A screening that ends cleanly either way
Conditional logic turns one answer into two paths. No leaves a dated screening record with the DPO’s view, which WP248 expects; Yes opens the full assessment. Every project that was screened leaves evidence.
This free DPIA checklist is for DPOs, privacy leads and project owners in organisations subject to the EU GDPR, the UK GDPR or both. It runs one assessment for one project: screening against Article 35(3), the authority lists and the nine EDPB criteria, then the description of the processing, consultation, necessity and proportionality, risks and measures, and sign-off. Where high risk remains, it takes you through prior consultation under Article 36. The result is a signed DPIA, or a dated record of why none was needed.
Article 35(1) requires a DPIA before any processing that is likely to result in a high risk to people’s rights and freedoms, in particular where new technologies are used. Article 35(3) names three cases that always qualify, and each supervisory authority publishes its own list under Article 35(4). The Article 29 Working Party’s guidelines (WP248 rev.01, endorsed by the EDPB on 25 May 2018) add nine criteria: evaluation or scoring, automated decisions with legal or similar effect, systematic monitoring, sensitive or highly personal data, large scale, matching or combining datasets, vulnerable people, innovative technology, and processing that stops people using a right, service or contract.
The usual failure is timing. WP248 says to start the DPIA as early as practicable and treat it as a continual process, not a one-off. One assessment may cover a set of similar operations with similar high risks. The annual GDPR Compliance Audit Checklist checks that your DPIA register is complete; this template produces each entry in it.
Who: the controller, seeking the DPO’s advice where one is designated; processors must assist (Article 28(3)(f)).
Contains at least: a description and the purposes, necessity and proportionality, the risks to individuals, and the measures to address them (Article 35(7)).
Review: at least when the risk changes (Article 35(11)).
Trigger: the DPIA shows high risk that your own measures cannot bring down.
Send: roles of controllers and processors, purposes and means, safeguards, DPO contact details, the DPIA and anything else requested (Article 36(3)).
Reply: written advice within up to eight weeks, extendable by six for complex processing.
The DUAA left the UK DPIA and prior consultation duties in place. Since 30 September 2026 both articles name the Information Commission, still known as the ICO. The ICO’s own list adds ten types of processing, including biometrics, invisible processing and tracking, and its DPIA guidance is marked as under review because of the Act. The earlier Data Protection and Digital Information Bill would have replaced DPIAs with a narrower assessment; it fell when Parliament was dissolved in May 2024.
If the project deploys a high-risk AI system, Article 26(9) of the EU AI Act tells deployers to use the provider’s instructions for use in their DPIA. Some deployers will also need a fundamental rights impact assessment from 2 December 2027, which can cross-refer to the DPIA. The EU AI Act Compliance Checklist covers that side.
One checklist per project. The screening answer decides whether the full assessment appears, and the residual risk answer decides whether prior consultation does.
The fourth task asks whether a DPIA is required. No shows only the screening record; Yes opens Phases 2 to 7.
Article 35(7)(a). Shown only when the screening says a DPIA is required, as are Phases 3 to 7.
Article 35(2), (7)(b) and (9).
Article 35(7)(c). The risks are to the people whose data it is, not to the organisation.
The residual risk answer decides whether Phase 6 appears. Both sign-offs are approvals assigned to the people named on the first task.
Shown only when the residual risk is still high. Due dates run from the date the request is submitted.
Article 35(11) asks for a review at least when the risk changes; the last task sets the triggers.
The table maps each DPIA rule to its source in each regime and to the phase that records the evidence. National lists and sector rules can add to it, so treat the table as a starting point, not legal advice.
| Requirement | EU GDPR | UK GDPR | Evidenced in |
|---|---|---|---|
| When a DPIA is required | Art. 35(1) and (3); WP248 criteria | Same articles; ICO guidance | Phase 1 |
| Authority lists | Art. 35(4)–(5): each supervisory authority | Art. 35(4)–(5): the Information Commission | Phase 1 |
| DPO advice and monitoring | Arts. 35(2) and 39(1)(c) | Same | Phases 3 and 5 |
| Processor assistance | Art. 28(3)(f) | Same | Phase 2 |
| Minimum content | Art. 35(7)(a)–(d) | Same | Phases 2 to 5 |
| Codes of conduct | Art. 35(8) | Same | Phase 2 |
| Views of people affected | Art. 35(9), where appropriate | Same | Phase 3 |
| Prior consultation | Art. 36(1) and (3) | Same, with the Information Commission | Phase 6 |
| Authority’s reply | Art. 36(2): up to eight weeks, plus six; extension notified within one month | Same | Phase 6 |
| Review | Art. 35(11) | Same | Phase 7 |
| High-risk AI deployers | AI Act Arts. 26(9) and 27(4) | No equivalent | Phase 7 |
| Maximum fine for DPIA failures | Art. 83(4)(a): €10 million or 2% of worldwide turnover | Art. 83(4)(a): £8.7 million or 2% | Whole checklist |
Three things were moving at the time of review. The EDPB adopted a common DPIA template (version 1.0) for public consultation, which closed on 9 June 2026; a final version had not been announced, and national authorities are expected to adopt it as their template or align their own with it. The Commission’s Digital Omnibus proposal of 19 November 2025 would replace national lists with a single EU list prepared by the EDPB, but it was still at first reading without a Council mandate in September 2026, so it is not law. In the UK, the ICO’s DPIA guidance remains under review after the Data (Use and Access) Act. Nothing on this page is legal advice.
Conditional logic turns one answer into two paths. No leaves a dated screening record with the DPO’s view, which WP248 expects; Yes opens the full assessment. Every project that was screened leaves evidence.
Risks, likelihood, severity, measures and residual risk sit in a table inside the task, with the data flow diagram and vendor answers attached as files. Nothing is pasted in from a spreadsheet the day before sign-off.
DPO advice and the final sign-off are approvals assigned to the people picked on the first task. If you consult the authority, due dates run from the submission date, and the activity trail shows who decided what and when.
CheckFlow is not a GRC platform, a legal adviser or a risk engine, and it does not decide whether your processing is high risk. It runs the steps, assigns them and keeps the evidence. CheckFlow’s compliance checklist software covers the rest of your privacy calendar.
Neighbouring jobs have their own templates. The GDPR Compliance Audit Checklist tests the DPIA register once a year, and the Vendor Risk Assessment Checklist collects the processor facts Phase 2 needs. Where the project uses AI, the EU AI Act Compliance Checklist handles classification and the fundamental rights impact assessment.
Whenever processing is likely to result in a high risk to people’s rights and freedoms, and always in the three Article 35(3) cases: automated decisions with legal or similarly significant effects, large-scale special category or criminal offence data, and large-scale monitoring of public areas. Processing on your authority’s list needs one too. WP248 treats two of its nine criteria as a usual sign, and says that if you are unsure, you should carry one out.
The controller is responsible, and in practice the project team usually writes it because it knows the processing. The DPO advises (Article 35(2)) and monitors how the DPIA is carried out (Article 39(1)(c)). Many organisations keep the DPO in that reviewing role so the monitoring stays independent. Record the DPO’s advice in the DPIA, and if you do not follow it, record why.
Under Article 36(2), the authority gives written advice within up to eight weeks of receiving the request, extendable by six weeks for complex processing. It must tell you of an extension within one month, and the clock stops while it waits for information it has asked for. The ICO says it decides within 10 days whether to accept a consultation. Article 36(1) requires the consultation before processing begins, so build the wait into the plan.
No. WP248 recommends publishing at least a summary or conclusion, especially where the public is affected, and says the published version can leave out security details and commercially sensitive material. The full DPIA goes to the authority if you consult it under Article 36, or if it asks.
Not in substance. UK GDPR Articles 35 and 36 keep the same tests, content and eight-plus-six-week reply period; the only change, from 30 September 2026, is that they now refer to the Information Commission. The narrower “assessment of high-risk processing” proposed in the earlier Data Protection and Digital Information Bill never became law.
It adds inputs and a neighbour. Article 26(9) of the AI Act requires deployers to use the provider’s instructions for use when carrying out the DPIA. Public bodies, private providers of public services, and deployers using AI for credit scoring or life and health insurance pricing also need a fundamental rights impact assessment from 2 December 2027, and since the 2026 amendments it can cross-refer to the DPIA instead of repeating it.
14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.