DPIA

Expand All

Helpful Videos for You

Need help? Check out videos for quick assistance!

 

A Data Protection Impact Assessment (DPIA) is a structured process used to evaluate and mitigate privacy risks associated with data processing activities. It is particularly important for operations that are likely to result in a high risk to individuals' rights and freedoms. Conducting a DPIA helps organisations ensure that they are adhering to data protection laws and taking appropriate steps to safeguard personal information.

DPIAs are a key component of data protection compliance frameworks, designed to identify risks early and implement necessary measures to prevent harm to individuals. The process typically involves assessing the nature, scope, context, and purposes of the data processing, as well as evaluating potential risks to data subjects. It is essential for organisations to document this process thoroughly, not only to demonstrate accountability but also to provide evidence of compliance to regulatory authorities, if needed.

A successful DPIA includes input from various stakeholders, such as those responsible for the collection and processing of personal data to data protection leaders, IT professionals, and other professionals, to ensure that all potential risks are considered. The DPIA also provides an opportunity to review existing security measures and determine if they are adequate or if additional safeguards are required. Additionally, organisations must ensure that data subjects’ rights, such as the right to access, correct, or erase their personal data, are protected throughout the data processing lifecycle.

By carrying out a DPIA, organisations can proactively address privacy concerns, minimise the likelihood of data breaches, and build trust with customers and regulators. This guide will outline when a DPIA is required, the steps involved in the assessment process, and best practices for ensuring comprehensive risk management in data processing activities.

Access to DPIA is included as part of 9ine’s Privacy Platform licence. For further information contact [email protected].

Accessing DPIA

Upon purchasing 9ine’s Privacy Platform and its associated features, users can be granted access to DPIA. Your organisation’s administrator(s) can allocate permission via User Management.

The User Management area where a DPIA administrator allocates DPIA module permission

Granting access to this feature does not automatically provide access to all DPIAs. However, it allows users to log a new DPIA. Users must be added as DPIA owners, members, a screening reviewer, reviewers, approvers, attachment reviewers or notified users to gain edit access. Owners and members of any risks, issues, lessons or tasks are also granted edit access if the item is associated with the DPIA. DPIAs can be deleted by the owner, record of processing area owner, record of processing activity owner or your App account administrators. A DPIAs permissions include:

  • Owner
  • Member
  • Screening reviewer
  • Reviewer
  • Approver
  • Notified user
  • Attachment reviewer

Warning:

If a DPIA is linked to a record of processing activity, the area and processing activity owners and members are granted edit access. Similarly, the record of processing activity owner, member, reviewer, approver, attachment reviewers, notified users gain edit access.

 

There can only be a single owner of a DPIA but there are no limits to the number of members or notified users. Each attachment can also have one reviewer. Owners can edit and delete their assigned items, while all other roles have edit rights but cannot delete. When more than two members or notified users are added, the additional user details are combined into a single pill, which can be clicked to view further details. These pills are alphabetically ordered.

 
 

Adding and removing notified users

To add a notified user, use the mention function in the Additional Notes feature. To begin, click the @ symbol on your keyboard and type the first name of the user you wish to mention. A user can be mentioned at the start, in the middle, or at the end of the entered text. To remove a user as a notified user, simply delete their name from the relevant note.

Mentioning a user sends an in-Platform notification and an email unless the user has disabled email notifications. The email notification sends a complete copy of the text entered by the user in the 9ine Platform, to the user’s registered email address.

 
 

Understanding how to create a DPIA

Begin by clicking New DPIA, to get started. You will then be presented with a popup which displays a mandatory field DPIA title.The New DPIA popup with the mandatory DPIA title field

On entering a title, you have two options:

  • Save & Close: Saves the information, creates the DPIA, and returns you to the DPIA log.
  • Save & Add Details: Saves the information and navigates you to the DPIA Screening step of the DPIA form.
 
 

Creating a new DPIA or editing an existing one

When creating a new DPIA , you will be navigated to the form and presented with the DPIA Screening step. If it is determined that a full DPIA is required, you will then be presented with an additional five steps, including:

  • Processing Description
  • Information Rights Risk
  • Security of Processing
  • Processing Risk Summary
  • Review & Approval

The DPIA form showing the five assessment steps across the topThe title of the DPIA is consistently displayed at the top of the form, and to the right, a unique reference number is provided. This number is prefixed with DPIA and followed by a unique identifier that cannot be edited.

In the Data Protection Impact Assessment (DPIA) form, users can add a retention by clicking Add Retention or link an existing retention from the dropdown list on the Processing Description step.

For new DPIAs, only the DPIA Screening step will be enabled by default. Users must first answer the question, Will a DPIA be completed? in the Screening Outcome section before they can proceed. This question allows organisations to conduct a preliminary assessment before deciding whether a full DPIA is required.The Screening Outcome section with the Will a DPIA be completed question

  • On selecting Yes, you must enter a date in the Completion Required By field. Once this is done, the Save & Exit button will change to Save & Next, allowing you to navigate to the Processing Description step of the DPIA form.

The Completion Required By field shown after selecting Yes

  • On selecting No, additional fields will appear, including an explanation text box, a Screening review required by field, a Review status dropdown (with options: DPIA not required, DPIA required and Awaiting review), and a Next Review Date field. The buttons will remain as Cancel and Save & Exit, preventing further progression.

The additional fields shown after selecting No

  • On selecting Don’t Know, you must enter the Screening review required by, Review status, and Next review date fields. The buttons will remain as Cancel and Save & Exit, preventing further progression.

The additional fields shown after selecting Don't Know
A DPIA can be linked to a record of processing activity and its associated area by selecting from the Processing activity dropdown on the DPIA Screening step.The Processing activity dropdown on the DPIA Screening step

When a DPIA and RoPA are linked through the DPIA screening process (via the Processing Activity field), or by clicking Save & Begin DPIA on step four of the record of processing activity form, duplicate questions are automatically populated and updated to prevent re-entering the same information. If the DPIA already contains data, saving will prompt you to confirm that the existing information will be overwritten with data from the processing activity. Once saved, the previous data cannot be restored.

For example, the DPIA screening step clearly indicates, Any changes made here will also reflect in the associated processing activity.The warning message shown on the DPIA screening step

Third parties such as data processors will be identified as part of your DPIA process. These third parties will often be software vendors or suppliers where there is a transfer of personal data from the organisation to the third party. On the Vendor Assessment (VA) logs, the quick actions menu offers an option to link a vendor to a DPIA. Once linked, the details are reflected on both the vendor log and the respective DPIA form.The Vendor Assessment quick actions menu with the option to link a vendor to a DPIA

Tip:

Tooltips are available throughout the DPIA form to provide guidance and support, offering helpful insights and additional context for a more informed and accurate assessment.

 

You have the ability to document processing responsibilities within the Processing Description step 1.Documenting processing responsibilities within the Processing Description step

In step 2, Information Rights Risk, when selecting Yes, or Possible, sub-questions and an additional comments field will appear.The Information Rights Risk step with conditional sub-questions

On navigating to step 4 Processing Risk Summary you will be presented with a Summary of Activities table which is used to capture any risks, issues, lessons, and tasks created through the DPIA process.The Summary of Activities table on the Processing Risk Summary step

In step 5, Review & Approval, you have the ability to capture both review and approval details, including who is responsible for carrying out the task, the date of the review and approval, and the status of each.The Review and Approval step capturing reviewer, approver, dates and statuses

The Review status records where the review has reached, with these options:

  • In Progress
  • Ready to Review
  • Requires Review
  • Reviewed

The Approval status records the approval decision, with these options:

  • Not approved until all risks have been mitigated
  • Accept residual risks subject to mitigating actions completed within 30 days
  • Accept residual risks, approved with no further action
  • Approved with no further actions required
  • Not approved until further details obtained
 
 

Selecting data subjects and the associated personal and special category data

Within each form in the 9ine Platform (Records of Processing Activity, DPIA, Processing Operation Assessment, and Incident Management), you can select data subjects along with their associated personal and special category data. On selecting a data subject, their details appear in a pill below the question for easy reference.

Tip:

If a data subject type is not available in the Platform’s default list, you can add it using the +Other function. Any data subjects added this way will be accessible to all users in your organisation for future use.

 

Each data subject appears in the popup when you click Select Personal Data or Select Special Category Data. When you add any Personal Data or Special Category Data in the corresponding popup, a Copy To All button becomes visible. This button lets you copy the selected data option to all applicable entries, ensuring consistency and efficiency across the forms. The secondary number displayed in the Answered pill represents the total number of selected data subjects. For example, if one data subject was initially selected and an additional two were chosen, the count would change from 1 to 3.

 
 

Creating an associated risk, issue, lesson, or task (Summary of Activities)

In the top right corner there is a +New button which provides four options: New Risk, New Issue, New Lesson, and New Task. When you create a risk, issue, lesson, or task the details are automatically added to the Summary of Activities table.

For more detailed information on the specific logs, please refer to their individual user guides: Risks & Issues, Lessons and Tasks.

 
 

Utilising the additional notes and attachments features

The Additional Notes feature allows you to maintain a single repository of information related to a DPIA. You can add multiple notes at once using the Save Note function. These notes are saved without the need to click the primary Save at the bottom of the page. When adding a new note, a record of the user's details, date, and time of entry are added, and the most recent notes will automatically appear at the top of the list. If an individual note is edited, the time and date of the note are updated.

Tip:

Individual notes can only be edited or deleted by the user who originally created the note. However, users have the option to add comments to notes created by others.

 

Additional formatting functionality is provided in the additional notes feature. If entering large volumes of data, click the Full Screen or Expand Popup options.

Warning:

For security purposes, the 9ine Platform will log users out of their active sessions after 45 minutes of inactivity, with a reminder triggered at 30 minutes of inactivity. If you are in full screen mode, the reminder may not appear unless you have browser-based notifications enabled. Typing in the field is not considered activity; activity is only registered when clicking Cancel or Save.

 

The Attachments feature allows you to upload files or images using your native file explorer. You can upload up to five attachments at once:

  • Maximum file size: 10MB
  • A maximum of five files can be uploaded at a time
  • Supported file types: jpg, jpeg, tif, tiff, png, odg, otg, txt, rtf, doc, docx, pages, odt, ott, odm, pdf, xml, xmlx, numbers, ods, ots, ppt, pptx, key, keynote, odp, otp, xls, xlsx, tsv, csv, pst, eml, emlx, ost, oft, msg
  • The file name cannot contain special characters

Each attachment uploaded can be assigned a reviewer, allocated a review date, and further information can be included. This process ensures that attachments added remain current and do not become obsolete.

 
 

Understanding how to use the DPIA log

When creating a new DPIA, or editing an existing one, the details entered are added to the log. Each DPIA is automatically assigned a unique reference number (starting with DPIA) that cannot be edited.

To view only the areas you are responsible for, use the My DPIAs toggle located in the top right corner of the log. This will filter and display items where you are the owner, member, screening reviewer, reviewer, approver, or notified user.

The My DPIAs toggle in the top right corner of the DPIA log

Default sorting is applied to the Ref No., which can be altered by clicking on the title of any other column. Clicking a column header once sorts the log by the selected column, and clicking it a second time reverses the order.

To remove individual columns, click View and deselect the columns you do not want to display, whilst retaining a minimum of one column. After selecting your preferred columns, click Apply. You also have the option to Save View. You can also change the sequence order of the columns by dragging and dropping them into your preferred order. Any changes are automatically saved and retained on the next login.

Tip:

The changes applied to the sequence order of the log and in the View popup are user and log specific and only applied to your profile. The sequence order in the View popup does not update to reflect the order created through your dragging and dropping actions.

 

To focus on a specific DPIA, you can use the Filter or Search functions. When a filter is active, an orange icon appears next to the filter icon for easy recognition. To quickly clear any filters, click the Clear Filters button in the popup. You can also apply a temporary filter without clicking Save Filter. To revert back to your saved filter, click Reset. Similarly, you can select data points and click Apply Without saving your filter options.

 
 

Downloading DPIA

To download a DPIA and its activities click the Download button located in the top right corner of the DPIA log. You can customise the download report to include or exclude data by using the search bar, filter, view options, or My DPIAs functions. Upon clicking Download, the export is processed in the background. Once complete, you will receive both an in-Platform notification and an email notification. The exported file is provided in XLS format. On the DPIA log, you have three download options available:

  • Log - Downloads in XLS format.
  • Advanced - Downloads in XLS format.
  • Form (available in the quick actions menu) - Downloads in DOCX format.
 
 

Understanding the quick actions for a DPIA

The DPIA log provides a range of quick-access functions within the menu options, including:

  • Add Note - Opens the DPIA form directly on the Additional Notes feature.
  • Add Member(s) - Opens a members popup to quickly grant users access to the DPIA.
  • Duplicate - Duplicates the DPIA and all associated risks, issues, lessons, and tasks labelling them with the prefix Copy of. The duplicated items do not include notes, attachments, logged time and logged cost data.
  • Download - Downloads the DPIA form in a DOCX format.
  • Close - Marks a DPIA and all its associated risks, issues, lessons, and tasks as closed, removing all items from their respective logs.
  • Reopen - Marks a closed DPIA, opens and restores all associated items. Related tasks are returned to Not Started, while associated risks, issues, and lessons are returned to Open status.
  • Delete - Marks a DPIA and all its associated risks, issues, lessons, and tasks as deleted, effectively removing them from the 9ine Platform.The quick actions menu opened from the three-dots icon on a DPIA log row
 
 

Configuring DPIA notification settings

Global Due Date Notifications Alerts

To ensure you're always informed of key moduleName milestones, users can configure their personal notification preferences within the Notification Settings area of the 9ine Platform. This enables both email and in-Platform alerts for important events in the moduleName lifecycle such as end dates, due dates, renewal reminders, termination deadlines, and next review dates.

To activate alerts:

  1. Navigate to your Notifications (available in the header)
  2. Click the Notification Settings icon

Toggle Global Lifecycle Alerts on for both In Platform and Email to receive notifications through both channels.

Under Reminder, you can select how far in advance you would like to be notified of an upcoming milestone (e.g. 7, 14, or 30 days before the due date). This ensures you receive early warnings before deadlines approach. You can choose any period from 1 to 31 days in advance.

These reminders are designed to give moduleName owners and stakeholders enough lead time to review, act, or make decisions before renewal or termination windows close.

To receive multiple reminders, you can enable Repeat notifications.

  • Repeats are available in weekly intervals and are only triggered if your chosen reminder period is 7 days or more.
  • The number of notifications is based on your reminder window:

For example:

  • If your reminder is set to 10 days, you’ll receive 1 notification.
  • If it’s set to 16 days, you’ll receive 2 notifications.

This flexible notification system helps ensure key events never go unnoticed, especially in busy school environments where planning ahead is essential.