Conduct a Data Privacy Impact Assessment
Launch the Data Privacy Impact Assessment workflow and work its six steps (Scope, Data, Impact, Safeguards, Governance, Review) to scope the program, inventory data, assess impact, record safeguards and governance, and submit.
Try it in CybervergentOverview
Run a DPIA through the six-step workflow, from scope to submission.
Step-by-step
- 1 Launch the 'Data Privacy Impact Assessment' workflow (the 'Data Privacy Impact' quickstart). It opens a six-step wizard: Scope, Data, Impact, Safeguards, Governance, and Review.
- 2 On 'Scope' (Privacy Program Scope), enter the Program Name, select the applicable regulations and frameworks (for example GDPR, NDPA, CCPA/CPRA), the primary legal basis for processing, and your operational jurisdictions, then click 'Continue'.
- 3 On 'Data' (Data Inventory & Classification), use the four tabs: add 'Personal Data' categories with sensitivity and volume, 'Processing Activities' (Article 30 records with purpose, legal basis, and retention), 'Data Subjects' (selecting Children triggers enhanced DPIA requirements), and cross-border 'Transfers' with their transfer mechanism.
- 4 On 'Impact' (Impact Assessment & Risk Analysis), complete the DPIA Trigger Assessment (two or more triggers mandate a full DPIA), then rate each privacy risk dimension for Likelihood and Severity to set its score.
- 5 On 'Safeguards' (Safeguards & Mitigation Measures), select your Privacy by Design measures (Article 25), map the compliance controls, and confirm the Data Subject Rights mechanisms (access, rectification, erasure, restriction, portability, object, automated decision, and withdraw consent).
- 6 On 'Governance' (Accountability & Governance), assign the DPO or privacy lead, then set the approval authority, review frequency, prior consultation status (Article 36), breach notification window, incident response status, and Records of Processing (Article 30) status.
- 7 On 'Review', check the DPIA Readiness score and the summary, then click 'Submit DPIA' to record the assessment.
Related articles
Data Security Posture (DSPM) Review your data security posture Read the DSPM overview and drill into inventory, issues, retention, assets, compliance, and gaps. Scans & Assets Create a monitor Set up a monitor to scan a target asset on a schedule. Scans & Assets View monitor results and assets Open a monitor to review its findings, asset details, and connection health. Alerts & Footprints Review and assess monitoring alarms See alarms raised across your monitors and assess their risk.