
When is a DPIA required?
Under GDPR Article 35, a DPIA is mandatory whenever processing is likely to result in a high risk to individuals — in particular:- Systematic and extensive automated decision-making with legal or similarly significant effects (credit decisions, hiring, insurance pricing)
- Large-scale processing of special category data (health, biometric, racial or ethnic origin, religious beliefs) or criminal-offense data
- Systematic monitoring of publicly accessible areas on a large scale
When two or more indicators apply, most DPAs expect a DPIA. When in doubt, screen — the screening record itself is evidence of a working accountability process.
Screening questions
Every new processing activity in your data map is evaluated automatically against EDPB criteria and your national DPA’s lists. You can also screen manually:Answer the screening questionnaire
Short, plain-language questions about the processing — scale, data categories, subjects, technology, and effects. Most answers pre-fill from the data map.
Get a determination
TruePrivacy records one of three outcomes: DPIA required, DPIA recommended, or not required — with the rationale mapped to the criteria that fired.
The assessment flow
Assessments are template-driven: start from the standard EDPB-aligned template, a template from your DPA, or one created from a previous assessment for similar processing (shared sections pre-fill; reviewers confirm each is still accurate for the new context).Describe the processing
Nature, scope, context, and purposes. Data categories, systems, retention, and third parties pre-fill from the data map — you focus on analysis, not data gathering.
Assess necessity and proportionality
Document the legal basis, why the processing is necessary for the purpose, and why less intrusive alternatives are insufficient.
Identify risks to individuals
Enumerate risks — unauthorized access, discrimination, loss of control, re-identification — from the perspective of the data subject, not the business.
Score each risk
Rate likelihood and severity on the risk matrix (below). The overall assessment score updates live as risks are added and scored.
The risk scoring matrix
| Minimal severity | Significant | Severe | Maximum | |
|---|---|---|---|---|
| Highly likely | Medium | High | Critical | Critical |
| Likely | Low | Medium | High | Critical |
| Possible | Low | Medium | High | High |
| Unlikely | Low | Low | Medium | High |
Mitigations
- Mitigations are tracked tasks — owner, deadline, status, evidence attachments — not bullet points in a document.
- Completed mitigations lower the residual score; overdue ones escalate to the assessment owner.
- Risks and mitigations feed the organizational privacy risk register, alongside vendor risk and AI governance findings.