Data Protection Impact Assessment (DPIA) Checklist Template

Too many DPIAs are written after launch to fill a folder. The vendor is signed, the data is flowing, and the measures section describes controls nobody has built. Article 35 asks for the assessment before processing starts, while it can still change the design.

This free DPIA checklist is for DPOs, privacy leads and project owners in organisations subject to the EU GDPR, the UK GDPR or both. It runs one assessment for one project: screening against Article 35(3), the authority lists and the nine EDPB criteria, then the description of the processing, consultation, necessity and proportionality, risks and measures, and sign-off. Where high risk remains, it takes you through prior consultation under Article 36. The result is a signed DPIA, or a dated record of why none was needed.

Use This Template Free See Live Example
No Credit Card Required

Last reviewed: October 2026

Screen First, Assess Second, Consult Only if Risk Stays High

Article 35(1) requires a DPIA before any processing that is likely to result in a high risk to people’s rights and freedoms, in particular where new technologies are used. Article 35(3) names three cases that always qualify, and each supervisory authority publishes its own list under Article 35(4). The Article 29 Working Party’s guidelines (WP248 rev.01, endorsed by the EDPB on 25 May 2018) add nine criteria: evaluation or scoring, automated decisions with legal or similar effect, systematic monitoring, sensitive or highly personal data, large scale, matching or combining datasets, vulnerable people, innovative technology, and processing that stops people using a right, service or contract.

The usual failure is timing. WP248 says to start the DPIA as early as practicable and treat it as a continual process, not a one-off. One assessment may cover a set of similar operations with similar high risks. The annual GDPR Compliance Audit Checklist checks that your DPIA register is complete; this template produces each entry in it.

Article 35: the assessment

Done by the controller, before processing

Who: the controller, seeking the DPO’s advice where one is designated; processors must assist (Article 28(3)(f)).

Contains at least: a description and the purposes, necessity and proportionality, the risks to individuals, and the measures to address them (Article 35(7)).

Review: at least when the risk changes (Article 35(11)).

Article 36: prior consultation

Needed only when high risk remains

Trigger: the DPIA shows high risk that your own measures cannot bring down.

Send: roles of controllers and processors, purposes and means, safeguards, DPO contact details, the DPIA and anything else requested (Article 36(3)).

Reply: written advice within up to eight weeks, extendable by six for complex processing.

UK after the Data (Use and Access) Act 2025

Articles 35 and 36 survive unchanged in substance

The DUAA left the UK DPIA and prior consultation duties in place. Since 30 September 2026 both articles name the Information Commission, still known as the ICO. The ICO’s own list adds ten types of processing, including biometrics, invisible processing and tracking, and its DPIA guidance is marked as under review because of the Act. The earlier Data Protection and Digital Information Bill would have replaced DPIAs with a narrower assessment; it fell when Parliament was dissolved in May 2024.

If the project deploys a high-risk AI system, Article 26(9) of the EU AI Act tells deployers to use the provider’s instructions for use in their DPIA. Some deployers will also need a fundamental rights impact assessment from 2 December 2027, which can cross-refer to the DPIA. The EU AI Act Compliance Checklist covers that side.

What the DPIA Checklist Covers

One checklist per project. The screening answer decides whether the full assessment appears, and the residual risk answer decides whether prior consultation does.

Phase 1

Phase 1: Screening

The fourth task asks whether a DPIA is required. No shows only the screening record; Yes opens Phases 2 to 7.

  • Register the project and name the DPO and the accountable approver — project owner, planned start of processing, and any joint controllers or processors
  • Check the three cases in Article 35(3) — automated decisions with legal or similarly significant effects, large-scale special category or criminal offence data, large-scale monitoring of a public area
  • Check the authority list for each country involved (Art. 35(4)) — each EU authority publishes one; the ICO’s list covers the UK
  • Score the processing against the nine EDPB criteria and decide — two or more usually means a DPIA, one can be enough, and where it is unclear do one anyway
  • Record why no DPIA is needed, with the DPO’s view — keep it on the project file and screen again if the scope changes
Phase 2

Phase 2: Describe the Processing

Article 35(7)(a). Shown only when the screening says a DPIA is required, as are Phases 3 to 7.

  • Map how the data moves — collection, use, storage, sharing and deletion, with the systems and people involved; attach a data flow diagram
  • Record the scope — data categories including special category data, number of people, volume, frequency, retention and geography
  • Describe the context — what people would expect, children or vulnerable groups, novel technology, and any approved code of conduct (Art. 35(8))
  • State the purposes and the benefits — for you, the people affected and society, including any legitimate interest relied on
  • Get the facts from processors and vendors — hosting, sub-processors, transfers and security; Article 28(3)(f) obliges processors to help
Phase 3

Phase 3: Consultation, Necessity & Proportionality

Article 35(2), (7)(b) and (9).

  • Ask the DPO for advice at the start — record the advice now, and at sign-off whether you followed it
  • Seek the views of the people affected or their representatives — a survey, staff representatives or user research; document why if that is not appropriate
  • Bring in security, engineering and legal input — on the measures, on what the system really does and on the lawful basis
  • Confirm the lawful basis and test necessity — could less data, less identifiable data or a less intrusive method meet the same purpose
  • Check minimisation, accuracy, retention, transparency and rights — plus processor contracts and safeguards for any transfer abroad
Phase 4

Phase 4: Identify & Assess Risks

Article 35(7)(c). The risks are to the people whose data it is, not to the organisation.

  • List the risks to individuals — unauthorised access, unwanted change or loss of data, and harms such as discrimination, financial loss or loss of control
  • Rate each risk for likelihood and severity — on a scale agreed before scoring; harm can be physical, material or non-material
  • Walk the data flow with the project team and the DPO — one step at a time, so risks at handovers and integrations are not missed
  • Mark which risks are high — they drive the measures in Phase 5 and, if they stay high, the consultation in Phase 6
Phase 5

Phase 5: Measures, Residual Risk & Sign-Off

The residual risk answer decides whether Phase 6 appears. Both sign-offs are approvals assigned to the people named on the first task.

  • Choose measures for each risk (Art. 35(7)(d)) — pseudonymisation, access controls, shorter retention, human review of automated decisions, an opt-out
  • Record the residual risk after the measures — and whether it is still high; where a risk is accepted, record who accepted it and why
  • DPO reviews the completed DPIA and gives advice — approval by the DPO, who also monitors how the DPIA is carried out (Art. 39(1)(c))
  • Accountable approver signs off the outcome — with reasons for any DPO advice not followed; approval by the accountable approver
Phase 6

Phase 6: Prior Consultation

Shown only when the residual risk is still high. Due dates run from the date the request is submitted.

  • Hold the processing until the authority has replied — Article 36(1) requires the consultation before processing starts
  • Prepare the consultation pack (Art. 36(3)) — roles, purposes and means, measures and safeguards, DPO contact details and the DPIA
  • Submit to the competent authority and record the date — your lead supervisory authority in the EU, the Information Commission in the UK
  • Track the reply period — any extension must be notified within one month; the clock stops while the authority waits for information
  • Act on the authority’s advice — redesign, add measures or stop; record the decision and update the DPIA
Phase 7

Phase 7: Integrate, Publish & Review

Article 35(11) asks for a review at least when the risk changes; the last task sets the triggers.

  • Add every agreed measure to the project plan with an owner — and check each is in place before the processing starts
  • Update the records of processing and the privacy notice — so Articles 30, 13 and 14 match what the DPIA approved
  • Decide whether to publish a summary — not required, but WP248 calls it good practice where the public is affected
  • Link the DPIA to a FRIA if a high-risk AI system is deployed — Article 27(4) of the AI Act lets the FRIA cross-refer instead of repeating it
  • Set review triggers and file the signed DPIA (Art. 35(11)) — new data, a new purpose, a new vendor, new technology or a breach

DPIA Requirements Mapped to the Checklist

The table maps each DPIA rule to its source in each regime and to the phase that records the evidence. National lists and sector rules can add to it, so treat the table as a starting point, not legal advice.

Requirement EU GDPR UK GDPR Evidenced in
When a DPIA is requiredArt. 35(1) and (3); WP248 criteriaSame articles; ICO guidancePhase 1
Authority listsArt. 35(4)–(5): each supervisory authorityArt. 35(4)–(5): the Information CommissionPhase 1
DPO advice and monitoringArts. 35(2) and 39(1)(c)SamePhases 3 and 5
Processor assistanceArt. 28(3)(f)SamePhase 2
Minimum contentArt. 35(7)(a)–(d)SamePhases 2 to 5
Codes of conductArt. 35(8)SamePhase 2
Views of people affectedArt. 35(9), where appropriateSamePhase 3
Prior consultationArt. 36(1) and (3)Same, with the Information CommissionPhase 6
Authority’s replyArt. 36(2): up to eight weeks, plus six; extension notified within one monthSamePhase 6
ReviewArt. 35(11)SamePhase 7
High-risk AI deployersAI Act Arts. 26(9) and 27(4)No equivalentPhase 7
Maximum fine for DPIA failuresArt. 83(4)(a): €10 million or 2% of worldwide turnoverArt. 83(4)(a): £8.7 million or 2%Whole checklist

Three things were moving at the time of review. The EDPB adopted a common DPIA template (version 1.0) for public consultation, which closed on 9 June 2026; a final version had not been announced, and national authorities are expected to adopt it as their template or align their own with it. The Commission’s Digital Omnibus proposal of 19 November 2025 would replace national lists with a single EU list prepared by the EDPB, but it was still at first reading without a Council mandate in September 2026, so it is not law. In the UK, the ICO’s DPIA guidance remains under review after the Data (Use and Access) Act. Nothing on this page is legal advice.

Why Run Your DPIAs in CheckFlow?

1

A screening that ends cleanly either way

Conditional logic turns one answer into two paths. No leaves a dated screening record with the DPO’s view, which WP248 expects; Yes opens the full assessment. Every project that was screened leaves evidence.

2

The risk register lives in the assessment

Risks, likelihood, severity, measures and residual risk sit in a table inside the task, with the data flow diagram and vendor answers attached as files. Nothing is pasted in from a spreadsheet the day before sign-off.

3

Named sign-offs and a tracked clock

DPO advice and the final sign-off are approvals assigned to the people picked on the first task. If you consult the authority, due dates run from the submission date, and the activity trail shows who decided what and when.

CheckFlow is not a GRC platform, a legal adviser or a risk engine, and it does not decide whether your processing is high risk. It runs the steps, assigns them and keeps the evidence. CheckFlow’s compliance checklist software covers the rest of your privacy calendar.

Neighbouring jobs have their own templates. The GDPR Compliance Audit Checklist tests the DPIA register once a year, and the Vendor Risk Assessment Checklist collects the processor facts Phase 2 needs. Where the project uses AI, the EU AI Act Compliance Checklist handles classification and the fundamental rights impact assessment.

Frequently Asked Questions

When is a DPIA mandatory under the GDPR?

+

Whenever processing is likely to result in a high risk to people’s rights and freedoms, and always in the three Article 35(3) cases: automated decisions with legal or similarly significant effects, large-scale special category or criminal offence data, and large-scale monitoring of public areas. Processing on your authority’s list needs one too. WP248 treats two of its nine criteria as a usual sign, and says that if you are unsure, you should carry one out.

Who should write the DPIA: the DPO or the project team?

+

The controller is responsible, and in practice the project team usually writes it because it knows the processing. The DPO advises (Article 35(2)) and monitors how the DPIA is carried out (Article 39(1)(c)). Many organisations keep the DPO in that reviewing role so the monitoring stays independent. Record the DPO’s advice in the DPIA, and if you do not follow it, record why.

How long does the regulator take to answer a prior consultation?

+

Under Article 36(2), the authority gives written advice within up to eight weeks of receiving the request, extendable by six weeks for complex processing. It must tell you of an extension within one month, and the clock stops while it waits for information it has asked for. The ICO says it decides within 10 days whether to accept a consultation. Article 36(1) requires the consultation before processing begins, so build the wait into the plan.

Do we have to publish our DPIA?

+

No. WP248 recommends publishing at least a summary or conclusion, especially where the public is affected, and says the published version can leave out security details and commercially sensitive material. The full DPIA goes to the authority if you consult it under Article 36, or if it asks.

Did the Data (Use and Access) Act change DPIAs in the UK?

+

Not in substance. UK GDPR Articles 35 and 36 keep the same tests, content and eight-plus-six-week reply period; the only change, from 30 September 2026, is that they now refer to the Information Commission. The narrower “assessment of high-risk processing” proposed in the earlier Data Protection and Digital Information Bill never became law.

Does deploying a high-risk AI system change the DPIA?

+

It adds inputs and a neighbour. Article 26(9) of the AI Act requires deployers to use the provider’s instructions for use when carrying out the DPIA. Public bodies, private providers of public services, and deployers using AI for credit scoring or life and health insurance pricing also need a fundamental rights impact assessment from 2 December 2027, and since the 2026 amendments it can cross-refer to the DPIA instead of repeating it.

Is CheckFlow free for this template?

+

14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.

Every DPIA Screened, Assessed and Signed Off Before Launch

Free trial — no credit card required.