Data Protection Impact Assessment
DPIA Questionnaire
A working questionnaire built from the EDPB's official DPIA template (v1.0, adopted 10 March 2026). Work through it section by section: start with the overview of the processing, then move into the detailed analysis, risk assessment, and final decision.
01
Overview
Who the controller and processors are, what the processing is called, and why a DPIA is being carried out.
02
Detailed analysis
The processing itself, its lawfulness, necessity and proportionality, and the compliance measures in place.
03
Risk & decision
Inherent and residual risk, the mitigation plan, and the final decision on whether the processing can proceed.
0
Overview of the processing
0.1 Controller(s)
If there are joint controllers, add one entry per controller and describe their respective obligations and tasks.
| Controller name | Management units responsible for the processing inside the organisation | Main establishment / point of contact or representative | DPO or similar function, if applicable |
|---|
0.2 Processor(s) and sub-processor(s)
| # | Processor | Definition of their obligations and tasks |
|---|
0.3 Name of the processing
0.4 Planning of the processing
0.5 DPIA technical sheet
1
Systematic description of the processing
1.1.a Processed personal data
| # | Processed personal data (item or element) | Explanation (data type, data subject category, details) | Special category |
|---|
1.1.b Purposes of the processing
| # | Purpose: specific and explicit reason for processing | Personal data involved (from 1.1.a) and justification |
|---|
1.1.c Secondary or compatible uses
| # | Secondary or compatible use of the data | Personal data involved, conditions, and compatibility assessment |
|---|
1.1.d Nature, scope and context of the processing
1.2 Functional description
Ideally supplement this table with one or more data-flow diagrams.
| # | Processing phase or stage | Type of operation(s) | Explanation |
|---|
1.3 Means of processing, supporting assets and underlying architecture
| # | Processing phase or stage (from 1.2) | Means of processing and supporting assets | Explanation |
|---|
1.4 Compliance with approved codes of conduct
| # | Code of conduct | Status | Why? |
|---|
2
Analysis of the processing
2.1.a Legal basis
One row per purpose/use from 1.1.b and 1.1.c.
| # | Purpose / use | Legal basis (Art. 6(1) GDPR) | Justification (analyse legitimate interests / balancing test where relevant) |
|---|
2.1.b Reasons to lift the processing prohibition
Only needed for special categories of data (Art. 9) identified in 1.1.a.
| # | Special category of data (from 1.1.a) | Reason to lift prohibition (Art. 9(2)) | Justification |
|---|
2.2.a Data minimisation and retention periods
| # | Processed personal data | Justification of need/relevance | Recipients | Justification | Retention period | Justification |
|---|
2.2.b Data quality
| # | Processed personal data | Quality metrics, requirements or thresholds | Justification |
|---|
2.3.a Measures supporting compliance with Article 5(1)(a-f) GDPR principles
2.3.b Measures supporting the exercise of data subjects' rights
2.3.c Measures supporting compliance with other GDPR requirements
2.3.d Measures supporting data protection by design and by default (Art. 25)
| # | List of supporting measures | Discussion of appropriateness and effectiveness | Status |
|---|
2.3.e Measures supporting security of processing (Art. 32)
| # | List of supporting measures | Discussion of appropriateness and effectiveness | Status |
|---|
3
Considerations on necessity and proportionality
3.1 Impacts of the processing on the rights and freedoms of data subjects
| # | Threats posed by the processing as designed (incl. mitigating measures) | How can it be materialised? | Risk sources (purpose, wrong design, weaknesses, exposures) | Impact on rights and freedoms |
|---|
3.2 Assess the necessity of the processing
3.3 Assess the proportionality of the processing
4
Risk assessment and management
4.1.a Impacts caused by non-default, accidental, unlawful or abnormal events
Identify, at minimum, threats that could lead to illegitimate access, undesired modification, or disappearance of data.
| # | Threats (malfunctions, deviations, CIA/cybersecurity threats) | How can it be materialised? | Risk sources (exposures, errors, vulnerabilities) | Impacts on rights and freedoms |
|---|
4.1.b Method
4.1.c Inherent risk assessment
| # | Risk to rights and freedoms (from 3.1 / 4.1.a) | Likelihood | Severity | Modulating factors | Risk level | Acceptable? |
|---|
4.2.a Additional mitigating measures
| # | Type of measure | Measure(s) | Mitigated risks (from 4.1.c) | Discussion of appropriateness and effectiveness | Status |
|---|
4.2.b Residual risk assessment
| # | Reassessed risk | Additional mitigating measures applied | Residual likelihood | Residual severity | Residual risk level | Acceptable? |
|---|
4.2.c Plan
5
Involvement of interested parties
5.1 DPO advice
5.2 Views of data subjects or their representatives
6
Conclusion and decision
Based on the assessment of risks and rights, select the decision taken.
| # | Condition |
|---|