institutional position should be verified for the date of use
Global PIA Composite
Primary lawLGPD
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Moldova

NCPDP ยท National Centre for Personal Data Protection
Europe ยท National Supervisory Authority
Global PIA Composite
Primary lawLaw on Personal Data
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Morocco

CNDP ยท National Commission for the Control of Personal Data Protection
Africa ยท National supervisory authority
Global PIA Composite
Primary lawGDPL
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Mozambique

INTIC ยท National Institute of Information and Communication Technologies / competent authority
Africa ยท Current institutional position should be verified
Global PIA Composite
Primary lawLPDA
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Netherlands

AP ยท Dutch Data Protection Authority
European Union ยท National Supervisory Authority
EU / EEA DPIA
Primary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

New Zealand

OPC NZ ยท Office of the Privacy Commissioner
Asia-Pacific ยท National privacy authority
New Zealand OPC PIA
Primary lawPrivacy Act 2020
DPIA terminologyPrivacy Impact Assessment (PIA)
Legal positionUse a brief or full PIA proportionate to risk and verify sector or public-body requirements.
Trigger testNew or changed collection, use, disclosure, data matching, AI, biometrics, surveillance, sensitive information or material effects on individuals.
Required methodDefine scope, map information flows, consult, identify privacy impacts, rate risks, assign mitigations, approve and review.
Authority escalationUse the privacy officer and seek OPC advice where significant uncertainty or unresolved risk remains.
Review ruleReview implementation and reassess when processing or risks materially change.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Nigeria

NDPC ยท Nigeria Data Protection Commission
Africa ยท National supervisory authority
Global PIA Composite
Primary lawNDPR
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Norway

Datatilsynet ยท Norwegian Data Protection Authority
Europe ยท National Supervisory Authority
EU / EEA DPIA
Primary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Peru

ANPD ยท National Authority for Personal Data Protection
Americas ยท National supervisory authority
Global PIA Composite
Primary lawLaw 29733
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Philippines

NPC ยท National Privacy Commission
Asia-Pacific ยท National supervisory authority
Global PIA Composite
Primary lawDP Act 2012
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Poland

UODO ยท Personal Data Protection Office
European Union ยท National Supervisory Authority
EU / EEA DPIA
Primary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Portugal

CNPD ยท National Data Protection Commission
European Union ยท National Supervisory Authority
EU / EEA DPIA
Primary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Qatar

NCGAA ยท National Cyber Governance and Assurance Affairs / competent privacy authority
Middle East ยท Current institutional position should be verified
Global PIA Composite
Primary lawData Protection Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Romania

ANSPDCP ยท National Supervisory Authority for Personal Data Processing
European Union ยท National Supervisory Authority
EU / EEA DPIA
Primary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Russian Federation

Roskomnadzor ยท Federal Service for Supervision of Communications, Information Technology and Mass Media
Europe ยท Federal supervisory authority
Global PIA Composite
Primary lawFederal Law on Personal Data
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Saudi Arabia

SDAIA/NDMO ยท Saudi Data and Artificial Intelligence Authority / National Data Management Office
Middle East ยท National data governance authority
Global PIA Composite
Primary lawData Protection Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Singapore

PDPC ยท Personal Data Protection Commission
Asia-Pacific ยท National regulatory authority
Singapore PDPC DPIA
Primary lawPDPA
DPIA terminologyData Protection Impact Assessment (DPIA)
Legal positionApply a lifecycle-based DPIA as accountability practice and verify any sectoral or contractual mandate.
Trigger testNew or changed high-impact processing, sensitive information, profiling, monitoring, AI, large-scale sharing or cross-border processing.
Required methodScope and describe processing; assess compliance, necessity, proportionality and risks; identify safeguards; approve; implement; monitor and review.
Authority escalationEngage the Data Protection Officer and sector regulator where applicable. Verify whether notification or consultation is required for the particular processing.
Review ruleMaintain throughout the system and data lifecycle.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Slovakia

UOOU SR ยท Office for Personal Data Protection of the Slovak Republic
European Union ยท National Supervisory Authority
EU / EEA DPIA
Primary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Slovenia

IP-RS ยท Information Commissioner of the Republic of Slovenia
European Union ยท National Supervisory Authority
EU / EEA DPIA
Primary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

South Africa

IR ยท Information Regulator
Africa ยท National supervisory authority
South Africa PIA
Primary lawPOPIA
DPIA terminologyPrivacy impact and risk assessment under POPIA accountability
Legal positionUse a documented assessment to demonstrate responsible-party accountability and verify current Information Regulator guidance and sector rules.
Trigger testSpecial personal information, children, biometrics, profiling, surveillance, extensive matching, cross-border processing or material risk to data subjects.
Required methodDocument purpose, lawful justification, minimality, openness, security safeguards, participation rights, operators, cross-border conditions, risks and controls.
Authority escalationEngage the Information Officer and determine whether prior authorisation or regulator engagement applies to the processing.
Review ruleReview on material change, incident, complaint or control failure.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Spain

AEPD ยท Spanish Data Protection Agency
European Union ยท National Supervisory Authority
EU / EEA DPIA
Primary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Sweden

IMY ยท Swedish Authority for Privacy Protection
European Union ยท National Supervisory Authority
EU / EEA DPIA
Primary lawGDPR
DPIA terminologyGDPR Data Protection Impact Assessment (Article 35)
Legal positionA DPIA is required before processing where the proposed processing is likely to result in high risk to people. Apply Article 35(3), the authority mandatory list and the EDPB high-risk criteria.
Trigger testSystematic and extensive evaluation with significant effects, large-scale sensitive or criminal data, large-scale systematic monitoring, national list triggers or a combination of EDPB high-risk indicators.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationObtain and record DPO advice. Where residual high risk cannot be mitigated, determine and complete prior consultation with the competent supervisory authority under Article 36 before processing.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Switzerland

FDPIC ยท Federal Data Protection and Information Commissioner
Europe ยท Federal Supervisory Authority
Switzerland DPIA
Primary lawFederal Data Protection Act
DPIA terminologyData protection impact assessment under the Federal Act on Data Protection
Legal positionAssess planned processing likely to result in high risk to personality or fundamental rights and verify current federal guidance.
Trigger testSensitive personal data at scale, systematic monitoring, profiling with high risk, innovative or extensive processing and other circumstances creating likely high risk.
Required methodDescribe processing; assess risks to affected people; document measures; consult the data protection adviser where appointed; record residual risk and decision.
Authority escalationDetermine whether consultation with the FDPIC is required where high residual risk remains and is not resolved through the statutory adviser route.
Review ruleUpdate where risk or processing changes materially.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Tanzania

PDPC Tanzania ยท Personal Data Protection Commission
Africa ยท National supervisory authority
Global PIA Composite
Primary lawDPA 2022
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Thailand

PDPC ยท Personal Data Protection Committee / Office of the PDPC
Asia-Pacific ยท National supervisory authority
Global PIA Composite
Primary lawPDPA
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Uganda

PDPO ยท Personal Data Protection Office
Africa ยท National supervisory authority
Global PIA Composite
Primary lawDPA 2019
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United Arab Emirates

UAE Data Office ยท UAE Data Office
Middle East ยท Federal privacy authority; free-zone regulators may also apply
Global PIA Composite
Primary lawData Protection Law
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United Kingdom

ICO ยท Information Commissioner's Office
Europe ยท National Supervisory Authority
UK ICO DPIA
Primary lawUK GDPR
DPIA terminologyUK GDPR Data Protection Impact Assessment
Legal positionComplete a DPIA before high-risk processing. Apply UK GDPR Article 35, the ICO high-risk processing list and current UK guidance.
Trigger testSystematic evaluation with significant effects, large-scale special-category or criminal data, systematic public monitoring and other processing identified by the ICO as likely high risk.
Required methodDescribe processing and consultation; assess necessity and proportionality; identify and assess risks to rights and freedoms; identify measures and safeguards; record DPO advice and sign-off.
Authority escalationConsult the DPO. Submit a prior-consultation request to the ICO before processing where identified high residual risk cannot be reduced.
Review ruleKeep the DPIA under review and update it when the nature, scope, context, purposes, technology or risk changes.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Alabama

AL AG ยท Alabama Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Alaska

AK AG ยท Alaska Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Arizona

AZ AG ยท Arizona Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Arkansas

AR AG ยท Arkansas Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawACDPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - California

CPPA ยท California Privacy Protection Agency
United States ยท State privacy regulator; Attorney General also has enforcement functions
California CPPA Risk Assessment
Primary lawCCPA/CPRA
DPIA terminologyCalifornia privacy risk assessment
Legal positionApply California risk-assessment requirements and rules to covered processing that presents significant risk to consumersโ€™ privacy.
Trigger testCovered processing identified by current CCPA regulations, including relevant sale or sharing, sensitive data, profiling or automated decision-making and other significant-risk activity.
Required methodDocument purpose, benefits, data categories, affected consumers, safeguards, negative impacts, necessity, alternatives, responsible persons and certification or submission requirements.
Authority escalationIdentify CPPA and Attorney General competence. Verify filing, certification, timing and record-retention requirements in the current regulations.
Review ruleUpdate when processing materially changes and at any required periodic interval.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Colorado

CO AG ยท Colorado Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawCPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Connecticut

CT AG ยท Connecticut Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawCTDPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Delaware

DE AG ยท Delaware Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawDPDPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - District of Columbia

DC AG ยท District of Columbia Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Florida

FL AG ยท Florida Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawFDBR
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Georgia

GA AG ยท Georgia Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Hawaii

HI AG ยท Hawaii Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Idaho

ID AG ยท Idaho Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Illinois

IL AG ยท Illinois Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Indiana

IN AG ยท Indiana Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawICDPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Iowa

IA AG ยท Iowa Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawICDPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Kansas

KS AG ยท Kansas Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Kentucky

KY AG ยท Kentucky Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawKCDPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Louisiana

LA AG ยท Louisiana Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Maine

ME AG ยท Maine Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Maryland

MD AG ยท Maryland Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawMODPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Massachusetts

MA AG ยท Massachusetts Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Michigan

MI AG ยท Michigan Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Minnesota

MN AG ยท Minnesota Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawMNDPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Mississippi

MS AG ยท Mississippi Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Missouri

MO AG ยท Missouri Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Montana

MT AG ยท Montana Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawMCDPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Nebraska

NE AG ยท Nebraska Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawNDPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Nevada

NV AG ยท Nevada Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawNDPP
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - New Hampshire

NH AG ยท New Hampshire Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawNHDPP
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - New Jersey

NJ AG ยท New Jersey Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawNJDPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - New Mexico

NM AG ยท New Mexico Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - New York

NY AG ยท New York Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawNYDSA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - North Carolina

NC AG ยท North Carolina Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - North Dakota

ND AG ยท North Dakota Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Ohio

OH AG ยท Ohio Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Oklahoma

OK AG ยท Oklahoma Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Oregon

OR AG ยท Oregon Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawOCPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Pennsylvania

PA AG ยท Pennsylvania Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Rhode Island

RI AG ยท Rhode Island Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - South Carolina

SC AG ยท South Carolina Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - South Dakota

SD AG ยท South Dakota Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Tennessee

TN AG ยท Tennessee Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawTIPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Texas

TX AG ยท Texas Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawTDPSA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Utah

UT AG ยท Utah Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawUCPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Vermont

VT AG ยท Vermont Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawVDPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Virginia

VA AG ยท Virginia Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawVCDPA
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Washington

WA AG ยท Washington Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - West Virginia

WV AG ยท West Virginia Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Wisconsin

WI AG ยท Wisconsin Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

United States - Wyoming

WY AG ยท Wyoming Attorney General
United States ยท State Attorney General / privacy enforcer
US State Data Protection Assessment
Primary lawFederal Law
DPIA terminologyUS state data protection assessment / risk assessment
Legal positionNo single federal DPIA regime applies across all processing. Test the current state law and rules for assessments covering processing that presents heightened risk.
Trigger testWhere regulated by the applicable state law: sale or sharing, targeted advertising, sensitive data, profiling or automated decision-making, substantial privacy risk, unfair treatment, financial or physical injury, intrusion or other defined heightened-risk processing.
Required methodDocument purpose, benefits, data categories, affected consumers, profiling logic where relevant, foreseeable harms, safeguards, necessity, alternatives, residual risk and approval. Preserve the assessment for regulator production where required.
Authority escalationConfirm the enforcing Attorney General, privacy agency and any sector regulator. Verify whether the assessment must be filed, certified, produced on request or retained internally.
Review ruleRepeat when processing materially changes and at the cadence required by applicable regulations or the approved risk programme.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Vietnam

MPS ยท Ministry of Public Security / competent personal data authority
Asia-Pacific ยท National competent authority
Global PIA Composite
Primary lawLaw on Info Security
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—

Zambia

DPA Zambia ยท Data Protection Commissioner / Data Protection Authority
Africa ยท National supervisory authority
Global PIA Composite
Primary lawPOPIA
DPIA terminologyPrivacy Impact Assessment / Data Protection Impact Assessment
Legal positionComplete a proportionate privacy impact assessment before high-impact or materially changed processing. Determine whether local law makes it mandatory, regulator-requested, public-sector specific or recognised accountability practice.
Trigger testSensitive or special-category data, large scale, systematic monitoring, profiling, automated decisions, vulnerable people, innovative technology, extensive matching, location tracking, denial of rights or significant cross-border processing.
Required methodDescribe the project and information flows; identify purpose, legal basis and affected people; test necessity and proportionality; identify risks to people; assign evidenced controls; determine residual risk; record advice, approval and review triggers.
Authority escalationEscalate to the privacy lead or DPO. Verify whether the competent authority must be consulted, notified or supplied with the assessment before processing where high residual risk remains.
Review ruleReview before launch and whenever purpose, data, technology, geography, vendors, access, scale or risk changes. Record incidents, complaints and control test results.
Respondent: Provide factual system, data-flow and control evidence. Identify uncertainty and do not assume a control operates without test evidence.
Approver: Confirm necessity, proportionality, control ownership, evidence, residual risk acceptance, conditions, end date and review date.
Authority-specific DPIA position must be verified against current law and official guidance at the assessment decision date.
Authority website โ†—
๐Ÿš€

Launch Assessment

Select a jurisdiction and scenario template, assign roles, set respondent and end dates and prepare the secure respondent pack

New assessment

Required fields are marked *

Decision-tree screening

Before launch
1
Does the project process personal data or materially affect privacy?If no, record a threshold decision. If yes, continue.
2
Does an authority list or US state trigger expressly require an assessment?Check selected jurisdictions, sensitive data, profiling, sale, targeted advertising, ADMT and minors.
3
Are two or more EDPB high-risk indicators present, or one sufficiently serious indicator?Scoring, significant decisions, monitoring, sensitive data, scale, matching, vulnerable groups, innovation and denial of rights or service.
4
Can the processing be redesigned before assessment?Assess necessity, less intrusive alternatives and privacy by design before committing to the architecture.
โš™

Assessment Workflow

Eight governed stages from threshold screening to closure, monitoring and reassessment
Total assessments5
Open5
Overdue responses1
High risk4
Comments1
Templates19

Lifecycle for test

Current stage 1 of 8
1
Intake and thresholdRequester / Privacy analyst: Scope, jurisdictions and assessment need recorded
Current
2
Respondent evidenceRespondent / SMEs: Processing, data flows, purposes, roles and controls evidenced
Pending
3
Necessity and rightsBusiness owner / Legal: Necessity, proportionality, legal basis, transparency and rights tested
Pending
4
Risk analysisPrivacy / Security: Risk events scored and controls linked to operating evidence
Pending
5
DPO reviewDPO: Independent advice, consultation decision and conditions recorded
Pending
6
Approver decisionAccountable approver: Approve, reject or require changes with risk acceptance rationale
Pending
7
Implementation validationControl owners: Conditions implemented, tested and evidenced
Pending
8
Closure and monitoringAssessment owner: End date, review triggers and continuing monitoring set
Pending

Role-specific responsibilities

Requester: Define the change, sponsor, outcome and required decision.
Respondent: Provide complete factual answers, diagrams, contracts, configurations and control evidence.
Privacy analyst: Test threshold, scope, necessity, proportionality, rights and risk to people.
Security: Evidence technical controls, threat scenarios, detection, recovery and testing.
Legal: Confirm roles, bases, statutory duties, contracts, rights and consultation triggers.
DPO: Advise independently, challenge unsupported claims and record prior-consultation decision.
Approver: Own the decision, conditions and any accepted residual risk.
Control owner: Implement, test and maintain each mitigation and review trigger.

Workflow integrity checks

1
Complete 16 unanswered assessment questions.Suggested from current answers, dates, risk evidence and workflow state.
2
Identify and score risk events for affected people.Suggested from current answers, dates, risk evidence and workflow state.
๐Ÿ“š

DPIA and PIA Template Library

Jurisdiction-specific, role-specific and scenario-specific assessment packs

EDPB 2026 DPIA Meta-Template

EU/EEA
General high-risk processing

EU-EDPB-2026 16 core questions

UK ICO DPIA

UK
UK GDPR high-risk processing

UK-ICO 16 core questions

CNIL AIPD

France
French AIPD method

FR-CNIL 16 core questions

Germany DSK DSFA

Germany
German mandatory-list and high-risk review

DE-DSK 16 core questions

Italy Garante DPIA

Italy
Innovative technology or systematic monitoring

IT-GARANTE 16 core questions

AI and Automated Decisioning DPIA

Global
AI, profiling, LLM and agentic systems

AI-ADM 16 core questions

Employee Monitoring DPIA

Global
Email, device, productivity, CCTV and location monitoring

EMP-MON 16 core questions

Biometric and Facial Recognition DPIA

Global
Identification, verification or categorisation

BIO 16 core questions

Children and Age Assurance DPIA

Global
Services likely to be accessed by children

CHILD 16 core questions

Health, Genetic and Research DPIA

Global
Health, genetic, clinical and research data

HEALTH 16 core questions

CCTV and Systematic Monitoring DPIA

Global
Public spaces, workplaces and video analytics

CCTV 16 core questions

Location and Tracking DPIA

Global
Precise geolocation, telematics and movement patterns

LOC 16 core questions

Cloud, Vendor and Data Platform DPIA

Global
Cloud, SaaS, data lake and platform migration

CLOUD 16 core questions

Data Sharing and Matching DPIA

Global
Inter-agency sharing, matching and enrichment

SHARE 16 core questions

Connected Device and IoT DPIA

Global
Sensors, smart devices and ambient collection

IOT 16 core questions

US State Data Protection Assessment

United States
Sale, targeted advertising, sensitive data, profiling and ADMT

US-STATE 16 core questions

Global PIA Composite

Global
Multi-jurisdiction programme or system

GLOBAL 16 core questions

Combined DPIA and Transfer Assessment

Global
Cross-border processing and remote access

TRANSFER 16 core questions

AI Fundamental Rights Impact Assessment

EU/Global
High-impact or high-risk AI

FRIA 16 core questions
๐Ÿ›

Authority Guidance and Jurisdiction Rules

Official authority library, divergence alerts and current-status warnings for assessment decisions
Legal currency control: EDPB 2026 template is still pending finalisation. ICO guidance states it is under review following UK legislative changes. PRIVASTU records source status and requires human verification at final sign-off.

Official guidance library

11 sources

EDPB ยท EU/EEA

2026 DPIA consultation meta-template ยท Draft pending finalisation
Use with WP248 criteria. The consultation closed in June 2026 and the final common template is pending.

Open official source

ICO ยท United Kingdom

UK DPIA guidance ยท Current but under review
The ICO states its guidance is under review following the Data (Use and Access) Act. Verify current guidance before final legal sign-off.

Open official source

CNIL ยท France

AIPD method, templates and knowledge bases ยท Current
Context, fundamental principles, privacy risks and formal validation. Includes required and non-required processing lists.

Open official source

BfDI / DSK ยท Germany

DSFA and mandatory processing lists ยท Current
Structured prior risk analysis with lists for federal public bodies and non-public controllers.

Open official source

Garante ยท Italy

DPIA guidance and tools ยท Current
High-risk processing, systematic monitoring, sensitive data and innovative technologies require close assessment.

Open official source

CPPA ยท California

Risk assessment and ADMT regulations ยท Effective 1 January 2026
Final regulations cover risk assessments, cybersecurity audits and automated decisionmaking technology.

Open official source

Connecticut AG ยท Connecticut

Data protection and profiling impact assessments ยท Current
Heightened-risk processing and profiling assessments require purpose, context, data, performance, limitations, monitoring and safeguards.

Open official source

OAIC ยท Australia

10-step Privacy Impact Assessment ยท Current
Threshold, plan, describe, consult, map flows, analyse, manage, recommend, report and review.

Open official source

NZ OPC ยท New Zealand

PIA toolkit ยท Updated October 2025
Brief analysis, full PIA, risk table and review, including AI use.

Open official source

OPC Canada ยท Canada

PIA process and federal submission ยท Updated 2025
Risk-proportionate PIA before new or substantially modified programmes using personal information.

Open official source

PDPC ยท Singapore

Guide to Data Protection Impact Assessments ยท Current
Lifecycle-based assessment aligned to PDPA accountability.

Open official source

Jurisdiction decision rules

EU/EEA: assess before processing where high risk is likely. Use national Article 35 lists and consult the authority if residual high risk remains.
UK: screen for likely high risk, complete before processing and preserve DPO advice. Verify current ICO guidance at decision date.
France: apply CNIL required/non-required lists, nine criteria and the four-part AIPD method.
Germany: identify public or non-public sector and test the applicable BfDI or DSK mandatory list.
Italy: consider Garante list triggers, including innovative technologies and systematic monitoring.
US states: assess sale, targeted advertising, sensitive data, profiling and ADMT under applicable state laws. California regulations are effective from 1 January 2026.
Global PIA: add stakeholder consultation, information-flow mapping, recommendations, implementation ownership and ongoing review.

Coverage disclaimer

The library supports major authority methods and an extensible jurisdiction layer. It does not claim to reproduce every national or subnational supervisory authority document. Final legal conclusions must be verified against the authority responsible for the actual processing.

VendorCategoryData RoleRisk Tier Risk ScoreDPA StatusLast Assessed Next ReviewStatusActions
KetchPrivacy managementUSSignedYesCompleteMediumApproved
FilersKeepersRetention toolingUKIn negotiationN/APendingMediumReview
Cloud AI LabsModel hostingUSDraftRequiredOpen issuesHighBlocked

Risk Distribution

Highest Risk Vendors

Ranked by composite risk score

Risk Heat Map

Likelihood ร— Impact

DPA / Contract Status

Certification Coverage

VendorFrameworkSentDueStatusCompletionRisk findingActions

Assessment Questionnaire Library

10 governance frameworks. Click any questionnaire to preview, customise, or send. All templates use [CLIENT_ENTITY] placeholders - populated when deployed for a client.

VendorDocument typeVersionSigned dateExpiry dateStatusActions

Onboarding Pipeline

Periodic Review Schedule

Offboarding Tracker

Vendors in offboarding - data deletion confirmation, contract termination, access revocation

Risk by Category

Risk by Geography

Assessment Completion Rate

Transfer Mechanism Coverage

Board-Ready Report

Narrative summary of vendor risk posture for board or audit committee

Portal Configuration

Active Portal Sessions

Reminder Schedule

First reminder
Second reminder
Overdue escalation
Escalate to

Contracts & Data Processing Agreements

Central register of all vendor contracts, DPAs, SCCs and addenda. Expiry alerts and renewal workflow integrated.

VendorDocument typeVersionSignedExpiresSCCs / TIAData rolesJurisdictionStatus

Fourth-Party Risk

Sub-processors, nested dependencies and supply-chain relationships disclosed by your vendors. Maps concentration risk and regulatory exposure across the vendor ecosystem.

Dependency map

Vendor โ†’ sub-processor chains

Concentration risk

Sub-processors used by multiple vendors
Disclosed sub-processors
Sub-processorCountryServiceUsed by vendorsData categoriesTransfer mechanismRisk

Vendor Monitoring & Alerts

Continuous monitoring of vendor risk signals - DPA expiry, assessment overdue, security incidents, news monitoring and regulatory changes affecting your vendor base.

DPA expiries - 60 days
Assessment overdue
Risk score changes
Alert rules

Vendor Risk Reports & Analytics

Board-ready reports, regulatory compliance summaries and operational analytics across the full vendor estate.

Risk distribution

Vendors by risk level

Assessment coverage

% of vendors assessed by framework
Export report packages
PRIVASTU ยท Policy Management

Complete | Intelligent | Policy Governance

25 deployable policy templates ยท version control ยท approval workflows ยท attestation campaigns ยท cross-module intelligence ยท regulatory change tracking

โš  2 policies overdue - DSAR Handling Standard & AI Governance Standard require immediate review
โ†ป 4 policies due within 30 days - schedule reviews now to maintain compliance posture
๐ŸŒ EU AI Act Aug 2026 - AI Governance Policy template updated with Annex III FRIA requirements
โœ“ 15 policies published - core GDPR programme coverage achieved
25
Total policies
In register
22
Published
Active and current
3
In review / Draft
Need attention
1
Overdue
Past review date
11/12
Mandatory coverage
Core GDPR policies published
78%
Avg health score
Completeness index
PolicyCategoryGDPR / Legal basisMandatory OwnerVersionLast reviewedNext review AudienceStatusCross-linksActions
Master Privacy Policyv4.2Group Privacy Office2026-04-15GlobalPublished
DSAR Handling Standardv2.1Privacy Ops2026-03-30HR / LegalIn review
AI Governance Standardv1.0AI Office2026-03-25All staffDraft

25 fully deployable, GDPR-compliant policy templates. Each includes all required clauses, defined roles and responsibilities, review triggers and cross-references to related policies and modules. Click any template to view the full document.

Core GDPR Published
Privacy Policy (External)
Art. 12 - 14
Public-facing transparency notice for all personal data processing. Meets Art. 13/14 requiโ€ฆ
Mandatory
Core GDPR Published
Internal Data Protection Policy
Art. 5(2), 24
Master internal policy demonstrating accountability and governance. Sets out roles, responโ€ฆ
Mandatory
Core GDPR Published
Data Retention and Deletion Policy
Art. 5(1)(e)
Establishes maximum retention periods per data category and lawful basis, deletion schedulโ€ฆ
Mandatory
Core GDPR Published
Data Breach Response and Notification Policy
Art. 33, 34
Defines the 72-hour ICO notification process, severity classification, internal escalationโ€ฆ
Mandatory
Core GDPR In Review
Data Subject Rights Handling (DSAR) Policy
Art. 15 - 22
End-to-end procedure for handling all data subject rights requests. Covers verification, tโ€ฆ
Mandatory
Core GDPR Published
DPIA Procedure
Art. 35
Step-by-step procedure for conducting Data Protection Impact Assessments. Includes Articleโ€ฆ
Mandatory
Technical Published
Information Security Policy
Art. 32
Technical and organisational security measures for personal data processing. Aligned to ISโ€ฆ
Mandatory
Operational Published
Data Classification and Handling Policy
Art. 5, 24
Defines four-tier classification scheme (Confidential, Restricted, Internal, Public) with โ€ฆ
Recommended
Governance Published
Third-Party Processor / Vendor Management Policy
Art. 28
Due diligence requirements for appointing processors, mandatory DPA terms, sub-processor cโ€ฆ
Recommended
Governance Published
Training and Privacy Awareness Policy
Art. 24, 39
Mandatory privacy training requirements, frequency, content standards, role-specific modulโ€ฆ
Recommended
Core GDPR Published
International Data Transfers Policy
Art. 44 - 49
Lawful mechanisms for international transfers (SCCs, IDTA, BCRs, adequacy decisions, DPF).โ€ฆ
Recommended
Governance Published
Data Governance and Accountability Framework
Art. 5(2), 24
Overarching accountability framework defining privacy governance structure, RACI matrix, bโ€ฆ
Recommended
Technical Published
BYOD and Remote Working Policy
Art. 32
Security controls for personal devices, remote access, home network standards, VPN requireโ€ฆ
Recommended
Technical Published
Acceptable Use Policy (AUP)
Art. 32
Permitted and prohibited use of IT systems, data and internet access. Social media, personโ€ฆ
Recommended
Specialist Published
Cookie and Tracking Technology Policy
UK PECR / ePrivacy
Cookie categories, consent requirements under UK PECR and ePrivacy Directive, cookie noticโ€ฆ
Mandatory
Specialist Draft
AI Governance and Automated Decision-Making Policy
Art. 22 ยท EU AI Act
Governance of AI systems including Annex III high-risk AI, EU AI Act FRIA requirements, auโ€ฆ
Recommended
Core GDPR Published
Legitimate Interests Assessment (LIA) Procedure
Art. 6(1)(f)
Three-part LIA test procedure (purpose, necessity, balancing), documentation requirements,โ€ฆ
Recommended
Core GDPR Published
Consent Management Policy
Art. 6(1)(a), 7
Valid consent standards (freely given, specific, informed, unambiguous), withdrawal mechanโ€ฆ
Mandatory
Specialist Published
Children's Data and Online Safety Policy
Art. 8 ยท UK AADC
Age verification standards, UK Age-Appropriate Design Code (AADC) obligations, children's โ€ฆ
Mandatory
Specialist Published
Special Category Data Processing Policy
Art. 9, 10
Processing conditions for health, biometric, genetic, racial/ethnic origin, religious, polโ€ฆ
Mandatory
Specialist Published
Employee Monitoring and Workplace Surveillance Policy
Art. 88 ยท Employment law
Lawful basis for employee monitoring (email, internet, location, CCTV, productivity tools)โ€ฆ
Recommended
Governance Published
Privacy by Design and Default Policy
Art. 25
Privacy by design obligations for new products, systems and processes. Data minimisation dโ€ฆ
Recommended
Governance Published
Whistleblowing and Privacy Disclosure Policy
EU Whistleblower Directive ยท Art. 24
Secure whistleblowing channel governance, reporter anonymity protections, investigation daโ€ฆ
Recommended
Core GDPR Published
Records Management and RoPA Governance Policy
Art. 30, 5(2)
Standards for maintaining, updating and auditing Records of Processing Activities. Responsโ€ฆ
Mandatory
Technical Draft
NIS2 and Operational Resilience Policy
NIS2 Directive ยท Art. 32
NIS2 Directive obligations for essential/important entities: risk management, incident repโ€ฆ
Recommended

Active approval workflows

Policies currently in review or awaiting sign-off
AI Governance PolicyUrgent
9d in stage
Stage: DPO Review ยท Owner: AI Office ยท Since 12 Mar Mar
DSAR Handling Standard
3d in stage
Stage: Legal sign-off ยท Owner: Privacy Ops ยท Since 18 Mar Mar
NIS2 Operational Resilience Policy
7d in stage
Stage: CISO review ยท Owner: Security ยท Since 14 Mar Mar
Employee Monitoring Policy (update)
16d in stage
Stage: HR / Union consultation ยท Owner: HR ยท Since 05 Mar Mar

Workflow stages

Draft
Policy owner creates initial draft. AI grammar and compliance check runs automatically.
Legal / DPO review
Legal counsel and DPO review for compliance accuracy, regulatory completeness and internal consistency.
Stakeholder sign-off
Relevant department heads and CISO sign off via digital attestation. Countersignature recorded.
Published
Policy published to policy portal. Attestation campaign auto-triggered. Next review date set.

Completed reviews (this quarter)

Data Retention Policy
Approved by: DPO + Legal + Board
10 Mar Mar โœ“
Special Category Data Policy
Approved by: DPO + HR Director
02 Mar Mar โœ“
Privacy by Design Policy
Approved by: DPO + CTO
22 Feb Mar โœ“

Active attestation campaigns

Staff acknowledgement of published policies
Internal Data Protection Policy
92%
287/312 staff ยท Deadline: 31 Mar
Acceptable Use Policy (AUP)
95%
296/312 staff ยท Deadline: 31 Mar
AI Governance PolicyNew
25%
12/48 staff ยท Deadline: 14 Apr
Information Security Policy
97%
304/312 staff ยท Deadline: 01 Mar

Completion rates

Overall programme attestation: 94% of staff have acknowledged all mandatory policies. Non-completions are tracked below.
Internal Data Protection Policโ€ฆ
92%
Acceptable Use Policy (AUP)โ€ฆ
95%
AI Governance Policyโ€ฆ
25%
Information Security Policyโ€ฆ
97%

Non-completions requiring action

Staff who have not yet acknowledged mandatory policies
16 staff members have not completed all mandatory attestations. Automated reminder scheduled for 25 March.
Staff memberDepartmentOutstanding policiesAction
James T.EngineeringAI Governance Policy
Sarah M.MarketingAI Governance ยท AUP
+ 14 more ยท Export full list

PRIVASTU Policy Intelligence

AI-powered gap analysis vs GDPR, UK GDPR, EU AI Act, NIS2, ISO 27001 requirements
2
Critical gaps
3
Significant gaps
5
Minor gaps
15
Policies adequate
PRIVASTU analysis: Your core GDPR policy programme is largely in place (15 of 25 policies adequate). The two critical gaps are your AI Governance Policy (overdue - EU AI Act Annex III deadline August 2026) and the NIS2 Operational Resilience Policy (in draft - NIS2 already in force). Completing these two would raise your programme maturity from Medium to High.
Critical
EU AI Act Annex III - policy absent
AI Governance Policy is in draft with 42% health score. Three AI systems may require FRIA by August 2026. Action: Complete POL-016 immediately.
Critical
NIS2 Directive coverage gap
NIS2 Operational Resilience Policy (POL-025) is in draft. NIS2 is already in force for essential/important entities. 24-hour incident reporting obligation not yet documented.
Significant
Children's data policy health score below target
POL-019 health score 69%. UK Age-Appropriate Design Code (AADC) obligations not fully reflected. Age verification standards need updating.
Significant
DSAR Policy overdue for review
POL-005 is In Review and past its review date. DSAR Handling Standard must be current at all times given direct regulatory exposure.
Minor
LIA Procedure not cross-linked to RoPA
POL-017 health score 72%. The Legitimate Interests Assessment procedure should reference the RoPA records that use Art. 6(1)(f) as lawful basis.
Positive
Core GDPR programme: adequate
Policies POL-001 through POL-014 collectively cover all mandatory GDPR requirements. Board-level accountability framework (POL-012) is published - a differentiator from 62% of peer organisations.

Upcoming reviews - next 90 days

40
days
Acceptable Use Policy (AUP)
2026-09-01 ยท CISO / HR
70
days
Privacy by Design and Default Policy
2026-10-01 ยท DPO / Product / IT

Overdue reviews

โš 
Privacy Policy (External)
Was due: 2026-04-15
โš 
Internal Data Protection Policy
Was due: 2026-03-15
โš 
Data Retention and Deletion Policy
Was due: 2026-05-01
โš 
Data Breach Response and Notification Policy
Was due: 2026-02-01
โš 
Data Subject Rights Handling (DSAR) Policy
Was due: 2026-03-30
โš 
DPIA Procedure
Was due: 2026-01-01
โš 
Information Security Policy
Was due: 2026-04-15
โš 
Data Classification and Handling Policy
Was due: 2026-06-01
โš 
Third-Party Processor / Vendor Management Policy
Was due: 2026-03-01
โš 
Training and Privacy Awareness Policy
Was due: 2026-05-01
โš 
International Data Transfers Policy
Was due: 2026-05-01
โš 
Data Governance and Accountability Framework
Was due: 2026-04-01
โš 
BYOD and Remote Working Policy
Was due: 2026-02-01
โš 
Cookie and Tracking Technology Policy
Was due: 2026-04-01
โš 
AI Governance and Automated Decision-Making Policy
Was due: 2026-03-25
โš 
Legitimate Interests Assessment (LIA) Procedure
Was due: 2026-06-01
โš 
Consent Management Policy
Was due: 2026-03-01
โš 
Children's Data and Online Safety Policy
Was due: 2026-01-01
โš 
Special Category Data Processing Policy
Was due: 2026-02-01
โš 
Employee Monitoring and Workplace Surveillance Policy
Was due: 2026-05-01
โš 
Whistleblowing and Privacy Disclosure Policy
Was due: 2026-06-01
โš 
Records Management and RoPA Governance Policy
Was due: 2026-03-01
โš 
NIS2 and Operational Resilience Policy
Was due: 2026-06-01

Review triggers

๐Ÿ“… Annual scheduled - all policies reviewed minimum annually
โš– Regulatory change - triggered when PRIVASTU Horizon detects relevant law change
๐Ÿ”ด Incident trigger - relevant policy reviewed after any related incident
๐Ÿ”ง Process change - triggered when linked RoPA record or vendor is materially updated
๐Ÿ“‹ Assessment finding - DPIA or LIA finding triggers linked policy review
PRIVASTU ยท Global Data Retention & Destruction

Global retention intelligence and coached implementation

A jurisdiction-aware operational library, defensible retention schedule, secure disposition workflow, legal-hold register, 75-control implementation programme, role queues, evidence trail and email-ready report studio.

Reliance standard: this workspace is a global operational baseline rather than a substitute for current local legal advice. Every fixed period must be traced to its purpose, statutory floor, maximum or limitation period, sector rule, legal hold and official source before approval. Profiles marked โ€œlocal validation requiredโ€ must not be treated as final law.
143jurisdictions / states
2574obligation coverage points
61schedule rules
75programme controls
0disposition events
0active holds

Implementation position

Phase 1 ยท Foundation0% ยท 0/15 complete
Phase 2 ยท Design0% ยท 0/20 complete
Phase 3 ยท Implementation0% ยท 0/25 complete
Phase 4 ยท Validation & Maturity0% ยท 0/15 complete

Coached next steps

Approve the first schedule baseline

Select priority record classes, validate official sources and obtain owner/legal approval.

Configure legal hold governance

Create the hold roles, notice template, periodic review and formal release process.

Run a controlled disposition pilot

Select a low-complexity repository, document exclusions, validate deletion and issue a certificate.

14 rules are due for review

Revalidate purpose, law, system scope, notices and technical enforcement.

Priority legal and operational signals

Legal sources require verification

61 schedule rules remain a working baseline rather than approved local law.

Secure sanitisation assurance

Disposition method must match media type, sensitivity, recoverability and validation evidence.

Derived and replicated data

Ensure erasure propagates to backups, copies, embeddings, feature stores, exports and processors.

Over-retention risk

0 programme items are blocked, overdue or at risk; 0 are currently in progress.

Role accountability

Data OwnerConfirm purpose, record population, trigger, business need, system scope and operational impact.0 controls
Records ManagementMaintain the schedule, classification, lifecycle states, review calendar, archival decisions and evidence standards.0 controls
Privacy / DPOChallenge purpose, proportionality, transparency, rights impact, processor propagation and global consistency.75 controls
LegalIdentify statutory floors, limitation periods, privilege, litigation exposure, legal holds and local-law conflicts.75 controls
IT / SecurityTranslate approved rules into system controls, deletion jobs, backup cycles, validation and recoverability limits.0 controls
ApproverConfirm legal source, proportionality, operational feasibility, ownership, residual risk and evidence before sign-off.0 controls
AI Governance Programme Intelligence

150-control AI governance command view

The full implementation programme sits in PROPELLOR. This AI Governance view deliberately presents only the higher-level intelligence needed by AI owners, risk leaders and executive oversight: delivery health, EU AI Act readiness, AIGP coverage, critical gaps and regulator-guidance currency.

150Programme controls
0%Overall progress
0Complete
0In progress / review
0Blocked
0Overdue

Programme architecture

Strategy, Accountability & Governance
0%
AI Inventory & Classification
0%
Legal Applicability & Regulatory Change
0%
Prohibited Practices & Rights Protection
0%
High-Risk AI System Controls
0%
Data Governance & Data Quality
0%
Technical Documentation & Recordkeeping
0%
Human Oversight & Transparency
0%
Seven further programme domains are managed in the full PROPELLOR board.

Executive signals and next steps

0 blocked controls require accountable intervention.
0 controls are beyond their recommended due date.
150 controls require evidence validation or completion.
Next step: open PROPELLOR and work the current 90-day sprint, starting with critical and high-priority controls.

EU AI Act control spine

The control board covers governance, prohibited practices, high-risk systems, GPAI, transparency, data governance, technical documentation, logging, human oversight, accuracy, robustness, cybersecurity, conformity, registration, post-market monitoring and incidents.
15 domains12 sprints4 phases150 controls

Regulator and professional interoperability

Every control retains its IAPP AIGP domain, competency and performance indicator mapping. The programme also contains the reviewed European DPA guidance library and control-level mapping from EDPB, ICO, CNIL, Garante, German DSK and other European authorities.
27 DPA sources4 AIGP domainsEU AI Act articles

AI Use Detection & Discovery

Discover, evidence and govern potential AI usage across documents, websites, software artefacts and enterprise workflows. Technical evidence is separated from probabilistic indicators and all conclusions remain subject to human validation.

2SCANS COMPLETEDFiles, URLs and evidence bundles
1CONFIRMED AI USESDirect machine-verifiable evidence
0SHADOW AI SIGNALSUnapproved or unregistered use
3AWAITING REVIEWHuman validation required

1. Upload documents or technical artefacts

Select files first. Nothing is analysed until the visible Submit & Scan button is pressed.

โŒ
Drop files here or click to choose PDF, DOCX, PPTX, XLSX, HTML, JSON, source code, manifests, images and evidence bundles
No files selected

2. Website, URL or pasted source assessment

Enter a URL and optionally paste source, a manifest, policy text or a network extract to materially strengthen the evidence scan.

3. Scan context and governance routing

Preparing scan0%

Evidence findings

Review each signal, validate or reject it and route confirmed use into governance.

SourceFindingEvidenceConfidenceRiskReview statusActions
DORA Implementation Plan.docx
22/07/2026, 15:59:14
No reliable AI indicator found
No finding
The extracted material did not contain direct or corroborating evidence. This is not proof that AI is absent.Inconclusive
12%
LowRouted to AI Governance
LOA Master Classification Tool - Operational Guide & Technical Analysis.pdf
22/07/2026, 11:15:15
AI subject-matter reference
AI subject matter
Matched ai subject matter indicator โ€œAI-poweredโ€ in extracted document content.Indicative
48%
LowAwaiting human review
LOA Master Classification Tool - Operational Guide & Technical Analysis.pdf
22/07/2026, 11:15:15
Planned or future AI capability
Planned AI
Matched planned ai indicator โ€œPhase 1: Manual Foundation (Current Implementation) 247 core elements pre-classโ€ in extracted document content.Strongly indicated
78%
MediumAwaiting human review
LOA Master Classification Tool - Operational Guide & Technical Analysis.pdf
22/07/2026, 11:15:15
Explicit rule-based or non-AI disclosure
Non-AI disclosure
Matched non-ai disclosure indicator โ€œSIMULATION ONLYโ€ in extracted document content.Confirmed
92%
LowAwaiting human review

Shadow AI discovery

Signals from unapproved providers, API keys, model endpoints, AI-enabled SaaS features, agent frameworks and unregistered workflows.

No shadow AI signals detected.

Content provenance laboratory

Metadata, generator identifiers, content credentials, revision artefacts, AI disclosures and synthetic-content indicators are shown separately from technical proof of AI system use.

No provenance or synthetic-content indicators recorded.

AI Use Detection Report Studio

Generate the same two output formats used throughout AI Governance.

Two report outputs are available for every report type. Structured HTML is optimised for working review, evidence interrogation and data extraction. Polished HTML uses the high-spec PRIVASTU presentation format with a branded cover, executive summary, analysis cards, detailed evidence tables, methodology, reliance statement and print-ready styling.
โ—‰

Complete AI Use Discovery Report

All scans, findings, evidence strength, governance triggers and recommended actions.

โ—†

Executive AI Discovery Summary

Board-ready exposure, confidence, shadow AI and remediation priorities.

โ–ค

Document and Artefact Assessment

File-level technical indicators, metadata, provenance and limitations.

โ—Ž

Website AI Surface Report

URL, source, endpoint, SDK, disclosure and crawler escalation evidence.

โŒ

AI Evidence Chain Report

Traceable evidence hierarchy, confidence rationale and reviewer status.

โ—

Shadow AI Exposure Report

Unapproved services, model endpoints, API-key indicators and ownership gaps.

โ—‡

Content Provenance Report

Metadata, C2PA-style indicators, generator references and authenticity limits.

โ–ฆ

AI System Bill of Materials

Providers, models, frameworks, tools, vector stores and detected dependencies.

โš–

Regulatory Trigger Assessment

Potential EU AI Act, UK GDPR, DPIA, FRIA, transparency and vendor triggers.

โœ“

Registration and Remediation Plan

Prioritised actions, accountable owners, evidence requests and closure route.

โ—Ž

AI Infrastructure Intelligence Map

Trace each AI system and agent through models, data stores, APIs, cloud regions, edge infrastructure, satellite links, encryption keys and human control points. Evaluate sovereignty, concentration, resilience, change impact and regulatory evidence from one governed map.

Global Geographic Intelligence Console

Infrastructure, AI, physical routes, sovereignty, resilience, incidents and accountability in one governed layer

Visible points12
High / critical6
Countries12
Single points of failure4

Ask the globe

Select layers or ask a geographic governance question.
2026

Scenario simulation

No scenario active.

Priority geographic signals

Open AI Transfer Finding ยท 86Unresolved transfer evidence and provider-change exposure
LEO AI Telemetry Satellite ยท 74Onboard anomaly detection ยท signed telemetry ยท ground-controlled keys
Virginia Foundation Model Endpoint ยท 72External LLM API ยท transfer and subprocessor controls
Cape Town Warm Disaster Recovery ยท 67Encrypted recovery copies ยท tested restoration required
Singapore Edge Inference ยท 61Local intent classification and minimisation
Frankfurt High-Risk Cluster ยท 58Restricted Annex III workloads

Incidents

Response and escalation
Incident response is tracking 3 live records. Immediate focus should remain on escalated matters, running regulatory clocks and repeat control failures.
ReferenceIncidentSeverityJurisdiction72h ClockOwnerStatus
INC-1442Misdirected email with HR dataMediumUKRunningSecurityInvestigating
INC-1443Lost encrypted laptopLowFranceNot startedITContained
INC-1444Improper access to customer exportHighGermanyRunningPrivacy + LegalEscalated
๐Ÿ“Š

PRIVASTU Reports

12 board and compliance reports ยท Live data ยท ICO-aligned

12
Reports Available
Live
Data Source
ICO
Aligned
๐Ÿ“Š
Loading Report Suite
Privacy Risk ยท DSAR Pipeline ยท Breach Log ยท Consent Health ยท Maturity Score
๐Ÿงฐ

Toolkits & Decision Pathways

Interactive decision trees, guided wizards, and visual tree builder for building your own

Interactive Decision Trees

Step-by-step guided pathways for complex privacy decisions. Each tree captures reasoning, suggests actions, and documents outcomes.

โš–๏ธ
Lawful Basis Finder
Which of the 6 lawful bases applies to your processing activity? Walks through consent, contract, legal obligation, vital interests, public task, legitimate interests.
5 stepsArt 6GDPR
๐Ÿ”
DPIA Trigger Tool
Is a Data Protection Impact Assessment required? Tests against the 9 WP29 criteria and Art 35(3) high-risk triggers.
6 stepsArt 35WP29
โฐ
Retention Period Calculator
Determine a safe, defensible retention period for a data category considering legal, operational, and disposal obligations.
4 stepsArt 5(1)(e)
๐Ÿšจ
72h Breach Notifier
Was this incident a personal data breach? Must we notify the supervisory authority within 72 hours? Must we notify affected individuals?
5 stepsArt 33/34
๐Ÿ›ก๏ธ
International Transfer Safeguards
Can we lawfully transfer personal data out of the UK/EEA? Adequacy decisions, SCCs, BCRs, and derogations.
5 stepsCh. V
โœ…
Is Consent Valid?
Test consent against GDPR's strict validity requirements: freely given, specific, informed, unambiguous and with a clear affirmative action.
5 stepsArt 7
๐Ÿ‘ค
DSAR Response Type
Identify whether this is an access, rectification, erasure, restriction, portability, or objection request, and the right response path.
5 stepsArt 15-22
โœฆ
EU AI Act Risk Classifier
Determine whether an AI system is prohibited, high-risk, limited-risk or minimal-risk under the EU AI Act.
5 stepsEU AI Act
โš ๏ธ
Article 9 Condition Finder
Walk through all Article 9(2) conditions and identify the evidence and safeguards needed.
9 stepsArt 9GPO Data Hub
๐Ÿ’ผ
Vendor Risk Tier
Classify processors into critical, elevated, standard or no-personal-data tiers.
4 stepsArt 28GPO Data Hub
๐Ÿช
Cookie Classification
Classify essential, exempt analytics, consented analytics and marketing technologies.
3 stepsPECRGPO Data Hub
๐Ÿ”’
LOA / Restricted Data Router
Apply the dual-track LOA and privacy routing model to US and restricted data.
4 stepsLOAGPO Data Hub

Visual Decision Tree Builder

Build your own custom decision trees. Add questions, options, and outcomes. Save, export, and deploy to the gallery.

Add Nodes

Templates

Blank TreeStart from scratch
Yes/No TemplateBinary decision path
Multi-choice Template4-option branching
Scored AssessmentCumulative risk scoring

My Trees

๐ŸŒฒ
No tree yet
Click "+ New Tree" or choose a template to begin building

Tree Settings

Selected Node

Select a node to edit
๐Ÿ“˜
Privacy Fundamentals
8 modules ยท ~4 hours ยท Foundation-level certification covering GDPR principles, data subject rights, lawful bases, and privacy by design.
๐ŸŽ“
DPO Certification
16 modules ยท ~32 hours ยท Professional certification aligned to IAPP CIPP/E syllabus. DPO responsibilities, Art 35, international transfers, enforcement.
โœฆ
AI Governance
10 modules ยท ~18 hours ยท EU AI Act readiness, risk classification, conformity assessments, transparency, and AI system registration.
๐Ÿšจ
Incident Response
6 modules ยท ~8 hours ยท 72-hour breach workflow, containment, impact assessment, regulator and individual notification templates.

Controller / Processor Role Qualification

A seven-stage operational assessment for controller, processor, joint-controller, independent-controller and layered-role determinations. It includes all 27 EU Member States, national supplementary-law prompts, sector overlays, clause guidance, a polished result page and full report exports.

27EU Member State supplementary-law and DPA contexts
29Sector contexts with relevant EU instruments and role questions
7Guided stages from scope through determination and record
8Operational outputs including polished and structured HTML, JSON, Word-style, CSV and clause packs
Use: assess one defined processing operation at a time. The tool preserves the factual GDPR purpose and essential-means test then adds country, employment, health, financial, communications, public-sector, AI, cybersecurity and product-law context. Local legal verification remains required.
โš–
Role Qualification Workspace
Select Load workspace to initialise the full assessment.
โš–๏ธ

Decision Tree

Step through each question

Your Path

Settings
Connectivity
Governance
Display
Deployment

Settings Operations Centre

Govern organisation structure, access, integrations, alerts, deployment and evidence from one controlled workspace.

0Entities and sites
0Users
0Connected systems
0Enabled frameworks
0Active alert rules

Organisation

Core identity, legal entity and primary contacts.

Identity

Data Protection Officer

Global Corporate Hierarchy

Build your multi-entity structure - parent group, subsidiaries, branches and joint ventures. Each entity inherits or overrides its privacy configuration.

Users & Roles

Manage system users, invite team members, assign roles that propagate permissions across all modules.

UserEmailRoleEntityStatusLast activeMFA
Stewart Haynes
s.haynes@example.com Super Admin PRIVASTU Group Ltd Active Today On
Anna Mรผller
a.muller@eu.example.com DPO / Privacy Lead PRIVASTU EU GmbH Active Yesterday On
James Chen
j.chen@sg.example.com Privacy Manager PRIVASTU Asia Pte Ltd Active 2 days ago Off
Sarah Okafor
s.okafor@example.com Legal Counsel PRIVASTU Group Ltd Active 3 days ago On
Mark Rossi
m.rossi@eu.example.com CISO / Security PRIVASTU EU GmbH Inactive 2 weeks ago Off

Role Management

Define roles, set module-level permissions, control what each role can see, create, edit and approve across the system.

Super Admin
Full system access - all modules, settings and user management.
Data Mapping: fullDSAR: fullAssessments: fullVendors: fullSettings: fullSignals: full
DPO / Privacy Lead
All privacy modules. Full read/write on assessments, RoPA, DSAR and signals. No settings.
Data Mapping: fullDSAR: fullAssessments: fullVendors: fullSettings: readSignals: full
Privacy Manager
Operational privacy management. Create and edit records. No system settings.
Data Mapping: fullDSAR: fullAssessments: fullVendors: readSettings: noneSignals: read
Legal Counsel
Read access to all modules. Can comment on assessments and sign off on LIAs/DPIAs.
Data Mapping: readDSAR: readAssessments: fullVendors: readSettings: noneSignals: read
CISO / Security
Access to incidents, vendor risk, AI governance and security-relevant assessments.
Data Mapping: readDSAR: readAssessments: readVendors: fullSettings: noneSignals: read
HR Administrator
Access to DSAR (employee requests), training and people-related RoPA records only.
Data Mapping: restrictedDSAR: fullAssessments: readVendors: noneSettings: noneSignals: none
Read Only
View all privacy records. Cannot create, edit, or approve anything.
Data Mapping: readDSAR: readAssessments: readVendors: readSettings: noneSignals: read

APIs & Integrations

API keys, webhooks and SSO configuration.

REST API Keys

Production API Key
prv_prod_โ€ขโ€ขโ€ขโ€ขโ€ขโ€ขโ€ขโ€ขโ€ขโ€ขโ€ขโ€ขโ€ขโ€ขโ€ขโ€ขโ€ขโ€ขโ€ขโ€ขโ€ขโ€ขโ€ขโ€ข
Sandbox API Key
prv_test_โ€ขโ€ขโ€ขโ€ขโ€ขโ€ขโ€ขโ€ขโ€ขโ€ขโ€ขโ€ขโ€ขโ€ขโ€ขโ€ขโ€ขโ€ขโ€ขโ€ขโ€ขโ€ขโ€ขโ€ข
Endpoint: https://api.privastu.com/v1/

Webhooks

https://hooks.slack.com/services/T00/B00/xxxโ€ฆ
Events: New DSAR, Incident escalation
Active
https://outlook.office.com/webhook/xxxโ€ฆ
Events: Assessment overdue
Inactive

SSO / OAuth

Data Import & Export

Bulk import records and export the full privacy estate for audit or migration.

Import by module

โ–ฃ
RoPA / Data Mapping
CSV or XLSX with processing activities, purposes, legal bases and transfers.
๐Ÿ‘ค
DSAR Register
Existing DSAR records with requester, type, status and deadline.
โ–ฅ
Vendor Register
Vendor list with DPA status, risk tier and service details.
โ–ค
Assessment Register
DPIA, LIA, TRA records with status, owner and risk rating.
โš 
Incident Log
Historic incidents with severity, status and jurisdiction.
โ‰ฃ
Policy Library
Policy metadata including version, owner, review dates.

Export

Import history

System Connectors

Pre-built integrations with enterprise systems to keep PRIVASTU data current automatically.

โ˜
Salesforce
CRM
Connected
Processing activities, data subject lists and vendor contracts
Last sync: 2 hours ago
๐Ÿ‘ฅ
Workday
HRIS
Connected
Employee and applicant data, processing activities, training records
Last sync: 4 hours ago
๐Ÿ”ง
ServiceNow
ITSM
Connected
Incident records, case data and DSAR workflow integration
Last sync: 1 hour ago
โ„
Snowflake
Data Warehouse
Attention
Analytics and AI model feature data - transfer and minimisation review
Last sync: 3 days ago
๐Ÿ”
Microsoft Azure AD
Identity
Connected
Single sign-on, user provisioning and group-based role assignment
Last sync: Active
๐Ÿ’ฌ
Slack
Notifications
Connected
Deadline alerts, new DSAR notifications and system health alerts
Last sync: Active
๐Ÿ“‹
Jira / Confluence
Project Management
Not connected
Assessment tasks, remediation tickets and policy approval workflows
๐Ÿ”’
OneTrust
Privacy Platform
Not connected
Data migration and RoPA import from existing OneTrust implementation
โœ
DocuSign
eSignature
Not connected
DPA and assessment approval workflows with digital signatures

Compliance Frameworks

Select applicable frameworks. Obligations, triggers and DPA guidance surface throughout the product.

EU GDPR EU
General Data Protection Regulation (EU) 2016/679
UK GDPR + DPA 2018 UK
UK post-Brexit data protection regime
CCPA / CPRA US
California Consumer Privacy Act and Privacy Rights Act
Brazil LGPD Brazil
Lei Geral de Proteรงรฃo de Dados Pessoais
PDPA (Singapore) APAC
Personal Data Protection Act 2012 (amended 2020)
APPI (Japan) Japan
Act on the Protection of Personal Information (amended 2022)
POPIA (South Africa) Africa
Protection of Personal Information Act 2013
PDPL (Saudi Arabia) MENA
Personal Data Protection Law 2021
India DPDP Act 2023 India
Digital Personal Data Protection Act 2023
Switzerland nFADP Switzerland
Revised Federal Act on Data Protection (2023)
EU AI Act EU
EU Artificial Intelligence Act 2024
NIS2 Directive EU
Network and Information Security Directive 2022

Notifications & Alerts

Alert triggers, recipients and channels.

Channels

Alert rules

DSAR approaching deadline (7 days)
Email + Slack โ†’ DPO, Privacy Manager
New high-risk incident logged
Email + Slack โ†’ DPO, CISO
Assessment overdue
Email โ†’ DPO
Vendor DPA expiring (30 days)
Email โ†’ Privacy Manager
Training completion below 80%
Email โ†’ HR Administrator

Audit Log

Immutable record of all actions, data changes and user activity. Exportable for regulatory and internal audit.

TimestampUserModuleActionRecordIP
2026-03-21 09:14 Stewart Haynes DSAR Manager Record created PRIV-DSAR-20260321-X9B3 192.168.1.10
2026-03-21 09:00 Anna Mรผller Assessment Manager Status updated AM-004 โ†’ Mitigation Planning 10.0.1.45
2026-03-20 16:30 System Vendors DPA expiry flagged Cloud AI Labs - DPA due for renewal -
2026-03-20 15:44 James Chen Data Mapping Record updated Behavioural Analytics - risk HIGH 172.16.0.22
2026-03-20 14:12 Sarah Okafor Incidents Severity escalated INC-1444 โ†’ Critical 192.168.1.15
2026-03-20 11:00 System Training Completion milestone DSAR Handling - 74/82 complete -
2026-03-19 09:30 Stewart Haynes Settings User invited mark.rossi@eu.example.com 192.168.1.10

Deployment Setup

Configure PRIVASTU for client deployment - environment, licensing, onboarding and go-live checklist.

Environment

Client onboarding checklist

Licence & subscription

Security & Authentication

MFA, session controls and access restrictions.

Authentication

Enforce MFA for all users
Required for all roles on first login.
SSO required (disable password login)
Force all users through SSO provider.
IP allowlist enforcement
Restrict access to approved IP ranges only.

Session & password policy

Branding

Customise PRIVASTU for your organisation or client. Applied to reports, exports and the portal header.

Identity

Live preview:
P
PRIVASTU
360ยฐ Enterprise Privacy Management

Environment Status

Live health indicators for all PRIVASTU system components.

System information

Tint My Display

Personalise your workspace - themes, tints, layout and font size. All changes apply instantly.

Theme presets

Deep Space
Default dark
Midnight
Rich dark blue
Obsidian
Near-black grey
Forest Night
Eye-friendly green
Aurora
Deep teal dark
Dusk
Warm purple dark
Solar Dark
Amber warm dark
Eye Comfort
Low-contrast warm
Slate
Blue-grey pro
Light
Clean light mode
Light Warm
Warm paper white
High Contrast
Max readability

Tint colour

Apply a colour wash over your display. Adjust intensity with the slider.

Custom:

Navigation layout

Left sidebar
Default PRIVASTU layout
Right sidebar
Content-first view
Top navigation
Max vertical space

Font size & density

12px18px
\n\n"); function _go(){ var fr = document.getElementById('lms-iframe'); if(!fr || fr.getAttribute('data-ok')) return; fr.setAttribute('data-ok','1'); try { fr.src = URL.createObjectURL(new Blob([_d],{type:'text/html;charset=utf-8'})); } catch(e) { try { fr.contentDocument.open(); fr.contentDocument.write(_d); fr.contentDocument.close(); } catch(e2) { fr.srcdoc = _d; } } } window._privaLmsInit = function(){ setTimeout(_go, 80); }; })(); \n\n"); function _initLMS(){ var fr = document.getElementById('lms-iframe'); if(!fr || fr.getAttribute('data-lms-ok')) return; fr.setAttribute('data-lms-ok','1'); try { var blob = new Blob([_lmsData], {type:'text/html;charset=utf-8'}); fr.src = URL.createObjectURL(blob); } catch(e) { try { fr.contentDocument.open(); fr.contentDocument.write(_lmsData); fr.contentDocument.close(); } catch(e2) { fr.srcdoc = _lmsData; } } } window._privaLmsInit = function(){ setTimeout(_initLMS, 80); }; window._initLMS = _initLMS; })(); '; // -- DOWNLOAD -------------------------------------------------------------- var blob = new Blob([html], {type:'text/html;charset=utf-8'}); var url = URL.createObjectURL(blob); var a = document.createElement('a'); a.href = url; a.download = filename; a.style.display = 'none'; document.body.appendChild(a); a.click(); setTimeout(function(){ document.body.removeChild(a); URL.revokeObjectURL(url); }, 1000); if (window.pvRBACToast) pvRBACToast('Report downloaded: ' + filename, '#22c55e'); }; })();
SA Super Admin โ–ผ
P
Processingโ€ฆ