DPIA template

A DPIA that survives
a second reading.

A nine-section Data Protection Impact Assessment template that works for DPDP Section 10 and GDPR Article 35, with notes on what makes each section pass or fail review. Free to copy.

Questions

The things people ask us

Who has to do a DPIA under DPDP?

Significant Data Fiduciaries must carry out periodic Data Protection Impact Assessments under Section 10. Everyone else is not required to, but the assessment is the cheapest way to find out what you actually process, and it is the document a buyer's security review asks for.

Is a DPDP DPIA the same as a GDPR one?

The structure is similar and one document can serve both if you are careful. The differences are that DPDP ties the assessment to SDF designation rather than to a risk threshold, and that the consent and notice sections need to reflect DPDP's specific requirements including the language obligation.

How often is 'periodic'?

The Act says periodic without fixing an interval. Annually, and on any material change to processing, is the defensible reading and the one most auditors will expect.

What makes a DPIA fail a review?

Two things, consistently. It describes intentions rather than the system as built, and it has no date or owner, so nobody can tell whether it is current. Both are fixable by generating the assessment from live control state instead of writing it from memory.

Book a walkthrough

Stop writing assessments from memory.

Bring one processing activity to a 30 minute call. We will fill the template from your live systems and you will see which sections you could not have answered by hand.