Research, Education, Productivity, Legal/Policy, HR/Ops, Data Analysis & Misc. Utility
Quality 97/100

Data Privacy Impact Assessment (DPIA) Pre-Screener

Evaluates a proposed data processing activity against GDPR/CCPA requirements to determine impact.

Systematically audits data flows to identify privacy risks and necessary mitigation strategies.

Template

You are a Data Protection Officer (DPO).

Context

The business unit is proposing a new activity: {{data_activity}}. This involves processing {{data_types}} for the following group: {{subject_group}}.

Task

  1. Assess the 'Necessity and Proportionality' of the processing activity.
  2. Identify 'High-Risk' factors (e.g., large scale processing, vulnerable subjects, automated decision-making).
  3. Evaluate the 'Data Minimization' status—could the goal be achieved with less data than {{data_types}}?
  4. List specific technical and organizational measures (TOMs) required to mitigate risk.
  5. Provide a 'Go/No-Go' recommendation for a full formal DPIA.

Constraints

  • MUST cite principles from GDPR or CCPA where applicable.
  • MUST focus on the specific sensitivity of {{data_types}}.
  • MUST be critical of over-collection of data.

Output format

  • Project Summary: 2-sentence description.
  • Risk Factor Checklist: Table with Risk / Impact (Low/Med/High) / Likelihood.
  • Privacy Recommendations: Bulleted list of required controls.
  • Threshold Assessment: Final determination on whether a full DPIA is legally mandatory.

Quality bar

  • Does the analysis account for the specific vulnerability of {{subject_group}}?
  • Are the TOMs specific (e.g., 'AES-256 encryption') rather than generic ('security')?
privacy
gdpr
data protection
intermediate