A DPIA that survives
a second reading.
A nine-section Data Protection Impact Assessment template that works for DPDP Section 10 and GDPR Article 35, with notes on what makes each section pass or fail review. Free to copy.
The nine sections
Copy this structure. The section titles matter less than the discipline of answering each one about a single processing activity rather than about the company in general.
| Section | What it has to establish |
|---|---|
| 1. What is being assessed | The processing activity, the system it runs in, and who owns it. One activity per assessment; a DPIA covering 'the product' is not an assessment. |
| 2. Data inventory | Every category of personal data involved, whether any of it is sensitive, the volume, and the source. If you cannot fill this in confidently, run discovery before you continue. |
| 3. Purpose and lawful basis | The purpose in plain language, the basis relied on, and for consent, the notice version that asked for it. |
| 4. Necessity and proportionality | Why this data and not less. The honest answer to 'what would break if we collected half of this' belongs here. |
| 5. Flows and recipients | Where the data goes, including processors, sub-processors and any transfer outside India, with the contract that binds each one. |
| 6. Retention and deletion | How long, on what trigger it is deleted, and whether deletion has actually been tested. |
| 7. Risks to Data Principals | Scored on likelihood and impact. Risks to people, not risks to the company: those are different registers and conflating them is the most common error. |
| 8. Controls and residual risk | The controls that treat each risk, and what the risk score is after they are applied. This is where the assessment stops being a document and becomes a decision. |
| 9. Sign-off | Owner, date, review date. Unsigned and undated assessments are the ones that fail review. |
The two failure modes
It describes intentions. An assessment that says data is encrypted at rest, when the assessment was written before the migration and the migration slipped, is worse than no assessment: it is a documented claim you cannot support. Write what is true today and date it.
It goes stale silently. A DPIA is a snapshot, and snapshots age. If the controls named in section 8 start failing, nothing in the document changes, which is exactly the gap between a document and a control. Tying the assessment to live control state is the fix, and it is why our risk register recalculates residual risk from control results rather than storing the number somebody typed.
Scoring risks to people
Use a 5×5 on likelihood and impact, and be explicit that impact means impact on the Data Principal. A breach that is embarrassing for you and harmless to users is a low-impact risk in a DPIA and a high-impact one in your corporate register. Keeping the two apart is what makes the assessment credible to a regulator.
Impact on a person, in ascending order: inconvenience, financial loss, discrimination, identity theft, physical safety. If sensitive data or children's data is involved, the impact floor rises regardless of likelihood.
Want it prefilled?
If your systems are connected, most of sections 2, 5, 6 and 8 can be generated rather than written: discovery knows what data you hold, the flow map knows where it goes, and the control graph knows which controls are passing today. What remains is the judgement in sections 4 and 7, which is the part worth your time. We will walk one through with you.
The things people ask us
Who has to do a DPIA under DPDP?
Significant Data Fiduciaries must carry out periodic Data Protection Impact Assessments under Section 10. Everyone else is not required to, but the assessment is the cheapest way to find out what you actually process, and it is the document a buyer's security review asks for.
Is a DPDP DPIA the same as a GDPR one?
The structure is similar and one document can serve both if you are careful. The differences are that DPDP ties the assessment to SDF designation rather than to a risk threshold, and that the consent and notice sections need to reflect DPDP's specific requirements including the language obligation.
How often is 'periodic'?
The Act says periodic without fixing an interval. Annually, and on any material change to processing, is the defensible reading and the one most auditors will expect.
What makes a DPIA fail a review?
Two things, consistently. It describes intentions rather than the system as built, and it has no date or owner, so nobody can tell whether it is current. Both are fixable by generating the assessment from live control state instead of writing it from memory.
Stop writing assessments from memory.
Bring one processing activity to a 30 minute call. We will fill the template from your live systems and you will see which sections you could not have answered by hand.