For licensed Collaborators with permission for this task. Check the selected organisation; feature availability and record access still apply.
What you will achieve
Prepare a Data Protection Impact Assessment, gather review evidence and record the authorised decision through its workflow.
Completing form fields is not the same as approving the processing. Applicability and legal conclusions belong to the responsible privacy professionals.
Before you start
Agree the processing scope, assessment owner, DPO/reviewer and approver. Have the relevant RoPA, data entities, systems and source evidence available. Confirm the organisation has an appropriate DPIA workflow.
Build the assessment
- Open the DPIA catalogue and choose Create DPIA.
- Enter the title, description, Team, DPIA Owner and processing purpose.
- Link the relevant Data Entities and record the initial necessity, proportionality, consultation and review-date information.
- Create the record and open Scope. Check processing context, people affected and connections against the underlying activity.
- Work through Assessment, including screening and the detailed assessment sections. Distinguish evidence-backed answers from unknowns; review any AI suggestions before adopting them.
- In Risks, record the actual risks and current assessments. In Assurance, connect measures, testing and reviews to the claims they support.
- Record consultations and supporting documents. Assign unresolved work rather than concealing it in an optimistic conclusion.
Obtain review and approval
In Governance, record the formal DPO opinion and the controller's response. If the controller departs from advice, record the rationale using the departure controls; do not silently replace the opinion.
In Approval, choose the decision outcome and record any conditions. Approved with conditions requires at least one recorded condition. Review Pre-checks, then use the authorised workflow controls to commit the decision. Selecting an outcome alone is not the approval transition.
If the workflow is missing, ask the Organisation Administrator to configure the appropriate default. Do not try to bypass a workflow-managed assessment through an unrelated approval action.
Check it worked
Reload and confirm the committed decision, actor, conditions and workflow state. Inspect linked risks and safeguards. Give each outstanding condition an owner and verification path.
If something goes wrong
| Problem | Next action |
|---|---|
| Approval is blocked | Read the pre-checks and resolve the missing evidence or review |
| DPO advice is disputed | Record the controller response and rationale; retain the original advice |
| Assessment evidence changes | Reassess the affected conclusions before relying on the earlier decision |
| External consultation is required | Follow the authorised specialist-led process; a saved platform record does not itself send a submission |
Human judgement matters
Do not reduce a risk or mark a safeguard complete solely to enable approval. An assessment is useful because it exposes difficult decisions, not because every indicator becomes green.
What next?
For the wider context, see Manage privacy records and assessments.
Track approval conditions and review dates, and revisit the DPIA when processing or its evidence materially changes.
Get help
Ask your Organisation Administrator about access or the task owner about the content. For a platform error, include this guide reference, the affected page and a sanitised message, not confidential evidence or session details.