Creating a New DPIA
Helpful Videos for You
Need help? Check out videos for quick assistance!
This video walks through creating a Data Protection Impact Assessment (DPIA), from the first screening step to review and approval.
- From the left-hand menu, select Data Privacy and Protection, then DPIA, and click New.
- Enter a title in the popup (mandatory), then choose:
- Save & Close – saves your entry and returns you to the log.
- Save & Add Details – saves your entry and takes you to the screening step.
- Complete DPIA Screening and decide whether a full assessment is needed:
- Yes – enter a "completion required by" date; Save & Exit changes to Save & Next so you can move through the five further steps: Processing description, Information rights risk, Security of processing, Processing risk summary, and Review and approval.
- No – fill in the explanation box, "Screening review required by", review status and next review date.
- Don't Know – fill in "Screening review required by", review status and next review date.
- Note: If you select No or Don't Know, the later steps stay greyed out.
- Check the top of the form for your DPIA title and its reference number prefixed with "DPIA", which is generated automatically and cannot be edited.
- Tip: Tooltips throughout the form give helpful guidance and context.
- Link the DPIA to a Record of Processing Activity using the Processing Activity dropdown on the screening step (or via Save & Begin DPIA on step four of a RoPA form).
- Note: Duplicate questions are auto-populated, and a warning states: "Any changes made here will also reflect in the associated processing activity."
- In Processing Description, record third parties such as software vendors or suppliers.
- Tip: You can also link a vendor from the Vendor Assessment log; details then appear in both logs.
- Select data subjects and their personal or special category data; they appear as pills below the question.
- Tip: Use +Other to add a subject type that isn't listed; the pill counter updates as you add more.
- In Step 2 – Information Rights Risk, selecting "Yes" or "Possible" reveals sub-questions and a comments field; Step 3 lets you add further details.
- In Step 4 – Processing Risk Summary, add a New Issue, New Risk, New Lesson or New Task – each is added to the Summary of Activities table automatically.
- In Step 5 – Review & Approval, record who is responsible, the review date, approval date and status.
- Tip: Use additional notes and attachments to keep extra details in one place.
Related Videos
-
This video explains how the Privacy Dashboard works and the types of dashboard cards it offers, so you can monitor your organisation's data privacy, compliance, risk and governance in real time.
- Open the Privacy Dashboard, your command centre for compliance, risk and governance.
- Note: You may see 'No records available' until data has been added.
- Understand what you can see: you only see items assigned to you or those you have permissions for.
- Privacy permission roles include owner, member, notified user, attachment reviewer, reviewer and approver.
- Move between the 4 tabs – RoP, RoPA, DPIA and Retention – which together hold 40 cards.
- Use Column charts to compare potential privacy risks based on the sensitivity and volume of personal data.
- Use Gauge charts to track progress, such as the number of completed versus open DPIAs.
- Use Geo-charts to see DPIAs involving international transfers.
- Tip: Hover over any country to view details.
- Use Donut charts to see proportions, such as how many processing activities could negatively affect data subjects.
- Use Table charts for sortable, clickable data that links you directly to filtered logs for deeper insights.
An Overview of Privacy Dashboard
- Open the Privacy Dashboard, your command centre for compliance, risk and governance.
-
This video shows how to create a new Record of Processing Area (RoP) and start adding processing activities to it, either one by one or from templates.
- From the left-hand menu, under Data Privacy and Protection, select Records of Processing.
- Click New Processing Area.
- Complete the popup fields: Title, Owner, Members and Next Review Date.
- Note: Title, Owner and Next Review Date are mandatory. The next review date defaults to 12 months from today, but you can change it.
- Choose how to save: Save & Close, Save & Create Process or Save & Quickstart Your Process.
- With Save & Create Process, enter the Title and Purpose of the processing activity, then choose:
- Save & Close – return to the area log.
- Save & Add Another – keep creating activities.
- Save & Add Details – go straight into the full form assessment.
- With Save & Quickstart Your Process, pick from a categorised list of template processing activities: select the relevant processing areas and click Next (each area shows as a tab).
- Choose the activities you want to start and click Populate.
- Note: Activities created through Quickstart carry a unique icon, which disappears once you edit and save them.
Creating a New RoP
-
This video explains how to create a new Record of Processing Activity (RoPA) within a processing area and work through its assessment form.
- From the left-hand menu, click Data Privacy and Protection, then Records of Processing.
- Select the Record of Processing Area where you want to create the activity, then click New Process.
- Enter the title and purpose of your processing activity, then click Save & Add Details.
- Work through the four steps shown at the top: Processing Overview, Processing Description, Processing Risk and Processing Review.
- Note: If you have unsaved changes, use the buttons at the bottom of the screen to move forward.
- The activity title and a reference number starting with RoPA appear at the top; the number is generated automatically and cannot be changed.
- Record third parties, such as software vendors or suppliers. Link a vendor using the quick actions menu in the Vendor Assessment log; details then appear in both the vendor log and the activity form.
- Complete the Processing Risk Assessment on Step 3. As a general guide:
- More than two risks – consider a Data Protection Impact Assessment.
- More than four risks – start DPIA screening straight away.
- Processing involving vulnerable groups, such as children – a DPIA is strongly recommended.
- Tip: Tooltips offer guidance, and high-risk items are flagged automatically.
- Link a DPIA either by selecting the Processing Activity in DPIA screening, or by clicking Save & Begin DPIA on Step 4.
- Note: Answers to duplicate questions are synced automatically.
- Select data subjects with their personal data and special category data; choices appear as pills, and the Answered pill shows how many subjects you've selected.
- Click + New in the top-right corner to create a Risk, Issue, Lesson or Task; these are logged in the Summary of Activities table on Step 4.
Creating a New RoPA
-
This video explains how to use the DPIA Log to find, organise, export and manage your Data Protection Impact Assessments.
- From the left-hand menu, select Data Privacy and Protection, then DPIA.
- Note: New and edited DPIAs are recorded in the log automatically, each with a reference number beginning with DPIA that cannot be changed.
- Turn on the My DPIAs toggle (top-right) to see only assessments where you are the owner, member or notified user.
- Sort the log by clicking any column header (it sorts by Reference Number by default); click again to reverse the order.
- Customise columns: select View, deselect columns you don't need (keep at least one), and click Apply. You can save this as your preferred view.
- Drag and drop columns to reorder them; this is saved automatically to your profile.
- Note: Column order changes aren't shown in the View popup.
- Use Search or Filter to find an assessment. An orange dot shows a filter is active; use Clear Filters to remove them, or Reset to return to a saved filter.
- Understand the roles: Owner, Member, Screening Reviewer, Reviewer, Approver, Notified User and Attachment Reviewer.
- Each DPIA has one owner, with no limit on members or notified users; each attachment has one reviewer.
- Owners can edit and delete; other roles can edit but not delete.
- When a DPIA is linked to a Record of Processing Activity, the relevant users are automatically given edit access.
- Tip: When more than two members or notified users are added, the extra users are grouped into one alphabetical pill that expands on click.
- Click Download to export the log, tailored by filters, search, view options or the My DPIAs toggle.
- Tip: For full form details, use the download option in the quick-menu.
- Use the quick-access menu to add notes, manage members, duplicate, close or delete a DPIA.
- Note: Duplicating, closing or deleting a DPIA includes all its associated risks, issues, lessons and tasks.
Understanding the DPIA Log
- From the left-hand menu, select Data Privacy and Protection, then DPIA.
Contact Us
If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.