workflow

DPIA / Privacy Impact Assessment

GDPR Article 35 data protection impact assessment as a decision-aware workflow, run on the existing Process item (process_type=business_process) that represents the processing activity under assessment — the Process item doubles as the AssureSwarm proxy for the activity's records-of-processing (RoPA) entry, and the instance enriches it rather than creating a duplicate. It draws on upstream evidence — the RoPA extract, the data inventory and data-flow map, the Article 28 processor arrangements and transfer impact assessment from vendor due diligence, and the security risk assessment for the hosting systems — and moves the activity from screening, through necessity and proportionality and privacy-risk treatment, to a residual-risk decision with Article 36 prior consultation where needed and DPO sign-off. The named deliverable is the signed, versioned DPIA package (or, on the screened-out path, a defensible screening memo), registered against the Process item with tracked mitigation actions; close-and-archive hands that package off to records-of-processing maintenance. In scope: one processing activity (or a set of similar operations with comparable risks per Article 35(1)) from screening through sign-off; out of scope: the related workflows it draws on or feeds — vendor due diligence for new processors, transfer impact assessment for third-country transfers, security risk assessment for the hosting systems, and the records-of-processing maintenance that absorbs the outcome.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
reg
department
privacy
lineOfDefense
operate

Details

teams
  • privacy
domains
  • reg
standards
  • gdpr
sourceTemplateId
workflow-library:reg-dpia-privacy-impact-assessment
releaseId
sha256:067c568dd4441d2e2af151c0e54d600bf0756560cae3f64ccce9b450523a9e04
canonicalUrl
https://workflow-library.com/all/?w=reg-dpia-privacy-impact-assessment
capabilities
    mappingStatus
    mapped
    lineOfDefense
    operate
    controls
    • UC-RISK-16
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:067c568dd4441d2e2af151c0e54d600bf0756560cae3f64ccce9b450523a9e04

            Connections