Free Tool

Data Protection Impact Assessment (DPIA) Template
fourteen sections aligned with GDPR Article 35 and 36, ISO/IEC 27701, NIST Privacy Framework, and adjacent regimes

A free, copy-ready GDPR Article 35 DPIA template. Fourteen structured sections covering controller and DPO identity, processing description with explicit Article 35(3) and WP248 trigger record, lawful basis per purpose with Article 9 and Article 10 conditions, necessity and proportionality assessment with Article 22 automated decision-making coverage, data flow map and processor list with Article 28 DPA and international transfer mechanism references, risk identification per data subject category against Recital 75 harm categories, four-by-four likelihood-by-severity risk evaluation matrix with inherent and residual columns, controls and safeguards per risk with named operational status, consultation with DPO and data subjects under Article 35(2) and 35(9), Article 36(1) prior consultation decision with forced four-state selection and sign-off lock, scheduled review cadence and event triggers under Article 35(11), named sign-off chain across controller representative, DPO, joint controllers, and stakeholders, cross-references to data classification, retention, vendor risk, and adjacent privacy and security artefacts, and document control with retention and disposal rules. Aligned with GDPR Article 35 and 36, UK GDPR with ICO mandatory list, ISO/IEC 27701:2019 Clause 6.15.1.1 and Annexes A.7.2.5 and B.8.2.1, ISO/IEC 29134:2017, NIST Privacy Framework v1.0, NIST SP 800-53 Rev. 5 PT-2 and PT-3 and RA-8, EU AI Act Article 27 fundamental rights impact assessment where applicable, Brazil LGPD Article 38, California CPPA risk assessments, China PIPL Article 55 to 56, and Korea PIPA Article 33. Built for privacy programme leads, data protection officers, GRC and compliance teams, product security teams, AppSec teams, internal security teams, cloud security teams, data security teams, CISOs and security directors, security architects, security programme managers, legal counsel, and external compliance consultants who need a defensible Article 35 artefact rather than a checkbox.

No credit card required. Free plan available forever.

Loading tool...

Hold the DPIA portfolio on the same workspace as the security findings it depends on

SecPortal pairs every DPIA review to an engagement record so the controller representative sign-off, the DPO advice, the prior consultation decision, the residual-risk read, and the controls evidence chain all live on one workspace with named-actor activity log. Free plan available.

No credit card required. Free plan available forever.